# What not to upload

Read this before you drag anything into a project.

---

## Never upload

- Passwords, logins, API keys, anything from a password manager
- Bank details, card numbers, anything that would let someone take money
- Your customers' personal data. Names, addresses, phone numbers, medical or
  financial details. If it identifies a real person who has not agreed to it
  being there, leave it out.
- Employee records, contracts, disciplinaries, salaries
- Anything covered by an NDA with somebody else
- Anything a regulator would need to see a paper trail for

## Fine to upload

- Your own company information
- Your own services and prices
- Public reviews and testimonials
- Your published marketing, website copy, brochures
- Case studies where the customer has agreed to be named
- Your own processes, checklists and templates

## The test

Before you upload a file, ask: would I be comfortable if this ended up in front
of somebody outside the business? If the answer is no, either take that bit out
or do not upload the file.

## Anonymising is not just swapping the name

If you want to use a real job as an example, taking the customer's name out is
not enough. Postcodes, phone numbers, street addresses, invoice numbers and
photographs of the property will all still identify them. Take those out too.

## Who can see the project

Anyone you share the project with can read every file in it, and can see the
project instructions. On a Team or Enterprise plan a project shared with the
workspace is visible to everybody in the workspace. Check who is in there before
you upload anything sensitive.

## If you are in a regulated industry

Healthcare, finance, legal, insurance, anything with a governing body. Speak to
whoever handles your compliance before you upload client information, and keep a
note of what you decided. This file is not legal advice.
