Use the assistant to prepare, then have the conversation yourself. It does four jobs well, in order: play the client as uncharitably as you fear they will be, separate what happened from how you feel about it and what you are afraid it says about you, draft a one-paragraph opening that states your purpose and the outcome you want without blame, and list the questions you should ask instead of the speeches you are tempted to make. Before the assistant touches any of it, write the facts down by hand and strip every name. You are paying for a rehearsal. It raises the odds you say the thing you meant, and nobody has shown it fixes the outcome.

The conversations this covers are the ones small service firms actually have: a scope dispute where both sides remember the kickoff call differently, an invoice that is late and has quietly become a relationship problem, a price rise you have been putting off, and ending an engagement. Chasing an unpaid invoice is a letter, and an assistant can draft a letter and you can send it. A hard conversation is a call, and the assistant's job ends when the call starts.

Exhibit 1

The preparation runs in six steps and the last one belongs to a person

1. Write the facts by hand, strip names 2. Play the client, uncharitably 3. Split the three conversations apart 4. Draft a one-paragraph opening 5. List questions in place of speeches 6. Have the conversation yourself You Assistant You
Note: a sequence of steps, not a measured procedure

Write the facts by hand first

Open a plain document and type six things: the dates, what was agreed, what you delivered, what the client has said in their own words, what you want to happen, and what you are afraid of. Type it. The typing is the point, because it forces you to find out which of your "facts" you can produce and which ones live in your memory of a phone call.

This is the material you would hand a lawyer, and most of the work happens here. An assistant given a clean, nameless version of it has something to push against. An assistant given a vague grievance returns the same vague grievance in better grammar.

Names go in the trash before the prompt does

Client names, the amount tied to a name, the address, and the contact who complained do not go into a consumer chat. Anything under an NDA stays out too. Write "the client," write "the second invoice," write "their operations lead." The scenario survives the anonymizing intact, and the version you paste is yours to work with.

A firm doing bookkeeping work already lives under a confidentiality rule: the AICPA Code's Confidential Client Information Rule bars a member in public practice from disclosing confidential client information without the client's specific consent. That rule is about disclosure to anyone without consent, so it reaches an AI vendor's servers as easily as a contractor's inbox. Pasting a client name into a prompt is a disclosure. A design or consulting firm with no CPAs in it is not bound by that rule, and we would apply it to every engagement we take, because pasting a name is the same disclosure whichever service you sell. What each vendor does with what you paste is plan-specific, dated, and worth reading before you type.

On ChatGPT Free, Plus, and Pro on a personal workspace, data sharing is on by default, and OpenAI says so plainly. The switch is Settings, then Data controls, then Improve the model for everyone. Turning it off means new conversations are not used to train OpenAI models. It does not delete what you already have: your chats stay in your history, and what you wrote last month is not pulled back. One exception OpenAI states: give a reply a thumbs up or thumbs down and that whole conversation may be used for training even after you opt out.

OpenAI's enterprise privacy page, dated January 8, 2026, says that by default it does not use business data from ChatGPT Business, Enterprise, Edu, Teachers, and the API to train models. No training by default is not the same as no access: OpenAI says it runs business data through automated classifiers and that a small set of staff and bound contractors can review it for abuse. A consumer ChatGPT login does not inherit those commitments, because they attach to the workspace, not to the habit of using ChatGPT for work.

On Claude Free, Pro, and Max, you choose whether your chats are used to improve the models, a choice Anthropic has described since its consumer terms update announced in 2025. If you allow training use, Anthropic says it can keep that data, de-identified, for up to five years; if you do not, the older 30-day retention continues. The choice applies to new or resumed chats, and deleting a conversation takes it out of future training. Claude for Work, the API, and Claude Gov are not trained on by default, with one exception on Anthropic's commercial privacy page: feedback you submit on purpose, such as a thumbs up, can be used.

Google's Gemini Apps Privacy Hub says a subset of chats is reviewed by human reviewers, including trained reviewers at its service providers, and Google tells users directly not to enter confidential information they would not want a reviewer to see. Reviewed chats are kept for up to three years even if you delete the activity.

Microsoft is the one to read carefully, because it has two products under one name now. Microsoft's admin documentation says prompts, responses, and data reached through Microsoft Graph are not used to train foundation language models in the organizational product. The consumer version works the other way: Microsoft says it uses conversation activity with Copilot for AI training unless you are signed out, under 18, covered by an organizational account, or opted out. Microsoft also says some conversations are reviewed by people. Its model-training text currently sits on a page marked as applying to the older consumer app, after Microsoft renamed Microsoft 365 Copilot to Microsoft Copilot and shipped a new app on August 18, 2026, so check which product any quoted sentence is about.

Exhibit 2

The facts go into the prompt and the client's names and account details stay out

Goes in The dates What was agreed What you delivered The client's own words What you want to happen What you are afraid of Stays out Client names The amount tied to a name The address The contact who complained Anything under an NDA Write "the client" instead
Note: an operating rule for one task, not a compliance program

The general version of this, including what belongs on your own machine, is in which parts of your work can go in ChatGPT, and the two assistants we compare most often are Claude and ChatGPT for back-office work.

Job one: the assistant plays the client

Ask it to argue the client's case as well as it can, at full strength, with no obligation to be fair to you. Feed it your facts, then say: "You are the client. I am going to tell you we think the extra work is outside scope. Give me your four best rebuttals and do not soften them."

This is the part owners skip, and it carries most of the value. You have probably been rehearsing a version of this conversation in your head for weeks, and that version stars you as reasonable and the client as briefly confused. The assistant will not do you that favor. It will find the sentence in your own scope document that is ambiguous, which is the sentence the client is going to read out.

Vendors sell this shape of rehearsal now. Crucial Learning sells an AI role-play feature for practicing high-stakes workplace conversations before they happen, and says it extends their training instead of replacing it. Google's Gemini Live pages describe turning the phone into a mock interviewer with feedback on tone and clarity. OpenAI's Academy publishes an interview practice flow where ChatGPT plays the hiring manager, asks one question at a time, and gives one or two tips after each answer. The vendor pages are for job interviews; the shape transfers to a client call. None of those pages prints a study showing the practice improves anything.

The evidence on rehearsal is mixed. In a 2013 JAMA randomized trial of 472 clinician trainees, simulation-based communication training improved acquired skill but did not improve patients' ratings of communication compared with usual education. The authors read that gap as an open question about transfer from practice to real conversations, which is the honest framing for a scope dispute. The positive side of this literature is observational: a 2016 study of 1,537 physicians at one large medical center found that experiential communication training with small-group practice improved patient satisfaction scores, and the authors stated they could not rule out other causes. Practicing changes how you show up. Nobody has shown it fixes the outcome.

One caution about the frame itself. Douglas Stone, Bruce Patton, and Sheila Heen published Difficult Conversations in 1999, out of the Harvard Negotiation Project, the group behind Getting to Yes. Their argument is that a hard conversation is really three conversations at once: the "what happened" conversation, the feelings conversation, and the identity conversation. The publisher describes the method as built on fifteen years of research and consultation at the project, which is a description of where it came from, not a measured success rate. Kerry Patterson, Joseph Grenny, Ron McMillan, and Al Switzler wrote Crucial Conversations, published by McGraw-Hill and first cataloged in 2001; Crucial Learning, the company they run, defines a Crucial Conversation as one with high stakes, opposing opinions, and strong emotions. Both frameworks are products sold alongside courses and assessments. They are useful vocabulary. Do not expect a study behind the promise.

Job two: split the three conversations apart

Give the assistant your written facts and ask it to sort them into three columns: what an impartial observer could confirm happened, what you feel about it, and what you are worried this says about you as a professional. Then read the columns separately.

The third column is the one that ruins these calls. A late invoice becomes evidence that you do not run a tight business. A scope dispute becomes proof that you should never have taken the job. The client never said any of that, and it is usually the loudest voice in your head during the meeting, so it comes out as defensiveness. Naming it on paper before the call is how you keep it off the call.

Ask the assistant to do one more cut: mark every sentence in your notes that contains a judgment about the client's motives, and rewrite those as observations. "They are stringing us along" has no evidence attached to it. "We sent the second invoice on the date in the notes and have no reply" can be checked.

Job three: draft the opening paragraph

Stone, Patton, and Heen advise opening with what they call the third story, the version a neutral observer would give, and their instruction is to name the gap between your account and the client's account instead of opening with your verdict. The book treats the aim as a learning conversation, an exchange where you intend to find out something you do not yet know. That is a good specification for a prompt.

Ask for one paragraph, five sentences at most. It should name the situation in terms both sides would sign, state the purpose of the call, state the outcome you want, and end with one question. No blame, no history lesson, no "as you know." Then read it aloud once, because written openings are longer than spoken ones and you will run out of breath.

Exhibit 3

A usable opening names the gap, the purpose, the outcome, and one question

1 Name the gap Your account and theirs, in terms both sides would sign. 2 State the purpose of the call No blame, no history lesson. 3 State the outcome you want Pick one you can stand behind: a price rise,a revised scope, a payment plan, a termination date. 4 Ask one question Find out something you do not yet know.
Note: a shape for the paragraph, not a script to memorize

The named outcome is the part you must decide yourself. Pick one: a price rise, a revised scope document, a payment plan on an old invoice, a termination date. The assistant will happily propose all of them, and a proposal you cannot stand behind at the end of the call is worse than no proposal.

Job four: questions in place of speeches

Ask for eight questions to ask on the call, ordered, with a one-line note on what each one is likely to teach you. "What were you expecting when we sent the second invoice?" is a better move than your best paragraph about scope, and it costs you nothing to ask.

The party that asks the questions sets the agenda. That habit is the same one behind quotes that get answered and turning meeting notes into an action list.

Check four things before you dial

Every fact in your opening is true, and you can produce the document behind it. The outcome you propose is one the firm can stand behind, which means you checked the rate, the deadline, and the scope against the numbers in your books. Nothing the assistant wrote commits the firm to anything: read the opening for words like "we will" and "going forward" and cut them unless you decided them. And you have chosen, in advance, the one thing you will not concede, written at the top of your notes where you can see it.

Then send yourself the notes, close the assistant, and make the call. Pasting a rehearsed paragraph into an email is the one move that wastes all of this, because the client answers the email and now the disagreement is a document with two versions on file. Preparing the person is one of the everyday tasks AI can take over in a small business, and it is also one of the tasks where the privacy settings decide what you may paste. Nihul Consulting's AI enablement work covers setting up the data-control side of this, which prompts are safe to send and which are not.

Start a conversation

All notes Start a conversation