It might be different for others, but for most sensitive data I'm privy to on a job (api keys, their users' personal data), my employer could or should already have access to all of that. I've removed the occasional screenshot that had a personal dev tool key or similar though. Typically all this should be covered by a contract with a client though; they shouldn't just be stealing API keys and whatnot from your screenshots...