25 ChatGPT-5.5 Prompts to Help Older Adults Review Suspicious Messages, Bills, Travel Plans, and Online Safety


Safety boundary: ChatGPT cannot authenticate a sender or declare a message safe. OpenAI reports that users aged 55+ grew from 6% to nearly 10% of weekly messages; the prompts below therefore emphasize redaction, independent official-channel verification, and trusted-person review before action.
Why this prompt collection starts with “pause, redact, verify”
This opening section sets the safety rules for the 25 copy-paste prompts that follow. The prompts are designed for older adults, family helpers, librarians, community educators, and advanced ChatGPT users who want a careful second look at suspicious messages, confusing bills, travel details, online shopping questions, and account-recovery notices. The goal is not to make ChatGPT the judge of what is “safe.” The goal is to slow the decision down, separate observable warning signs from guesses, protect private information, and create a short checklist for independent verification before anyone pays, replies, clicks, downloads, changes an account, or shares sensitive information.
OpenAI has recently framed this need as a practical AI-literacy issue for older adults. According to OpenAI, OpenAI Academy and Older Adults Technology Services from AARP announced free in-person ChatGPT workshops for 1,000 older adults across 10 U.S. cities as part of a multi-year collaboration focused on everyday AI skills and online safety. OpenAI also reported that the U.S. share of ChatGPT messages associated with people aged 55 and older grew from 6% to nearly 10% in one year. Those figures are vendor-published claims from OpenAI, and they are useful here because they show why scam review, bill explanation, travel planning, and privacy-safe prompting need plain-language procedures rather than abstract AI advice.
OpenAI’s older-adult AI Skills Jam examples include trip planning, understanding confusing letters or bills, spotting potential scams, exploring hobbies, and staying connected with family. Those are everyday tasks where ChatGPT can be helpful as a reading assistant, organizer, checklist generator, or rehearsal partner. They are also tasks where a wrong next step can be expensive or stressful: a rushed payment, a link opened from a fake delivery text, a “bank” number copied from a scam email, or a one-time code shared with someone pretending to be technical support. This article therefore treats ChatGPT as a tool for structured thinking, not as an authority that can authenticate a sender or guarantee that a message is harmless.
The article provides 25 ChatGPT prompts for parents managing teen AI usage, including screen time, digital literacy, homework-help boundaries, and online safety conversations. The 25 ChatGPT Prompts for Parents Managing Their Teen’s AI Usage: Screen Time, Digital Literacy, Homework Help Boundaries, and Online Safety Conversations article is a focused companion for ChatGPT Digital Literacy because it is the strongest match for a marker about using ChatGPT to build practical digital literacy and safer online habits.
The safety pattern: urgent language, secrecy, suspicious links, then pause-think-ask
OpenAI’s workshop framing highlights urgent language, secrecy, suspicious links, and a simple “pause-think-ask” practice. That pattern is practical because many scams try to compress time, isolate the target, and move the conversation to a link, payment method, download, or code-sharing step. A text that says “act in 10 minutes,” “do not tell anyone,” “your account will be closed,” or “follow the included link to avoid a penalty” deserves extra caution even if it includes familiar names, logos, order numbers, or partial personal details. The warning sign is not merely that the message feels unpleasant; the warning sign is that it pressures the reader to act before verifying through a channel they chose independently.
“Pause” means do not click links, open attachments, call numbers supplied in the suspicious message, reply with personal details, send money, buy gift cards, move cryptocurrency, approve a login, install software, or provide a one-time code. “Think” means copy only the non-sensitive parts of the message into ChatGPT and ask for a warning-sign analysis, a redaction checklist, and a verification plan. “Ask” means contact a trusted person or an official organization through a contact method found independently, such as the phone number printed on a bank card, a statement already known to be genuine, a bookmarked government website, an official app opened directly, or an in-person visit to a local branch or service desk.
Decision rule: if a message asks for money, credentials, identity numbers, medical details, account recovery codes, remote access, secrecy, or immediate action, do not treat ChatGPT’s response as permission to proceed. Use ChatGPT only to prepare questions and a verification checklist, then confirm through a trusted person or an official channel found independently.
What ChatGPT can help with—and what it must not decide for you
For these prompts, ChatGPT’s safest role is to classify evidence that the user can see. It can identify pressure tactics, suspicious wording, mismatched sender names, unusual payment instructions, requests for secrecy, odd grammar, inconsistent dates, unclear fees, missing account context, and links that should not be opened from the message itself. It can also rewrite a confusing bill or notice into plain language, list questions to ask a provider, and prepare a calm script for calling an official number. That is different from verifying that a sender is genuine, confirming that an invoice is legitimate, determining legal liability, diagnosing a medical issue, resolving a tax matter, or deciding whether a financial transaction is safe.
OpenAI’s API safety best-practices guidance emphasizes defense in depth, human review for consequential outputs, clear limitation communication, privacy-preserving safety identifiers where appropriate, and access to original evidence for reviewers who need to verify a model-produced summary or decision. Applied to older-adult prompts, the same principle becomes simple: ChatGPT can help organize what you have, but a human still needs the original message, the real bill, the official account, or the trusted family context before taking consequential action. If the issue involves taxes, insurance, benefits, medicine, debt, housing, immigration, legal claims, banking, investments, or identity theft, the prompt should lead to verification and qualified advice rather than a final answer from the model.
| Use ChatGPT for | Do not use ChatGPT for | Required next step |
|---|---|---|
| Listing warning signs in a text, email, bill, travel notice, or marketplace message | Declaring that the sender is authentic or that a link is safe to open | Verify through an official contact method found independently |
| Creating a redacted summary of a confusing notice | Sharing full account numbers, passwords, one-time codes, medical records, or identity numbers | Remove sensitive details before prompting and keep originals offline |
| Drafting questions for a bank, insurer, travel provider, doctor’s office, or government agency | Replacing legal, tax, medical, insurance, or financial advice | Speak with the official organization or a qualified professional |
| Preparing a calm script for asking a family member or trusted helper to review something | Letting a helper, model, or caller pressure the older adult into immediate action | Pause the decision and confirm with a trusted person who is not part of the message thread |
Privacy redaction: what to remove before using any prompt
Every prompt in this article assumes that sensitive details have been removed before the user pastes text into ChatGPT. Redaction is not cosmetic; it is a safety step that limits unnecessary exposure and prevents the conversation from becoming a storage place for secrets. Before copying a message, bill, itinerary, or notice, remove passwords, passkeys, one-time codes, recovery codes, Social Security numbers, full driver’s license numbers, passport numbers, full bank or card numbers, insurance member IDs, full medical record numbers, tax identifiers, exact birth dates when not needed, full addresses when not needed, and any private details about another person who has not agreed to share them.
A useful redaction method is to replace details with labels that preserve the structure of the problem. For example, change a bank name to “[my bank],” a phone number to “[phone number in message],” a link to “[link removed],” a dollar amount to “[amount: about $500]” if the approximate size matters, and an account number to “[account ending in 1234]” only if the last four digits are already visible on a legitimate statement and needed for context. If a notice includes medical, legal, or tax content, provide a short paraphrase instead of the full document unless a qualified helper has approved what can be shared.
This Temporary Chat privacy guide explains how memory, plugins, custom instructions, and saving interact, giving readers concrete privacy settings to review before sharing redacted personal material with ChatGPT. The ChatGPT Temporary Chat Personalization Explained: Memory, Plugins, Custom Instructions, Saving, and Privacy article is a focused companion for Privacy Safe Prompting because the target directly addresses ChatGPT privacy behavior and is materially more useful to older adults than a crowdworker-evaluation playbook.
Independent official-contact discovery is non-negotiable
The most important verification rule is that official contact information should be found independently rather than through a suspicious message. If a text claims to be from a bank, do not use the phone number or link in that text. Use the number printed on the back of the card, a known official app opened directly, a statement already verified as genuine, or a branch visit. If an email claims to be from a delivery service, type the known company address into the browser yourself or use a saved app rather than following the email link. If a notice claims to be from a government agency, start from a known official source, a mailed document you already trust, or a local office contact—not the urgent message.
This rule also protects family helpers and librarians. A helper should not “just check the link” on behalf of the older adult, because that can move the risk to the helper’s device or normalize unsafe behavior. The better helper role is to sit with the person, remove sensitive details, ask ChatGPT to identify warning signs and questions, and then help locate an official contact through a source not supplied by the suspicious message. If there is disagreement, the safer default is to wait, document the concern, and seek a second trusted review rather than acting under pressure.
Trusted-person confirmation without taking away control
Trusted-person confirmation works best when it respects the older adult’s control. The helper should not seize the phone, make decisions privately, or shame the person for being uncertain. A good process is to ask permission, review only the relevant message or bill, redact sensitive information, run one of the prompts together, and write down the next verification step. The older adult should know who will be contacted, why that contact is official or trusted, and what information will be shared. If a payment, password change, account recovery, fraud report, legal filing, or medical decision is involved, the helper should pause and involve the appropriate official channel or qualified professional.
Family scams often exploit trust by impersonating a grandchild, friend, church member, neighbor, coworker, or service provider. For those messages, the verification question is not “does the story sound possible?” but “can we confirm this through a separate channel?” A safe family-verification prompt should produce steps such as calling the person at a known number, asking a question only the real person would answer, contacting another family member, or waiting until the urgency can be checked. It should not suggest sending money to prove love, keeping the request secret, or continuing the conversation only on the channel where the suspicious message arrived.
The no-action limit built into every prompt
Each copy-paste prompt later in this article includes a no-action limit: ChatGPT should not click links, contact senders, make payments, disclose secrets, approve logins, provide passwords, reveal one-time codes, or decide that a consequential action is safe. This matters because a well-written AI response can sound confident even when the evidence is incomplete. The prompts therefore ask for observable warning signs, uncertain interpretations, redaction guidance, safer wording for questions, and a verification checkpoint. The expected output is a checklist, not a green light.
The same no-action limit applies when the message appears routine. A real bill can still be confusing. A real travel update can still require independent confirmation. A legitimate provider can still send a poorly worded notice. ChatGPT can help translate, summarize, and organize, but it cannot see the sender’s private systems, validate an account balance, guarantee a refund, recover lost funds, or confirm that a payment destination belongs to the named organization. When the stakes are high, the safest answer is often a short plan: stop, redact, verify independently, ask a trusted person, and act only after the official source confirms the next step.
How to use the 25 prompts that follow
Use the prompts as templates, not scripts that must be filled with private data. Each prompt section includes a purpose, copy-paste prompt, required inputs, expected output, and verification checkpoint. For a suspicious text, the required input might be a redacted copy of the message and how it arrived. For a confusing bill, it might be a paraphrase of the charge, the date, and the organization name without account numbers. For travel planning, it might be destination preferences and mobility needs without passport details or payment information. If a prompt asks for something you do not have, write “unknown” rather than guessing.
The best workflow is deliberately slow: take a screenshot or save the message without interacting with it; redact sensitive details; paste the safe version into the chosen prompt; ask for warning signs and verification steps; discuss the result with a trusted person if the issue is consequential; find the official contact independently; and only then decide whether to ignore, report, call, pay, update, or escalate. That workflow turns ChatGPT into a calm preparation tool while keeping authority where it belongs: with the user, trusted people, official organizations, and qualified professionals.
Prompts 1–9: Suspicious Messages, Links, Attachments, Deliveries, and Charity Requests

OpenAI’s older-adult AI literacy work with Older Adults Technology Services from AARP emphasizes practical uses such as spotting potential scams, understanding confusing notices, and using a pause-think-ask habit before acting. The prompts below turn that pattern into repeatable checklists: pause before responding, redact private details, ask ChatGPT to separate observable warning signs from uncertainty, and verify through a trusted person or an official channel found independently.
This report on indirect attacks against AI chatbots explains how deceptive content can create scam and data-theft risks, reinforcing the need to pause, redact, and verify suspicious messages independently. The Indirect Attacks Exploit AI Chatbots, Posing Scam and Dat… article is a focused companion for Phishing and Scam Detection because the target is the catalog’s only direct scam-oriented article and supports the article’s warning-sign and independent-verification workflow.
Prompt 1: Suspicious text message
Purpose
Use this prompt when a text message claims there is a problem, prize, delivery, payment, account lockout, family emergency, or urgent request. The goal is not to prove the text is fake or safe; it is to slow the decision down and produce a verification plan that does not rely on the message itself.
Copy-paste prompt
I am an older adult reviewing a suspicious text message. Help me evaluate it safely.
Shared safety contract: Do not tell me to click links, open shortened links, call numbers from the message, contact the sender directly, make payments, buy gift cards, send money, download apps, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Message text, with private information removed:
[PASTE REDACTED TEXT MESSAGE]
Context:
[Who it claims to be from, whether I expected it, and what it asks me to do]
Please produce:
1. Plain-language summary of what the message is asking.
2. Observable warning signs, if any.
3. Uncertain items that need verification.
4. What personal information should stay redacted.
5. A safe next-step checklist using pause-think-ask.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The text message with names, phone numbers, account numbers, links, codes, and addresses removed or replaced with labels such as “[bank name]” or “[link removed].”
- Whether you expected the message, have an account with the named organization, or recently started a related transaction.
- Whether the message asks for urgency, secrecy, payment, codes, or a link tap.
Expected output
ChatGPT should provide a structured risk review, identify urgency or secrecy language, flag requests for payment or codes, and list information that should remain private. It should avoid declaring the text “safe” and should recommend independent verification.
Verification checkpoint
Do not reply to the text. If the issue could be real, use a phone number, app, paper statement, saved bookmark, or official website found independently—not the text message—to contact the organization, or ask a trusted helper to sit with you while you verify.
Prompt 2: Suspicious email
Purpose
Use this prompt for an email that claims to come from a bank, government agency, delivery company, retailer, charity, insurance provider, medical office, or technology company. Email scams often combine official-looking logos with pressure, confusing wording, or links that lead away from the real organization.
Copy-paste prompt
I am reviewing a suspicious email and want a cautious checklist, not a final judgment.
Shared safety contract: Do not tell me to click links, open attachments, call numbers from the email, contact the sender directly, make payments, buy gift cards, send money, download apps, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Email details, redacted:
Subject: [PASTE SUBJECT WITHOUT PRIVATE DATA]
Sender display name: [PASTE DISPLAY NAME ONLY IF SAFE]
Sender address domain, if visible without clicking: [PASTE DOMAIN OR “not sure”]
Body text with links, numbers, addresses, codes, and account details removed:
[PASTE REDACTED EMAIL BODY]
Please provide:
1. A one-paragraph summary.
2. Warning signs visible in the text.
3. Questions I should answer before trusting it.
4. Redactions I should keep in place.
5. A safe verification plan that avoids using email links or attachments.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- Redacted subject line and body text.
- Whether the sender address appears unusual, misspelled, unexpected, or different from prior legitimate messages.
- Whether the email contains an attachment, deadline, refund, invoice, account warning, or payment request.
Expected output
The response should distinguish what is visible, such as a mismatch in sender name or urgent wording, from what remains unknown, such as whether the sender account was compromised. It should advise against using embedded contact details for verification.
Verification checkpoint
Open a separate browser window or use a trusted app only if you normally use that service. Type the organization’s address yourself from a known source, use a paper statement, or call an independently found official number before taking action.
Prompt 3: Impersonation of family, friend, employer, or official
Purpose
Use this prompt when someone claims to be a grandchild, friend, co-worker, caregiver, police officer, government employee, bank representative, technical support worker, or another trusted person. Impersonation attempts often push urgency and secrecy to prevent you from checking with someone else.
Copy-paste prompt
I received a message that may be impersonating someone I know or an official organization. Help me slow down and verify safely.
Shared safety contract: Do not tell me to click links, contact the sender through the message, call numbers provided by the sender, make payments, buy gift cards, send money, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Redacted message:
[PASTE MESSAGE WITH NAMES, NUMBERS, LINKS, LOCATIONS, AND PRIVATE DETAILS REMOVED]
Claimed identity:
[Who they say they are]
Request:
[Money, secrecy, travel help, account help, personal information, emergency action, or something else]
Please create:
1. Impersonation warning signs.
2. Safe questions I can ask through a separate known contact method.
3. A list of details I should not reveal.
4. A calm script for telling the sender I will verify independently.
5. A trusted-person confirmation plan.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The claimed identity and relationship.
- The exact request, with private facts removed.
- Whether the sender discourages calling family, contacting a bank, or speaking with anyone else.
Expected output
ChatGPT should produce a verification checklist and a calm response script that does not reveal new information. It should treat secrecy, emotional pressure, and unusual payment methods as warning signs without claiming to know who is behind the message.
Verification checkpoint
Contact the real person using a number already saved in your phone, a prior verified email thread, or another trusted family member. If the sender claims to be an official, use independently found official contact information.
The article explains ChatGPT Trusted Contact, an optional 2026 safety feature that lets adult users designate a trusted family member, friend, or mentor. The ChatGPT Trusted Contact: Complete Setup Guide for the New Safety Feature in 2026 article is a focused companion for Family Online Safety because it fits a family-support angle for online safety, especially when older adults may want a trusted person involved in safety-related ChatGPT use.
Prompt 4: Urgent gift-card, wire, crypto, or payment request
Purpose
Use this prompt when any message asks you to pay quickly, buy gift cards, send wire transfers, use cryptocurrency, move money to “protect” it, pay a fine, cover a family emergency, or keep the transaction secret. The expected result is a stop-and-verify plan before any financial action.
Copy-paste prompt
I received an urgent payment request. Help me review it without taking action.
Shared safety contract: Do not tell me to click links, contact the sender, call numbers from the request, make payments, buy gift cards, send money, transfer funds, use cryptocurrency, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Redacted request:
[PASTE MESSAGE WITH AMOUNTS OPTIONAL, BUT REMOVE ACCOUNT NUMBERS, LINKS, CODES, NAMES, AND CONTACT DETAILS]
Payment method requested:
[Gift card, wire, payment app, crypto, bank transfer, cash, check, or other]
Deadline or pressure language:
[PASTE REDACTED PHRASE OR WRITE “none”]
Please provide:
1. High-risk payment warning signs.
2. Why urgency and secrecy increase risk.
3. Information I must not provide.
4. A no-payment verification checklist.
5. A short script for pausing the request.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The payment method requested.
- Any stated deadline, threat, reward, refund promise, or emergency claim.
- Whether the message says not to tell family, a bank, law enforcement, a store employee, or another trusted person.
Expected output
The output should emphasize that unusual payment methods and secrecy are major warning signs. It should recommend pausing, refusing to provide codes or receipts, and verifying through a separate channel before any transaction.
Verification checkpoint
Before spending or transferring money, speak with a trusted person and, if relevant, your bank using a known number. Store employees, librarians, family helpers, and community educators can help you pause, but they should not pressure you or take over your accounts.
Prompt 5: Suspicious link
Purpose
Use this prompt when a message includes a link that claims to resolve a package problem, account lockout, refund, ticket issue, medical portal notice, prize, tax question, or subscription renewal. The prompt asks ChatGPT to evaluate the surrounding message, not to open or analyze the link directly.
Copy-paste prompt
I received a message with a suspicious link. Help me decide how to verify without opening it.
Shared safety contract: Do not tell me to click the link, copy it into a browser, use a link expander, contact the sender, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Message text with the link removed:
[PASTE REDACTED MESSAGE]
Visible link text only, if safe to type without opening:
[PASTE ONLY THE DISPLAYED WORDS OR WRITE “link removed”]
Claimed organization:
[NAME OF ORGANIZATION, IF ANY]
Please provide:
1. Warning signs around the link.
2. What cannot be known without official verification.
3. Information I should not enter on any linked page.
4. Safer ways to reach the organization.
5. A pause-think-ask checklist.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The redacted message text with the actual link removed.
- The claimed organization or service.
- Whether the link arrived unexpectedly or after a recent transaction.
Expected output
ChatGPT should explain why links in unexpected messages are risky, identify pressure language, and offer safer independent routes such as a saved app, official website found separately, paper bill, membership card, or known phone number.
Verification checkpoint
Do not open the link. If you need to check the claim, start from a source you already trust, such as a saved bookmark, printed statement, official app, or number on the back of a card.
Prompt 6: Attachment risk
Purpose
Use this prompt when an email or message includes an attachment such as an invoice, receipt, voicemail, form, label, photo, document, calendar invite, or compressed file. The prompt is designed to help you decide whether independent verification is needed before opening anything.
Copy-paste prompt
I received a message with an attachment. Help me review the risk without opening it.
Shared safety contract: Do not tell me to open the attachment, enable macros, download files, click links, contact the sender through the message, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Redacted message:
[PASTE MESSAGE WITHOUT LINKS, CONTACT DETAILS, ACCOUNT NUMBERS, OR PRIVATE DATA]
Attachment description:
[File name if safe, file type if visible, and what it claims to be]
Was I expecting it?
[Yes, no, or unsure]
Please provide:
1. Attachment-related warning signs.
2. Questions to verify before opening.
3. Private information to keep out of replies.
4. Safe alternatives for obtaining the document.
5. A recommendation to pause until verified.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- What the attachment claims to be.
- Whether you expected a document from that sender.
- The sender’s claimed identity, with private details removed.
Expected output
The response should identify unexpected attachments, mismatched context, unusual file types, and pressure to open quickly as warning signs. It should recommend confirming through a known channel or asking the organization to provide the document through a verified portal.
Verification checkpoint
Do not open the attachment until you confirm it through a trusted route. If the document is legitimate, the sender should be able to confirm it through a known phone number, official portal, or prior verified conversation.
Prompt 7: Account-warning message
Purpose
Use this prompt for messages claiming your bank, email, social media, streaming, medical, tax, cloud, or shopping account will be closed, locked, charged, suspended, or compromised unless you act immediately. The prompt helps separate real account maintenance from pressure tactics.
Copy-paste prompt
I received an account-warning message. Help me review it safely before I do anything.
Shared safety contract: Do not tell me to click links, log in through the message, call numbers from the message, contact the sender directly, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Redacted account warning:
[PASTE MESSAGE WITH LINKS, NUMBERS, ACCOUNT DETAILS, CODES, AND PRIVATE INFORMATION REMOVED]
Claimed service:
[Bank, email, shopping site, medical portal, government account, or other]
Threat or deadline:
[PASTE REDACTED WORDING OR WRITE “none”]
Please provide:
1. Summary of the claimed problem.
2. Warning signs in the wording.
3. What I should never provide in response.
4. A safe account-checking plan.
5. When to ask a trusted helper to sit with me.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The claimed service and problem.
- Any deadline, threat, fee, or request to “verify” information.
- Whether you recently changed settings, made a purchase, or requested support.
Expected output
ChatGPT should recommend going directly to the service through a trusted route instead of using message links. It should flag requests for passwords, one-time codes, payment information, and identity data as unsafe to provide in response.
Verification checkpoint
Use the official app or website you normally use, or contact support through information found independently. If you feel rushed, stop and ask a trusted person to review the message with you before logging in or changing anything.
Prompt 8: Delivery notice
Purpose
Use this prompt for delivery, customs, shipping, missed-package, address-correction, or postage-fee messages. These notices are common because many people are waiting for packages, but a real delivery issue can be checked without using a suspicious message link.
Copy-paste prompt
I received a delivery or shipping notice that may be suspicious. Help me review it without clicking anything.
Shared safety contract: Do not tell me to click links, enter tracking numbers into a message link, call numbers from the notice, contact the sender directly, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Redacted delivery notice:
[PASTE MESSAGE WITH LINKS, TRACKING NUMBERS, ADDRESSES, PHONE NUMBERS, AND PRIVATE DETAILS REMOVED]
Was I expecting a delivery?
[Yes, no, or unsure]
What it asks me to do:
[Pay fee, update address, reschedule, verify identity, open attachment, or other]
Please provide:
1. Delivery-scam warning signs.
2. What could be legitimate but needs checking.
3. Information I should not enter.
4. Safe ways to verify shipping status.
5. A calm next-step checklist.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- Whether you are expecting a package.
- What the notice asks you to do.
- Whether it requests a fee, address confirmation, identity information, or a link tap.
Expected output
The output should identify suspicious requests for small fees, address updates, identity confirmation, and urgent rescheduling through a link. It should also acknowledge that legitimate deliveries can have delays, which is why independent checking matters.
Verification checkpoint
Check the retailer, shipper, or postal service through an account or tracking page you reach independently. If someone else ordered the item for you, ask that person through a known contact method.
Prompt 9: Charity request
Purpose
Use this prompt when a message asks for donations after a disaster, medical hardship, memorial, community emergency, religious appeal, political event, or personal story. The goal is to protect generosity by verifying the organization and payment route before giving.
Copy-paste prompt
I received a charity or donation request. Help me evaluate it carefully before I donate.
Shared safety contract: Do not tell me to click links, contact the sender through the request, call numbers in the message, make payments, buy gift cards, send money, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Require confirmation through a trusted person or an official channel I find independently before any action.
Redacted charity request:
[PASTE MESSAGE WITH LINKS, NAMES, PHONE NUMBERS, PAYMENT DETAILS, ADDRESSES, AND PRIVATE INFORMATION REMOVED]
Cause or organization claimed:
[PASTE GENERAL DESCRIPTION]
Donation method requested:
[Card, payment app, check, cash, wire, gift card, crypto, or other]
Please provide:
1. Warning signs in the appeal.
2. What information is missing or unverifiable from the message alone.
3. Donation methods that require extra caution.
4. A verification checklist before giving.
5. A respectful script for saying I need time to verify.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The general cause, organization name if visible, and requested donation method.
- Whether the request came from someone you know, a social media post, email, text, phone call, or mailed notice.
- Whether the message uses urgency, guilt, secrecy, or unusual payment instructions.
Expected output
ChatGPT should help you review the appeal without judging the cause itself. It should flag pressure tactics, vague organization details, and payment methods that are difficult to reverse, while encouraging independent verification before donating.
Verification checkpoint
If you want to give, find the charity’s official donation method independently or ask a trusted helper to verify it with you. Do not donate through links, phone numbers, QR codes, or payment handles supplied only in the suspicious request.
Prompts 10–18: Bills, Notices, Travel Plans, Shopping Decisions, and Account Recovery

OpenAI’s older-adult AI-literacy work highlights practical tasks such as understanding confusing letters or bills, planning trips, and spotting possible scams; the prompts below turn those use cases into slower, privacy-aware review routines. They do not ask ChatGPT to declare something “safe,” contact anyone, recover money, change an account, or replace a professional adviser. They ask for redaction, observable warning signs, uncertainty, and independent verification through a trusted person or an official channel found separately from the suspicious message.
When an unfamiliar charge specifically concerns ChatGPT, this plan-and-pricing guide helps readers distinguish official plan categories before they verify the charge through an independently located OpenAI channel. The The Complete Guide to ChatGPT Pricing in 2026 — Free, Go, Plus, Pro, Business, and Enterprise Compared article is a focused companion for Understanding Bills with ChatGPT because the target is narrower than general bill review, so the bridge limits it to ChatGPT-related charges and preserves the article’s no-payment, independent-verification boundary.
Prompt 10: Unfamiliar bill or invoice
Purpose: Use this prompt when a paper bill, email invoice, or mailed statement looks unfamiliar, arrives unexpectedly, has a short payment deadline, or includes confusing fees. The goal is to organize what the document appears to say without treating it as valid debt.
Copy-paste prompt:
I am reviewing an unfamiliar bill or invoice. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Help me slow down and review it safely.
First, tell me what I should redact before sharing details, including account numbers, full names, addresses, phone numbers, barcodes, QR codes, payment links, identity numbers, insurance numbers, bank details, and medical information.
Then review only the redacted text I provide. Separate:
1. Observable details: company name shown, amount, due date, services listed, dates of service, payment methods, contact information printed on the bill, and any collection or penalty language.
2. Warning signs: urgency, threats, unfamiliar company, unusual payment method, suspicious links, secrecy requests, mismatched dates, vague services, or pressure to pay immediately.
3. Uncertain interpretations: what could be legitimate, mistaken, duplicated, or fraudulent.
Do not say the bill is real or fake. Create a verification plan using official contact information I find independently from a prior statement, official website, insurance card, benefits portal, or trusted records—not from the suspicious bill itself. Include questions I can ask a trusted family member, caregiver, billing office, or consumer-help resource before taking action.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: A redacted description of the bill, the amount, the apparent sender, the date received, and whether you recognize the service or purchase.
Expected output: A plain-language bill summary, a warning-sign list, a “do not pay yet” verification plan, and a short call script that avoids giving sensitive information unless you initiated contact through an official channel.
Verification checkpoint: Before paying, disputing, or ignoring the bill, compare it with your own records and contact the organization through a phone number or website you locate independently, or ask a trusted helper to sit with you while you verify.
Prompt 11: Subscription charge you do not recognize
Purpose: Use this prompt for a bank, credit-card, app-store, cable, streaming, security-software, or membership charge that you do not remember approving. The aim is to sort likely explanations from warning signs without sharing card data.
Copy-paste prompt:
I found a subscription or recurring charge I do not recognize. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Help me review it without exposing sensitive information.
Tell me what to redact before I paste anything: full card numbers, bank account numbers, transaction IDs that could expose my account, addresses, phone numbers, email addresses, usernames, and screenshots with personal details.
Using only the redacted information I provide, separate:
1. Observable details: merchant name as displayed, amount, date, frequency, payment source type, and any description text.
2. Warning signs: unfamiliar merchant, changing amounts, free-trial conversion, duplicate billing, foreign transaction wording, refund pressure, suspicious cancellation links, or messages asking for secrecy or codes.
3. Uncertain interpretations: renamed merchant, household member purchase, bundled service, annual renewal, trial ending, or possible unauthorized charge.
Do not decide whether it is fraud. Make a step-by-step verification plan: check receipts, app subscriptions, email confirmations, household purchases, and official account portals reached independently. If the charge may be unauthorized, suggest contacting the bank or card issuer using the number on the card or a verified statement, not a link or phone number from an unexpected message.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted merchant descriptor, amount, date, recurrence pattern, and whether anyone in the household may have signed up.
Expected output: A checklist of likely explanations, warning signs, and safe next steps for cancellation, dispute preparation, or household verification.
Verification checkpoint: Do not enter card details into a cancellation page from an email or text; use the official app, statement, or card issuer contact path you already trust.
Prompt 12: Insurance or benefit notice without professional advice
Purpose: Use this prompt for confusing notices about insurance, Medicare-related mail, Social Security-related letters, pension communications, pharmacy benefits, housing assistance, or other benefits. It must summarize and prepare questions, not give legal, tax, medical, insurance, or financial advice.
Copy-paste prompt:
I received an insurance or benefit notice and need help understanding the wording. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not provide legal, tax, medical, insurance, or financial advice.
Before I share redacted text, list what to remove: full name, address, birth date, claim number, policy number, Medicare or insurance ID, Social Security number, income details, medical diagnoses, prescription details, banking information, QR codes, and barcodes.
After I provide redacted text, separate:
1. Observable details: agency or company name shown, notice date, deadline, requested action, benefit or policy mentioned, and appeal or contact language.
2. Warning signs: urgent threats, secrecy, payment demand, request for identity numbers, suspicious links, unofficial-looking sender, or pressure to switch plans immediately.
3. Uncertain interpretations: routine notice, renewal, denial, missing documentation, marketing mail, or possible scam.
Translate the notice into plain English. Make a question list for a licensed adviser, benefits counselor, official agency, plan administrator, or trusted helper. Remind me to find official contact information independently, not from a suspicious notice.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted notice text, type of benefit or insurance, deadline shown, and whether it came by mail, email, text, or portal message.
Expected output: A plain-English summary, a deadline table, a list of documents to gather, and questions to ask an official representative or qualified adviser.
Verification checkpoint: Confirm deadlines and required documents through an official portal, prior verified paperwork, or a qualified benefits counselor before sending forms, money, or identity information.
Prompt 13: Travel itinerary consistency check
Purpose: Use this prompt when reviewing flights, trains, hotels, cruises, rental cars, tours, or family-trip plans. It checks for contradictions such as impossible connection times, date mismatches, wrong airports, overnight gaps, and accessibility conflicts.
Copy-paste prompt:
I want to review a travel itinerary for consistency. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not book, cancel, or change anything for me.
Tell me what to redact before sharing: reservation numbers, ticket numbers, loyalty numbers, full names, birth dates, passport information, addresses, phone numbers, payment details, and medical or mobility information unless I summarize it generally.
Using my redacted itinerary, separate:
1. Observable details: dates, times, cities, airports or stations, hotel nights, check-in and check-out dates, transportation segments, and confirmation-source labels.
2. Warning signs: mismatched dates, too-short connections, arrival after hotel check-in issues, different airports in the same city, missing return trip, duplicate bookings, unusual payment instructions, or links in unexpected messages.
3. Uncertain interpretations: time-zone issue, overnight flight, schedule change, pending reservation, or formatting confusion.
Create a consistency checklist and questions I should answer before travel. Recommend confirmation through official airline, hotel, rail, cruise, or agency channels that I reach independently.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted itinerary details, destination, dates, transportation modes, lodging dates, and any general mobility or timing needs.
Expected output: A timeline, mismatch list, questions to resolve, and a pre-trip verification checklist.
Verification checkpoint: Before making payments or changes, compare the itinerary with official booking accounts or call numbers obtained independently from the airline, hotel, travel provider, or previous trusted records.
Prompt 14: Hotel or airline verification plan
Purpose: Use this prompt after receiving a schedule-change message, cancellation notice, upgrade offer, hotel-payment request, baggage-fee demand, or “confirm your reservation” message. The prompt builds a safe plan for checking the booking without using the message’s links.
Copy-paste prompt:
I received a hotel or airline message and need a safe verification plan. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not change, cancel, or confirm travel for me.
Tell me what to redact: confirmation codes, ticket numbers, loyalty numbers, full names, contact details, payment information, passport details, and QR codes.
Review the redacted message and separate:
1. Observable details: company name shown, flight or hotel name, date, claimed issue, requested action, deadline, and contact method provided.
2. Warning signs: urgent payment, threat of cancellation, suspicious link, request for codes, unusual payment method, secrecy, grammar oddities, mismatched booking details, or sender address mismatch.
3. Uncertain interpretations: legitimate schedule change, marketing upgrade, phishing attempt, third-party booking confusion, or hotel policy notice.
Build a verification plan that starts from official sources I find independently: airline app, hotel website typed manually, prior booking confirmation, travel agent contact already known, or phone number from the back of a membership card. Include a short script for asking, “Is there any action required on my reservation?” without volunteering extra personal information.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted message text, travel date, provider name, and whether you already have a booking with that provider.
Expected output: A ranked verification checklist, warning signs, and a safe phone or portal script.
Verification checkpoint: Treat any message that demands immediate payment, password reset, or one-time code as unverified until the travel provider confirms it through an official channel you reached yourself.
Prompt 15: Accessible-trip checklist
Purpose: Use this prompt to plan a trip around mobility, hearing, vision, medication timing, rest breaks, dietary needs, caregiver coordination, or other accessibility requirements. It helps prepare questions and checklists; it does not provide medical advice.
Copy-paste prompt:
I am planning a trip and want an accessibility checklist. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not provide medical advice or make reservations for me.
Tell me what to redact or summarize generally: medical diagnoses, prescription numbers, insurance IDs, full address, exact birth date, passport details, payment information, and emergency contacts. I can describe needs in general terms, such as “uses a cane,” “needs elevator access,” or “needs quiet rest breaks.”
Using my general trip description, separate:
1. Observable details: destination, dates, transportation modes, lodging type, planned activities, walking distances, stairs, transfers, and appointment times.
2. Warning signs: no elevator confirmation, tight connections, long walks, unclear bathroom access, late-night arrivals, inaccessible shuttle, medication timing conflict, or unclear emergency plan.
3. Uncertain interpretations: availability depends on provider confirmation, local conditions, weather, staffing, or equipment.
Create a checklist of questions for airlines, hotels, tour operators, family helpers, and medical professionals if needed. Remind me to confirm accessibility directly through official provider channels before paying or traveling.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: General destination, travel dates, transportation, lodging, activities, and accessibility needs stated without sensitive medical details.
Expected output: A practical checklist covering transportation, lodging, medication logistics, rest time, documents, emergency contacts, and provider questions.
Verification checkpoint: Confirm accessibility services directly with each provider and ask a trusted helper to review the plan before final payment or departure.
Prompt 16: Online-shopping comparison
Purpose: Use this prompt before buying a product online, especially when a discount looks unusually large, a seller is unfamiliar, or the product affects health, safety, mobility, home security, or finances.
Copy-paste prompt:
I am comparing online-shopping options and want to avoid rushed decisions. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not buy anything for me.
Tell me what to redact: account names, addresses, order numbers, payment details, personal photos, medical needs, and private messages with sellers.
Using the redacted product descriptions I provide, separate:
1. Observable details: product name, seller name, price, shipping cost, return policy, warranty language, delivery estimate, ratings shown, and payment methods.
2. Warning signs: price far below other sellers, pressure countdown, no return address, vague warranty, off-platform payment, suspicious links, copied photos, poor seller history, secrecy, or requests for extra personal information.
3. Uncertain interpretations: clearance sale, refurbished item, third-party seller, international shipping, marketplace listing, or incomplete product description.
Make a comparison table with pros, cons, unanswered questions, and safer alternatives for verification. Remind me to use official retailer sites or trusted marketplaces reached independently and to ask a trusted person before buying expensive, medical, or safety-related items.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted product descriptions, prices, seller names, return policies, and why you are considering the item.
Expected output: A comparison table, missing-information list, risk notes, and a “wait before buying” checklist.
Verification checkpoint: Do not purchase from a link in a suspicious message; independently visit the retailer or marketplace, review return rules, and confirm with a trusted helper for costly or consequential purchases.
Prompt 17: Marketplace seller warning signs
Purpose: Use this prompt for person-to-person marketplace listings, local pickup offers, rental listings, used cars, tickets, collectibles, equipment, or furniture sales. It focuses on seller behavior and transaction safety without arranging the deal.
Copy-paste prompt:
I am reviewing a marketplace seller or listing. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not contact the seller, negotiate, reserve, or pay for me.
Tell me what to redact: my full name, address, phone number, email, payment app details, pickup location, license plate, identification, order numbers, and private family information.
After I paste redacted listing text or messages, separate:
1. Observable details: item, price, location area, seller claims, payment request, pickup or shipping terms, photos described, and timeline.
2. Warning signs: off-platform payment, deposit pressure, courier story, overpayment, secrecy, refusal to meet safely, changing terms, too-good-to-be-true price, request for codes, request for ID photos, or suspicious links.
3. Uncertain interpretations: motivated seller, limited availability, legitimate shipping, incomplete listing, or misunderstanding.
Create a safety checklist: verify comparable prices, keep communication on the platform when possible, avoid advance payment to unknown sellers, choose safe public pickup practices if appropriate, and ask a trusted person to review before committing. Do not tell me the seller is safe.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted listing text, item type, asking price, seller messages, payment request, and whether pickup or shipping is proposed.
Expected output: A warning-sign assessment, comparison questions, and a safe-decision checklist.
Verification checkpoint: Pause if the seller asks for secrecy, codes, deposits, payment outside the platform, or identity documents; consult a trusted person before continuing.
Prompt 18: Account-recovery checklist
Purpose: Use this prompt when you cannot access an email, bank, social media, shopping, travel, utility, or benefits account, or when you receive a password-reset message you did not request. It prepares safe recovery steps without asking for secrets.
Copy-paste prompt:
I need help making a safe account-recovery checklist. Safety contract: Do not click links, contact senders, make payments, disclose passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets. Do not try to recover the account for me, guess passwords, or tell me to share codes.
Tell me what to redact: usernames if identifying, email addresses, phone numbers, recovery codes, one-time codes, security questions, account numbers, card details, identity documents, and screenshots showing personal data.
Using only my redacted description, separate:
1. Observable details: account type, what changed, error wording, date noticed, unexpected messages, devices involved, and whether money or personal data may be affected.
2. Warning signs: reset message I did not request, urgent warning, suspicious link, request for one-time code, changed recovery contact, unfamiliar login alert, secrecy, or pressure to pay for support.
3. Uncertain interpretations: forgotten password, expired session, service outage, device issue, mistyped address, legitimate security alert, or possible account takeover.
Create a recovery checklist that starts from the official app or website I reach independently, not from an unexpected message. Include when to ask a trusted helper, when to contact the provider through verified support, and when to consider freezing payments or cards only after confirming through the official institution.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs: Redacted account type, what you observed, date noticed, whether any money or private data may be involved, and whether you received unexpected reset messages.
Expected output: A safe recovery checklist, warning signs, evidence to save, and a trusted-helper plan.
Verification checkpoint: Never share a password, one-time code, recovery code, or remote-access permission with anyone who contacts you unexpectedly; use only official recovery pages or support contacts you locate independently.
Prompts 19–25: Privacy, Passwords, Updates, Family Confirmation, Hobbies, Appointments, and Final Decisions
OpenAI describes older-adult AI literacy as practical help with everyday tasks such as confusing bills, trip planning, scam awareness, hobbies, and family connection; OpenAI also reports that its Academy and Older Adults Technology Services from AARP announced free in-person ChatGPT workshops for 1,000 older adults across 10 U.S. cities, and that the U.S. share of ChatGPT messages associated with people aged 55 and older grew from 6% to nearly 10% in one year. Treat those claims as OpenAI-published context, not as proof that ChatGPT can determine whether a message, bill, website, or caller is legitimate.
The operating rule for the final seven prompts is simple: ask ChatGPT to slow the situation down, organize observable facts, list warning signs, identify what to redact, and prepare independent verification steps. Do not ask it to decide for you, contact anyone, open links, make payments, change passwords, give medical advice, or replace a trusted helper, official source, clinician, lawyer, insurer, bank, or government office.
The article offers ChatGPT prompts for vacation planning, including help crafting travel itineraries and planning getaways. The 99+ Innovative ChatGPT Prompts for Vacation Planning to C… article is a focused companion for Travel Planning with ChatGPT because it directly matches the travel-planning use case in the current article and gives readers more prompt examples for organizing trips.
Prompt 19: Privacy redaction before asking for help
Purpose
Use this prompt before pasting a message, bill, letter, travel document, or notice into ChatGPT. It helps the user remove personal, financial, medical, and authentication details while keeping enough context for a safe review.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
I want help redacting a message before I ask you to review it. Do not click links, contact senders, make payments, or ask me to reveal passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets.
Create a redaction checklist for this type of document: [text message / email / bill / medical appointment note / travel itinerary / account notice / other]. Tell me what to remove or replace with labels such as [NAME], [PHONE], [ACCOUNT LAST 4], [DATE], [CITY], or [AMOUNT]. Separate observable warning signs from uncertain interpretations. After redaction, remind me to verify any important action through a trusted person or an official phone number or website found independently, not through the suspicious message.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The document type, not the full private document.
- A short description of the concern, such as “unexpected bill” or “urgent account warning.”
- Whether the document involves money, travel, health, government benefits, or account access.
Expected output
ChatGPT should return a redaction checklist, safe placeholder examples, and a reminder that the redacted version should still omit credentials, full account numbers, medical details, and authentication codes.
Verification checkpoint
Before pasting anything, read the redacted text out loud or show it to a trusted helper and confirm that no password, one-time code, full identity number, full bank detail, or unnecessary medical detail remains.
Prompt 20: Password-manager conversation without sharing credentials
Purpose
This prompt helps someone discuss password managers without revealing actual passwords, reset codes, recovery phrases, or account-security answers. It is useful when a family member, librarian, or community educator is explaining safer account habits.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
Help me prepare a safe conversation about using a password manager. Do not ask me to type any real password, one-time code, recovery phrase, security answer, identity number, bank detail, medical data, or authentication secret. Do not click links, contact companies, or make changes for me.
Explain what a password manager is in plain language, what questions I should ask a trusted helper, and what warning signs would make a password-related message suspicious. Separate observable warning signs from uncertain interpretations. Identify what information I should redact if I later ask for help. Tell me to confirm account changes only through an official website or phone number I find independently, not through a message I received.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The user’s goal, such as “learn the basics,” “prepare for a library class,” or “ask my adult child for help.”
- The device type, such as phone, tablet, laptop, or desktop.
- Whether the user wants a beginner explanation or a checklist for a helper conversation.
Expected output
The response should provide a plain-language explanation, a no-secrets checklist, and questions to ask a trusted helper, such as who can access the vault, what happens if the device is lost, and how account recovery works.
Verification checkpoint
Do not enter or dictate any real password, recovery phrase, or one-time code during the conversation. If a helper asks for those details, pause and confirm whether the request is necessary through a second trusted person or the service’s official support guidance.
Prompt 21: Software-update verification without using suspicious links
Purpose
This prompt helps review a message claiming that a phone, browser, bank app, antivirus product, streaming service, or government portal needs an immediate update. The goal is to avoid installing software from a link in a suspicious message.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
I received a message saying I must update software or my account/device will be locked. Do not click links, download anything, contact the sender, make payments, or ask for passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets.
Help me review the message safely. Separate observable warning signs, such as urgency, secrecy, threatening language, unusual sender address, attachments, or suspicious links, from uncertain interpretations. Identify what I should redact before sharing the text. Give me a step-by-step plan to verify updates through the device settings, app store, or official website found independently, not through the message.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- A redacted version of the update message.
- The general device type and app category, without account credentials.
- Whether the message arrived by text, email, pop-up, phone call, or social media.
Expected output
ChatGPT should list warning signs, identify missing context, and produce a verification plan that uses normal update paths such as device settings or the known app store rather than links in the message.
Verification checkpoint
Before installing anything, confirm the update through the device’s built-in update screen, the app store, or a trusted helper. If the message asks for payment, secrecy, remote access, or a one-time code, stop and verify through an official channel.
Prompt 22: Family confirmation script for urgent requests
Purpose
This prompt creates a calm script for checking whether an urgent request from a supposed child, grandchild, friend, caregiver, employer, or official is real. It is designed for situations involving secrecy, distress, emergency travel, bail, hospital bills, replacement phones, gift cards, wire transfers, or payment apps.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
Help me create a family confirmation script for an urgent request I received. Do not click links, contact the sender, make payments, or ask me to reveal passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets.
The request says: [paste a redacted summary, not private details]. Separate observable warning signs from uncertain interpretations. Identify anything else I should redact. Write a short script I can use to contact the person through a phone number I already know or another trusted family member, not through the message. Include a pause-think-ask checklist before any money, account access, travel booking, or private information is shared.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- A redacted summary of the request.
- The claimed identity of the sender, such as “grandchild” or “bank employee.”
- The requested action, such as “send money,” “keep secret,” “buy cards,” or “share a code.”
Expected output
The response should provide a short phone script, a text-message script, a list of warning signs, and a verification path through known contacts rather than the suspicious message thread.
Verification checkpoint
Use a phone number already saved in your contacts, a family emergency list, or another trusted person. If the request says not to tell anyone, treat secrecy as a major warning sign and pause before responding.
Prompt 23: Hobby-research source check
Purpose
This prompt helps older adults explore hobbies such as genealogy, gardening, photography, travel history, crafts, cooking, local clubs, collectibles, or online classes while checking whether claims, vendors, or communities deserve more verification.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
I am researching a hobby and want help checking sources safely. Do not click links, join groups, contact sellers, make payments, or ask me to reveal passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets.
My hobby topic is: [topic]. The claim, class, group, product, or source I want to review is: [redacted description]. Separate observable warning signs from uncertain interpretations. Identify what I should redact before sharing more. Give me a checklist for comparing sources, checking dates, looking for independent confirmation, and asking a trusted person or official organization before I pay, sign up, travel, or share private information.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The hobby topic and type of source, such as article, class, group, seller, event, or product.
- A redacted description of the claim or offer.
- Whether payment, travel, personal contact, or account creation is involved.
Expected output
ChatGPT should produce a source-check checklist, questions to ask, warning signs such as pressure pricing or secrecy, and neutral language for asking a club, library, instructor, or family helper to review the opportunity.
Verification checkpoint
Before paying for a class, joining a private group, booking travel, or meeting someone, verify the organization through independent sources such as a library, community center, known club, official venue, or trusted local contact.
Prompt 24: Appointment-question preparation without medical advice
Purpose
This prompt helps prepare questions for a doctor, pharmacist, benefits office, repair appointment, tax preparer, lawyer, insurance representative, or service provider without asking ChatGPT to diagnose, prescribe, interpret private records, or make professional decisions.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
Help me prepare questions for an appointment. Do not give medical, legal, tax, insurance, or financial advice. Do not click links, contact the office, make payments, or ask me to reveal passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets.
The appointment type is: [medical / pharmacy / benefits / insurance / legal / tax / repair / other]. My general concern is: [brief non-sensitive summary]. Separate observable facts from uncertain interpretations. Identify what information I should redact before sharing. Create a short list of questions I can ask the professional, plus a reminder to confirm instructions through the official office or a trusted helper before making consequential decisions.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- The appointment category.
- A brief, non-sensitive summary of the topic.
- The user’s practical goal, such as “understand a letter,” “prepare questions,” or “bring the right documents.”
Expected output
The response should create a respectful question list, a document-preparation checklist, and a reminder that ChatGPT is not replacing the licensed professional, office staff, insurer, government agency, or legal adviser.
Verification checkpoint
Bring the question list to the appointment and let the professional answer. Do not paste detailed medical records, full benefit numbers, full insurance IDs, tax identifiers, or legal documents into ChatGPT unless you have intentionally redacted them and understand the privacy risk.
Prompt 25: Pause-think-ask decision review
Purpose
This final prompt is for any moment when the user feels rushed, confused, embarrassed, frightened, excited by an offer, or pressured to act alone. It turns OpenAI’s pause-think-ask scam-education framing into a repeatable decision review.
Shared safety contract: ChatGPT must not click links, contact senders, make payments, request or display passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets, and must require trusted-person or official-channel verification before action.
Copy-paste prompt
Help me pause, think, and ask before I act. Do not click links, contact anyone, make payments, or ask me to reveal passwords, one-time codes, identity numbers, bank details, medical data, or authentication secrets.
Situation summary: [redacted summary]. Requested action: [pay / click / call / reply / download / travel / share information / change account / other]. Deadline or pressure: [what they said]. Separate observable warning signs from uncertain interpretations. Identify what else should be redacted. Give me a decision checklist that includes: stop for now, verify through official channels found independently, ask a trusted person, and avoid acting through links or phone numbers in the suspicious message.
Safety contract: Do not click links, open attachments, contact the sender, make payments, or disclose passwords, one-time codes, identity numbers, bank details, or medical data. Separate observable warning signs from uncertain interpretations and state that you cannot authenticate the sender or declare the content safe. Tell me what to redact. Find contact details independently through an official website or official phone number, and have a trusted person review the situation before any action.
Required inputs
- A redacted summary of the situation.
- The action being requested.
- The deadline, threat, reward, secrecy instruction, or emotional pressure involved.
Expected output
ChatGPT should produce a pause-think-ask checklist, a warning-sign table, a trusted-contact plan, and a clear “do not act yet” recommendation when the situation involves urgent money, private data, account access, downloads, secrecy, or unfamiliar links.
Verification checkpoint
Before taking any consequential step, speak with a trusted person or use an official contact method found independently. If money has already been sent or credentials have already been shared, contact the bank, account provider, or appropriate official support channel directly; do not rely on ChatGPT to recover funds or resolve the incident.
Safe-use guidance for helpers, classes, and one-on-one support
Caregivers, librarians, senior-center instructors, and family helpers should treat ChatGPT as a conversation aid, not as the authority in the room. The helper’s job is to protect autonomy while reducing risk: let the older adult read the message, choose whether to proceed, decide who they trust, and confirm through official channels before any payment, account change, travel change, medical step, legal step, or financial decision.
OpenAI’s safety best-practices guidance emphasizes defense in depth, human review for consequential outputs, clear limitation communication, privacy-preserving identifiers where appropriate, and original evidence for reviewers who must verify a model-produced summary or decision. In everyday digital-literacy settings, the matching practice is to keep the original message available for human review, use redacted text with ChatGPT, and avoid treating the model’s summary as proof that a message is safe or unsafe.
| Facilitation step | Practical action | Do not do this |
|---|---|---|
| Start with consent | Ask whether the person wants help reading, redacting, or planning verification. | Do not take the device, reply to the sender, or make decisions without permission. |
| Redact first | Remove passwords, codes, full account numbers, identity numbers, addresses, medical details, and bank details before prompting. | Do not paste screenshots or full documents that contain unnecessary private information. |
| Identify pressure | Look for urgency, secrecy, threats, suspicious links, unfamiliar attachments, emotional manipulation, or payment demands. | Do not assume that polished writing, logos, caller ID, or personal details prove legitimacy. |
| Verify independently | Find the official phone number, app, office, or website using a saved contact, printed statement, known bookmark, device settings, or trusted organization. | Do not use contact details, links, QR codes, or attachments inside the suspicious message. |
| Escalate consequential actions | Require human confirmation before payments, account recovery, credential changes, travel changes, medical decisions, legal choices, or insurance actions. | Do not let ChatGPT authorize, automate, or pressure a consequential decision. |
A safe class exercise is to use fictionalized or heavily redacted messages that preserve warning signs without exposing real private data. For example, replace the sender, recipient, account number, phone number, address, and payment amount with placeholders, then ask ChatGPT to identify urgency, secrecy, suspicious-link language, missing context, and independent verification steps.
A safe one-on-one support script is: “Let’s not click anything yet. Let’s remove private details, ask ChatGPT to help us make a checklist, and then verify through a phone number or website we find separately.” This preserves the older adult’s control while making the pause-think-ask habit concrete.
If a person has already shared a password, one-time code, payment-card number, bank detail, identity number, or medical account access, stop using the suspicious conversation thread and move to official support. OpenAI’s API safety guidance notes that exposed or misused credentials should be revoked and replaced promptly; in consumer settings, that means contacting the relevant account provider, bank, or official support channel directly rather than waiting for an AI-generated assessment.
Access 40,000+ AI Prompts for ChatGPT, Claude & Codex — Free!
Get instant access to our complete Notion Prompt Library — the largest curated collection of prompts for ChatGPT, Claude, OpenAI Codex, and other leading AI models. Optimized for real-world workflows across coding, research, content creation, and business.
