BiVelio Shield — private prompts for ChatGPT & Claude
Overview
Use ChatGPT & Claude privately. Redacts your data locally before it leaves your browser, then restores it in the reply. Free.
Keep your private data out of the AI cloud — without changing how you work. BiVelio Shield sits between you and ChatGPT or Claude and removes sensitive information from the text you type on your own machine, before it leaves your browser (on a paid plan with a names gateway, each message also goes to that gateway first, with every value the extension detects already masked — see below). The AI provider receives placeholder tokens in place of those values — never the real ones — and the extension puts the real values back into the reply on screen, so your conversation reads normally. Verified end to end on both sites. On ChatGPT: a prompt carrying an email reaches the provider as a [BV:…] token, not the raw value — reload the thread and only the token was ever stored, and the reply shows your real values restored on screen. On Claude: the same round-trip was run on 2026-08-14 with a control in the same thread. IBANs, cards, national IDs and API keys run through the same engine and are covered by its test suite. What it protects (free, on-device, no signup): • Credit-card numbers (checksum-validated) • IBANs and bank details • National IDs — Spanish DNI/NIE/CIF, US SSN, and more • Emails and phone numbers — French numbers in their national format (06 12 34 56 78, also with dots or dashes, or run together after a label like Tél.), and Andorran numbers, too • API keys & secrets — OpenAI, AWS, GitHub, Stripe, Slack, and others • IP addresses • Postal addresses that name a street type (calle, carrer, rue, rua…) in Spanish, Catalan, French or Portuguese, and Spanish cadastral references • Passwords written in Spanish or Catalan, passport numbers, vehicle number plates and dates of birth, when a label names them — on the same line, on the line above or in a table's header row • Health, religious, biometric and genetic terms — a curated multilingual lexicon (GDPR Art. 9 special categories) • Your own confidential terms — client, matter or project names you add in the extension's options page. The list stays on your device, stored as you typed it (not encrypted), and is never sent Optional — "Redact on shape": turn it on to also hide mistyped IDs that fail their checksum. Off by default, and we tell you plainly it may over-redact things like order numbers or tracking codes — your choice. And even with it off: a checksum-valid identifier can occasionally swallow a word or two next to it, so the provider sees less of your sentence than you typed — never more. Honest about what it does NOT do — no dark patterns: • It does not remove people's names or general free-form text on its own, on any tier (no fixed shape to match), and an Art. 9 phrase written in wording its curated lexicon does not list will also pass. Names are looked for on one route only, and only for an organisation on a paid plan. With the Team plan that route comes with the plan: the address of the names service BiVelio operates arrives signed inside your organisation's own licence, so there is nothing to install and no URL to type, BiVelio acts as your organisation's processor under a data-processing agreement for it, and on Team an owner or an administrator can switch the layer off for everyone from the dashboard — while on Pro, and on any install whose gateway comes from the central managed policy, that policy takes precedence and the way off is to remove the address from it. On any paid plan your administrator can point the extension at a gateway of their own from that central managed policy. Either way the text of each message (up to 20,000 characters on Pro and 50,000 on Team, sent in pieces of up to 4,000 — and on Team also the text of an attachment, sent after the local redaction has replaced its identifiers) goes to that gateway before the local redaction runs — with the terms on your own or your organisation's confidential-terms list, and every value the extension detects on its own (identifiers, account and card numbers, contact details, secrets), first replaced by asterisks — and comes back as the positions of the personal data the gateway detects — names and places, and also contact details, identifiers, financial data, network addresses, secrets and GDPR Art. 9 special-category terms. In ChatGPT it also fires when you paste 1,000 characters or more into the chat box, at the moment of the paste, so a message you then decide not to send can still reach the gateway. It is a layer that reduces the leak of names and, measured, does not eliminate it (4.875%). A long message also meets a time limit: at the names service's measured speed, only about 45–75% of a 50,000-character message is checked for names before it runs out; the rest is sent without that check — still redacted locally — and a card says the message was not fully checked. With neither of those two the extension looks for names on no tier. • Voice / realtime mode is not protected. It redacts the text you type; a spoken turn in ChatGPT Advanced Voice or Claude voice travels over a separate live-audio connection it never sees — and a text tool cannot redact audio. Type, don't speak, when a turn carries sensitive data. • Claude's "Cowork" composer is not covered. The extension redacts Claude's normal chat send; Cowork posts to a different endpoint that it deliberately does not touch. Treat anything typed into Cowork as unprotected. • Files and attachments are inspected only on the Team tier. On the Free and Pro tiers the engine is text-only: an uploaded document, PDF, or a photographed passport is sent to the provider as-is, and a notice tells you when that happens. Team redacts them in your browser before they upload: text files, PDFs that have a text layer, and modern Word, Excel, PowerPoint and OpenDocument files. That includes the values typed into a PDF form's fields, OpenDocument files saved by LibreOffice, and an identifier split across several text cells of a table. Older pre-2007 binary Office documents cannot be read by any browser extension and are NOT redacted; nor are scans, photos, or documents with embedded objects. Those always ask before leaving unprotected. Redaction is not free of side effects: a PDF is rebuilt as text, so its images, charts and layout do not travel, and pictures inside Office files are blanked. A PDF page with little or no text — an image, a chart, or a scanned page, even one with a line of text stamped on it — is sent blank or nearly so, and the notice says so; a PDF in which most pages are like that is treated as a scan and asks you first. • If your organisation turns on the review before sending, a card lists what was detected in a message before it leaves, and you may keep a value of a kind your organisation allows: that value reaches the AI provider as you typed it. It is off unless your organisation turns it on. • Custom instructions and memory saved from the settings dialog are not redacted. Text you type in the composer is covered; text you save through ChatGPT's or Claude's own settings, memory or project-instruction screens travels on endpoints the extension does not intercept. Private by design: • 100% local on the free tier. No account, no sign-up, nothing sent to us. • Your data ↔ token map (the "vault") is stored encrypted on your device, with the key held only in memory — it is wiped when you close your browser, so old conversations de-identify themselves. • On the free tier it touches only the ChatGPT/Claude message endpoints — and Gemini's, if you switch Gemini on in the popup — and no other site. Paid plans add, to BiVelio: a licence check-in every 12 hours (the licence and a random device id, so a paid licence stays within its seats); an hourly report of value-free counts — what was protected, by kind, which sends were blocked or sent unprotected and the reason picked from a fixed list, stamped to the hour; and, only when a check-in comes back revoked, one request to privacy.bivelio.com for the current licence. Never your content. • If the extension is updated, disabled or removed while a chat tab is open, a message you send from that tab is not let out unredacted: it is held, and a card asks you to reload the tab. • On Claude, the first message of a new chat is sent a second time so the site can title the thread; that copy carries the same tokens as the message. Works with: • ChatGPT (OpenAI) — verified end to end on the live site • Claude (Anthropic) — verified end to end on the live site Available on Chrome, Edge, Brave, and other Chromium browsers today. Firefox and Safari coming soon. Free. Local. Yours.
5 out of 51 rating
Details
- Version0.10.1
- UpdatedOctober 6, 2026
- Size1.2MiB
- Languages11 languages
- DeveloperBiVelio IncWebsite
131 Continental Dr Ste 305 Newark, DE 19713 USEmail
support@bivelio.comPhone
+1 302-208-5841 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S149896199
Privacy
BiVelio Shield — private prompts for ChatGPT & Claude has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
BiVelio Shield — private prompts for ChatGPT & Claude handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site