Free · Browser-based · No account needed
Prompt redaction, before you share.
Remove sensitive details from your AI prompts with local prompt redaction. Paste your text, review the highlights, and copy a version with detected details replaced by labels. Your text stays on your device.
What we look for: names, companies, locations, addresses, job titles, emails, phone numbers, URLs, dates, account numbers and secrets. AI detection is supported by rules for IP addresses, IBANs, payment cards and SSNs in context.
Review every result: detection can miss details, especially unusual names and aliases. Coverage and device requirements
0 / 12,000 characters
Redacted prompt
A little privacy, before you paste.
Load the model and scan your text to see detected details and a redacted version.
Load once. Redact on your device.
About 1.13 GB on first use, cached for next time. Downloads start only when you click Load models. Requires WebGPU.
Further info
How prompt redaction works, what it covers, and what your device needs.
How are sensitive details detected?
OpenAI Privacy Filter identifies personal details and secrets. GLiNER PII Edge adds company names and other entities. Local rules check structured details, including IBAN and payment-card checksums. Overlapping detections are combined. Hover or tap a highlight to see which detector caught it.
What should I review before sharing a prompt?
Check both the original and redacted prompt. Automated detection can miss details or remove too much; it does not guarantee anonymity. These models are English-focused. German text can be scanned, but German accuracy has not been validated. Each scan accepts up to 12,000 characters, subject to a 4,096-token limit.
Does prompt redaction send my text to a server?
This tool processes text in your browser, without an account or API key. It does not send or save your text and has no analytics. Model files download from Hugging Face when you choose to load them. After loading, you can redact offline. The network monitor below shows requests observed by this page and its worker.
When do highlights appear, and what stays on my device?
Pasted text is scanned automatically once the models are ready. After editing, use Scan for sensitive details to refresh the result. Clear removes text from the page; Unload releases the models. Downloaded model files may remain in your browser cache for reuse.
Memory before you start
An estimated working budget for redacting typical passages of around 1,000 tokens.
Checking WebGPU…
Estimated requirement
≈ 6.5 GiB
Planning estimate, available before download. Longer passages can need more. Your device marker shows total RAM, not free GPU memory.
What’s included in the estimate
The model segments use the 0.85 GiB Privacy Filter weights and 0.17 GiB GLiNER PII Edge weights as baselines. The remaining allowance covers runtime, model copies, redaction buffers and headroom. We rounded the AI working budget to 4.5 GiB using local Privacy Filter tests around 1,000 tokens plus an unmeasured 0.5 GiB allowance for GLiNER PII Edge and added a separate 2 GiB allowance for the operating system, browser and other apps; this is an estimate, not a measured minimum or a guarantee for the full 4,096-token limit.
The browser reports rounded, sometimes capped system RAM. The checkmark means reported RAM exceeds the full 6.5 GiB estimate, including the system buffer. Busy computers can need more headroom, and dedicated GPU memory can differ. WebGPU does not report free GPU memory. Hover or tap your device marker for the detected specs.
The first download includes Privacy Filter and the 181 MB GLiNER PII Edge model, plus tokenizer files. The chart estimates working memory, including a buffer for other apps; download size is not total runtime memory.
Live network monitor
Request history & what this observes
Page: starting · Worker: starts with model
Received bytes not reported
No request entries yet. Observation is not fully available.
Observes HTTP fetch, XHR, beacon calls, and resource loads exposed by this page and its model worker. Setup and model downloads are separate from the scan phase. Some resource loads come from cache. Requests observed during a scan do not by themselves establish that text was sent.
This is an in-app observation, not a whole-device audit: WebSocket traffic, browser extensions, other tabs, and other apps are outside its scope. Received bytes are a measured lower bound for the displayed history; upload bytes are not measured.
For an independent check, inspect DevTools Network, or load the model first and run a scan offline.