PrivacyScrubber — PII Redaction for AI Chats



Overview
Mask PII & redact sensitive data locally before AI chats. Anonymize names, secrets & files in browser RAM with zero server egress.
Redact sensitive data, confidential records, and personal identifiable information (PII) before sending prompts to generative AI assistants. PrivacyScrubber automatically masks names, emails, national IDs, medical records, financial figures, API keys, and developer secrets — 100% locally inside your browser's Random Access Memory (RAM). No external servers. No cloud proxies. Zero prompt data ever leaves your device. Your daily prompts often contain sensitive information: client names, customer emails, payroll numbers, patient medical records, or internal API tokens. Pasting unmasked text into third-party AI interfaces exposes confidential data to external servers, cloud logging, and potential training ingestion. PrivacyScrubber intercepts sensitive text directly at the browser input layer, replacing confidential details with safe surrogate tokens (such as [NAME_1], [EMAIL_1]) before submission. When the AI returns its response, click Restore to rehydrate the original values locally in one click. Free to use. No account required. Verified operational offline in Airplane Mode. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ COMPATIBILITY & SUPPORTED INTERFACES ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PrivacyScrubber provides an integrated in-page Shield HUD compatible with major web AI chat tools and enterprise web forms: • Web AI Chat Assistants: Direct in-page Shield integration with leading web-based conversational AI assistants. • Enterprise Helpdesk: Direct support for customer support ticketing and composer forms. • Universal Web Popover: Redact text and mask sensitive data on any web page, CRM, or form via keyboard shortcut (Alt+Shift+X). ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ NEW IN V2.2.6: LOCAL DOCUMENT SANITIZATION ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ • Drag & Drop File Sanitization: Drop PDF, DOCX, and TXT documents directly into supported AI chats. • 100% Client-Side Parsing: Document extraction and PII masking occur entirely inside local browser memory via WebAssembly. • Zero Cloud Upload: Your raw files are never uploaded to any third-party conversion server. • Handles files up to 25MB locally with instant token substitution. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ WHAT PRIVACY SCRUBBER REDACTS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PrivacyScrubber automatically detects and sanitizes sensitive data entities: • Personal Contact Details: Full names, personal and work emails, international phone numbers, and physical addresses. • Government & National Identification: Social security numbers, tax identification numbers, driver's licenses, and passport credentials across major jurisdictions. • Healthcare & Medical Records: HIPAA Safe Harbor identifiers including medical record numbers (MRN), patient IDs, treatment dates, and clinical notes. • Financial & Payment Information: Credit and debit card numbers (with Luhn validation), bank accounts, IBANs, routing numbers, and compensation figures. • Software Credentials & Secrets: Cloud API keys, authorization tokens, private encryption keys, database connection strings, and administrative credentials. • Legal & Confidential Documents: Attorney-client privilege designations, case codes, settlement amounts, and internal ticket references. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ HOW IT WORKS: 3-STEP ZERO-TRUST WORKFLOW ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1. Enter Your Prompt or Drop a File: Type or paste your prompt into any supported AI chat interface, or drag a PDF/DOCX file into the chat box. 2. 1-Click Shield Protection: Click the PrivacyScrubber shield button (or press Alt+Shift+X). Sensitive entities are instantly replaced with surrogate tokens ([NAME_1], [EMAIL_1]). 3. Safe Ingestion & 1-Click Reveal: Submit the sanitized prompt. When the AI responds with surrogate tokens, click Reveal to restore the original cleartext locally in RAM. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SPECIALIZED DETECTION RULESETS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ In addition to universal personal data masking, PrivacyScrubber includes specialized rulesets tailored for regulated professional workflows: • Clinical & Healthcare: De-identifies patient records and research summaries according to HIPAA Safe Harbor standards. • Financial Services & Accounting: Protects account numbers, audit workpapers, and tax document structures. • Legal & Compliance: Preserves attorney-client privilege in case files and sanitizes commercial contract terms. • Human Resources: Redacts candidate personal data from resumes to support unbiased hiring reviews. • Engineering & DevOps: Detects accidental inclusion of infrastructure keys, system tokens, and server configurations. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ WHY CLIENT-SIDE LOCAL PROCESSING (ZTDS™) MATTERS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Unlike cloud-based security proxies or enterprise DLP gateways that route your confidential data through external third-party servers (introducing network latency and subprocessor compliance risks), PrivacyScrubber operates entirely on your device: • In-Browser RAM Execution: All redaction and unmasking happen inside your local browser memory. • Zero Server Egress: 0 bytes of prompt text or file contents are ever transmitted to PrivacyScrubber or external networks. • Airplane Mode Verified: Disconnect your internet connection and verify that PII masking continues to operate 100% offline. • Tab-Isolated Volatile Memory: Session maps exist only in volatile RAM and are automatically destroyed when the browser tab closes. • Zero Account, Zero Logging: No registration, no login, no tracking cookies, and no prompt storage. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ENTERPRISE COLLABORATION & AUDIT COMPLIANCE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ • Cryptographic Team Handoff: Collaborate on sanitized prompts across team members using peer-to-peer end-to-end encrypted session tokens (XChaCha20-Poly1305 + Argon2id). • CISO Audit Receipts: Generate downloadable PDF audit certificates with SHA-256 session digests to prove compliance with SOC 2, HIPAA, GDPR, and ISO 27001 requirements. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PROPRIETARY INTELLECTUAL PROPERTY & PATENTS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PrivacyScrubber's Zero-Trust Data Sanitization (ZTDS™) technology is protected under statutory intellectual property filings: • Registered Word Mark: ZTDS™ (State of Israel Patent & Trademark Office, Order #182655957, Nice Classes 9 & 42, Paris Convention priority locked). • Patent Application: State of Israel Ministry of Justice, Patent Office (ILPO), Application #331905 (Tracking ID: 94221, Paris Convention Art. 4 & 35 U.S.C. § 119 Priority). • Invention Title: SYSTEM AND METHOD FOR CLIENT-SIDE ZERO-TRUST DATA SANITIZATION AND CRYPTOGRAPHIC SESSION HANDOFF IN ARTIFICIAL INTELLIGENCE WORKFLOWS. • Virtual Patent Marking: https://privacyscrubber.com/patents/ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PEER-REVIEWED SCIENTIFIC RESEARCH ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ The ZTDS standard and its in-memory architecture are grounded in published academic research: • CERN / Zenodo: DOI 10.5281/zenodo.22058770 (ZTDS Protocol & Architectural Elimination of Cloud Egress) • OSF (Center for Open Science): DOI 10.17605/OSF.IO/5BYJF (Empirical Latency & RAM Profiling) • SSRN (Elsevier): SSRN ID 7335581 (Enterprise AI Governance & EU AI Act Article 10 Compliance) • Law Archive / OSF: ID 4wc86 (Preserving Attorney-Client Privilege in AI Workflows) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ KEYBOARD SHORTCUTS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ • Alt + Shift + P — Open PrivacyScrubber extension popup • Alt + Shift + X — Redact selected text and copy sanitized tokens to clipboard ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ FREQUENTLY ASKED QUESTIONS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Q: Can AI models see my real data if I use PrivacyScrubber? A: No. PrivacyScrubber replaces your real names, numbers, emails, and secrets with surrogate tokens ([NAME_1], [PHONE_1]) before the prompt is sent over the network. The AI model only receives the sanitized tokens. Q: Does PrivacyScrubber send my data to its own servers? A: Never. PrivacyScrubber operates with zero server infrastructure for prompt processing. All regex matching, parsing, and tokenization occur locally in your browser's RAM. You can disconnect your network (Airplane Mode) and confirm that sanitization works completely offline. Q: How do I restore the original values after the AI responds? A: When the AI model replies using the surrogate tokens, click the Reveal button in the chat interface. PrivacyScrubber matches the tokens back to your local session map and rehydrates the original text instantly in your browser. Q: What file types are supported for local sanitization? A: PrivacyScrubber supports local parsing and sanitization for PDF (.pdf), Word (.docx), and plain text (.txt) files up to 25MB directly in your browser. Q: Is PrivacyScrubber free? A: Yes. The General Profile is free to use with generous character limits and universal PII detection. PRO unlocks all 30 specialized industry profiles, batch file processing, custom regex rules, and offline OCR parsing. TEAMS enables organization-wide encrypted session sharing and team governance. PrivacyScrubber is an independent privacy and data protection tool developed under the Zero-Trust Data Sanitization (ZTDS) standard. All product names, logos, and brands mentioned are the property of their respective owners. Mention of any third-party services is strictly for descriptive identification of compatibility and does not imply affiliation, sponsorship, or endorsement. Protect your data at the source before sending prompts to AI.
5 out of 54 ratings
Details
- Version2.2.6
- UpdatedSeptember 30, 2026
- Size7.01MiB
- LanguagesEnglish
- DeveloperWebsite
Email
ilsimox@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site