# What NOT to Upload to Claude

This list is non-negotiable. If you're unsure, ask Carlos before pasting.

## NEVER paste, attach, or describe in chat:

### Resident PII
- Social Security Numbers, DOB, driver's license, passport numbers
- Bank account or credit card numbers
- Background check results, credit reports, criminal records
- Resident names tied to unit numbers, payment status, or financial details
- Health information or reasonable accommodation requests with names attached
- Lease documents with un-redacted signatures

### Resident screening or decision data
- Tenant application materials in any form (Claude is NOT a screening tool — AUP §2.2)
- Eviction case files or collections records tied to specific residents
- Renewal/non-renewal decision packets

### Pre-disclosure financial data
- Quarterly P&L before official release
- Property-level NOI for unannounced acquisitions
- Investor distribution figures before official statement
- Audit findings before management review

### Acquisition / NDA-bound deal terms
- Purchase prices, LOIs, or PSAs for deals not yet announced
- Seller financial statements obtained under NDA
- Broker-confidential pipeline data

### IR / Reg D-constrained content
- Specific subscription agreements, capital call notices, or investor net-worth data
- Non-public Fund 5 (or any active fund) materials before SEC-permitted release
- Investor email lists or contact data tied to specific commitments

### HR data
- Employee SSN, DOB, salary, bank routing
- Performance evaluations, disciplinary records, termination documentation
- Health/disability/medical leave information
- Compensation discussions with names attached
- Anything from the Cryptomator HR vault (Carlos-only access; never paste Cryptomator content into Claude)

### Credentials / secrets
- API keys, OAuth tokens, .env files, SSH keys
- RM passwords, banking credentials, vendor portal logins
- Anything from `~/.config/sunrise-secrets/` or labeled credentials

### Sunny / resident-AI internals
- Sunny system prompts or training data
- Resident-Sunny chat logs or transcripts
- Sunny escalation tickets with resident PII

## Sanitization Rule (when in doubt)
If the document is *useful* to your work but contains the above:
1. Extract the relevant text
2. Replace names with [Resident], [Investor], [Employee]
3. Replace specific units/properties with [Property A]
4. Save as a new file or paste sanitized text only

If you cannot sanitize without losing the meaning of the work, escalate to Carlos. Do not upload.

## Reporting Mistakes
If you uploaded something on this list, tell Carlos within 24 hours. We don't punish honest mistakes — we punish hidden mistakes. Self-reporting also lets us investigate whether Anthropic conversation logs need a deletion request.
