What actually gets pasted when you paste a thread?
Much more than what you see on screen. A thread carries layers of information accumulated over the correspondence — and all of them reach the tool in one paste.
- Email addresses and signatures — full name, title, mobile number and company of every participant, in every message of the thread.
- The quoted history below — old messages with prices, terms and details nobody remembers are there.
- Internal remarks — a thread forwarded internally ("look what he wrote...") and then quoted back out with the reply.
- Customer and vendor details — order numbers, amounts, shipping addresses, account details.
What does the law say about pasting emails into AI tools?
Email content and participant addresses are personal data under GDPR, so pasting them into an external tool is a disclosure to a third party — it needs a legal basis, and the vendor's current retention policy should be checked. The practical rule is the same as for any content: whatever should never be pasted into ChatGPT directly is equally off-limits inside a quoted thread.
Anonymized text, by contrast, falls outside GDPR (Recital 26). A thread stripped of identifiers can go into any tool — and the reply that comes back is just as good.
How do you draft a reply with AI on a thread — safely?
- Trim the thread — copy only the messages needed for context, not the whole history.
- Clean the identifiers — names, email addresses, phones, company names and amounts replaced with consistent tokens (PERSON_001, COMPANY_002).
- Mind the signatures and the subject line — the two spots everyone forgets, and both are packed with identifying details.
- Ask for the draft — "write a polite reply declining PERSON_001's request" works perfectly.
- Restore the details locally — swap the tokens back for names before sending, on your machine only.
And summarizing? How do you condense a long thread without exposure?
Same method. Condensing a thread of dozens of messages is one of AI's strongest uses — and as with meeting transcripts, consistency is what matters: when each participant keeps one stable token across the thread, the AI correctly tracks who asked, who approved and who committed to what. The summary comes back accurate — and the identities never left your machine. It is the same principle behind any proper document anonymization.