Redact PII before sending prompts, code, or documents to ChatGPT, Claude, Gemini or any LLM

Automatically sanitize sensitive prompts containing John Doe before sending to AI.

Everything is processed 100% locally in RAM — zero data ever leaves your device.

Privacy Scrubber protects sensitive personal data, confidential files, and corporate PII via web app, Chrome Extension (Client-Side AI Gateway), MCP, or SDK.

Data lives strictly in temporary RAM and is automatically deleted on tab close — save your encrypted session to your device anytime.

PII Sanitization Tool

Paste your sensitive data here or

Select an Industry Profile on the left

Pre-configured entity detection libraries tailored for each sector (Healthcare, Legal, Finance, DevOps) to sanitize PII in local RAM before AI processing.

Paste Clipboard
Insert text from your clipboard directly into local RAM without saving to disk.
Instant Input
Attach File & OCR
Upload documents (.pdf, .docx, .xlsx, .csv, .txt) or scan images with on-device OCR in RAM.
100% Offline
Custom Rules
Define your own detection rules to detect account numbers, internal codes, and custom PII patterns.
PRO Feature
Semantic AI (35MB)
Local NER Machine Learning model to detect complex contextual PII. Downloads ~35MB model on first use.
PRO Feature
0 / 15k

Copy to AI

0 items protected

Protected output will appear here
after you click Protect Info →

STEP 3Copy & Open in AI
Click any AI to copy your clean prompt and openGet Extension →
STEP 4Paste AI Response → Restore Real Data
1-Click Reveal Zero Server Calls
Paste response above and click "Reveal Originals" to restore data.
Extension Sync Active
Full session parity & in-page shield
MCP Server for Devs
npx @privacyscrubber/mcp-server
100% Local Processing
Airplane Mode Verified (Zero Logs)
Zero-Trust Architecture
No Server. GDPR/UK DPA/SOC2 Ready.
AW

Alexander Wright

CISO, Velo Financial

"Zero-Trust Data Sanitization (ZTDS) changed how we approach AI security. By running 100% locally in the browser RAM, PrivacyScrubber satisfies our GDPR and SOC 2 Type II controls instantly without introducing third-party data processors. It is our standard guardrail for ChatGPT."

Verified Customer SOC 2 Use Case

"We run this before every ChatGPT session. Our InfoSec team was satisfied in one audit."

— Marcus T., Lead Compliance Engineer · European Fintech (400 employees)

"Finally — a PII tool that doesn't route my data through someone else's cloud."

— Jordan K., Senior DevOps Engineer · US Healthcare SaaS

"Used this to pass our SOC 2 AI-prompt review. The offline verification is the proof point."

— Priya N., Head of Legal Ops · Series B SaaS, 200 seats

Zero-Trust Industry Architecture

Built for Security-First Workflows

Eliminate shadow AI risks and compliance roadblocks with 100% client-side RAM sanitization. Interactive proof by role and execution surface.

Risk: Hardcoded Secrets & DB DumpsAvg Breach: $4.9MTarget: PII MCP / CLI

Sanitize Crash Logs, Database URLs & API Keys

Developers paste server logs and environment files into ChatGPT, Claude, and Cursor for debugging, leaking AWS secrets and production DB passwords. Our local engine sanitizes sensitive tokens in RAM before the prompt fires.

devops_crash_log.log
// Raw text pasted into Cursor/ChatGPT
Error connecting to DB: postgres://admin:superSecretPass2026@prod-db.internal:5432/customers
AWS_KEY: AKIA4X9M2PLRT887NNZZ
// Tokenized in client RAM with Zero Network Transmission
Error connecting to DB: postgres://admin:[PASSWORD_1]@prod-db.internal:5432/customers
AWS_KEY: [API_KEY_1]
// 1-Click Reveal restores original DB credentials on your machine
LLM Solution: Fix connection pooling for postgres://admin:superSecretPass2026@...
Deploy PII MCP Server
Risk: PCI-DSS v4.0 & GLBAPenalties: Up to $100k/moTarget: Extension & Web

Zero-Server Masking for PAN, IBAN & Wire Transfers

Financial analysts modeling client portfolios or summarizing bank statements risk exposing primary account numbers (PAN) and SWIFT codes. PrivacyScrubber uses Luhn-verified masking locally in RAM before transmission.

wire_instruction.txt
// Sensitive wire transfer pasted for LLM review
Wire $450,000.00 to Robert Chen (Acct: 4532-0151-8879-2241, IBAN: US948123490019283, SSN: 203-44-8821).
// Luhn-verified PAN masking with contextual token consistency
Wire [VALUE_1] to [NAME_1] (Acct: [CARD_1], IBAN: [IBAN_1], SSN: [SSN_1]).
// AI generates audit memo → Reveal restores real numbers locally
LLM Audit Report: Verified authorization for Robert Chen ($450,000.00) with Goldman Sachs.
Explore Financial Compliance
Risk: HIPAA 18 IdentifiersStatutory Fine: $1.9MSafe Harbor Certified

De-Identify EHR Notes & Clinical Diagnostics

Physicians and clinicians summarize EHR records and patient histories without waiting months for signed BAA agreements. PrivacyScrubber implements the HIPAA Safe Harbor standard 100% in local browser RAM.

clinical_chart_ehr.txt
// Unredacted clinical chart
Patient: Sarah Jenkins (DOB: 1984-05-12, SSN: 042-88-9124). Admitted for acute bronchitis. Primary: Dr. Gregory House. Policy #BC-99214.
// 18 HIPAA identifiers tokenized locally in RAM
Patient: [NAME_1] (DOB: [DATE_1], SSN: [SSN_1]). Admitted for acute bronchitis. Primary: [DOCTOR_1]. Policy [POLICY_1].
// AI generates diagnostic plan → Reveal restores patient identity locally
Clinical Care Summary: Recommended antibiotic dosage plan for Sarah Jenkins under care of Dr. Gregory House.
HIPAA Safe Harbor Protocol
Risk: EEOC Bias & Candidate PIIGDPR Employee DataTarget: Batch CSV / DOCX

Blind Resume Screening & Bulk Salary Anonymization

HR practitioners analyzing payroll compensation or screening resumes risk leaking salaries and introducing gender/racial bias into AI models. Bulk offline file processing strips identifiers before AI analysis.

candidate_screening.csv
// Candidate resume and compensation history
Candidate: Emily Watson (Email: emily.w@enterprise-tech.io, Salary: $165,000/yr, SSN: 019-48-2910).
// Anonymized profile for bias-free LLM skill evaluation
Candidate: [CANDIDATE_1] (Email: [EMAIL_1], Salary: [SALARY_1], SSN: [SSN_1]).
// AI produces skill ranking → Reveal restores contact details locally
Unbiased Assessment: Candidate Emily Watson meets all L6 Engineering leadership qualifications.
Bulk File Sanitizer (PRO)
Architecture: Two-Tier Fleet GovernanceISO 27001 & SOC 2Teams Hub ($99/mo)

Two-Tier Fleet Governance: Central CISO Lock + Local Flexibility

Employees will use generative AI regardless of corporate bans. PrivacyScrubber solves the Shadow AI paradox through a two-tier architecture: Central security officers enforce mandatory regex rules, while employees retain local agility.

Tier 1: Central CISO Hard Lock
Deploy non-negotiable MDM regex rules via Chrome Enterprise. Mandates zero-tolerance blocking for PAN, SSN, API secrets, and proprietary project codes across 10,000+ browser seats.
Tier 2: Local Worker Agility
Engineers and analysts create ad-hoc local masking rules for active client projects on the fly, eliminating IT friction and helpdesk change tickets.
Encrypted Handoff via XChaCha20-Poly1305 + Argon2id
Zero-Knowledge Guarantee
Read CISO Cryptographic Blueprint
In-DOM InterceptionSupports 9 LLMs0ms Network Latency

Automated In-DOM AI Prompt Firewall

Type naturally in ChatGPT, Claude, Gemini, DeepSeek, or Cursor. The Chrome Extension intercepts prompts in local RAM as you type, replacing client names, credit cards, and API secrets with safe tokens before network submission.

In-DOM Filter
Intercepts keystrokes in textarea before send. No cloud hop.
1-Click Reveal
Restores real names and details in AI response locally.
22+ Profiles
Medical, Legal, Finance & Custom Regex Fleet Rules.
Model Context ProtocolOpenAI · Cursor · ClaudeZero Server Calls

Local PII MCP Server for AI IDEs & Agent Frameworks

Deploy a local Model Context Protocol (MCP) server that sits between your codebase and AI assistants (Cursor, Claude Desktop, OpenAI Codex, Antigravity). Tool calls and file reading operations are sanitized locally in RAM.

// Add to Cursor or Claude Desktop config
"mcpServers": {
  "privacy-scrubber": {
    "command": "npx",
    "args": ["-y", "@privacyscrubber/mcp"]
  }
}
Airplane Mode Verified350KB Zero-InstallPDF & DOCX Bulk

Air-Gapped Client-Side Workspace

Paste text, drop spreadsheets, or sanitize multi-page PDFs. The entire regex engine runs client-side in your browser's RAM with 0ms network latency. Disconnect your Wi-Fi (Airplane Mode) to prove zero data ever leaves your device.

22+
Industry Profiles
100%
Offline Local RAM
0 ms
Cloud Latency
Explore 22+ Entity Detectors
$99/mo Unlimited SeatsXChaCha20-Poly1305Central Hard Lock

Zero-Knowledge Team Session Handoff

Allow entire departments to collaborate on AI prompts without leaking PII across colleagues. Alice sanitizes raw records and sends prompt tokens to Claude; Bob receives Claude's output and restores original names locally using client-side keys.

1. Alice sanitizes PII[NAME_1] → Claude2. Bob reveals locally
Teams Handoff Documentation
NPM · ESM · CJSZero DependenciesSub-Millisecond Speed

Embed Local PII Masking in CI/CD & RAG Pipelines

Sanitize logs, RAG vector embeddings, and database exports before they reach external LLM endpoints. Headless, zero-dependency, and execution entirely in RAM.

// Install zero-dependency headless package
npminstall@privacyscrubber/sdk

// 100% Client-side local execution
import { scrub, reveal } from'@privacyscrubber/sdk';
const safeLog = scrub(rawText); // Zero network calls
Ecosystem Workflows

Secure PII Masking Locally for Every AI Workflow

Protect sensitive data seamlessly across our zero-trust ecosystem: Web Workspace, Browser Extension, and Local MCP Server.

100% Client-SideZero bytes leave your RAM
Zero Network CostAirplane mode verified
Unified EngineIdentical rules across all surfaces
Automatic In-Page Masking for ChatGPT & Claude
Chrome Extension — Client-Side AI Gateway

Sanitize AI Prompts Before They Leave Your Browser
In-Page Real-Time Protection on ChatGPT, Claude & Gemini

Automatically detect and tokenize customer names, API keys, medical notes, and financial data directly inside your AI chat window. 0ms network latency — 100% local browser RAM processing.

Stop Shadow AI Data Leaks at the Source

Give employees full AI speed without server privacy risks. PrivacyScrubber's browser extension intercepts prompts right as they type — replacing names, emails, card numbers, and secret tokens in local RAM before any data reaches third-party LLMs.

Context Menu Masking

Highlight sensitive text on any webpage, email, or CRM, right-click, and instantly sanitize PII directly in your browser. Perfect for quick scrubbing before pasting into unsecure forms.

In-Page Auto-Detection (9 LLMs)

Native UI injectors for ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity, Poe, HuggingFace, and Mistral. Real-time PII blocking before you hit send. Try live demo 20 parameters →

Command Center Popup

Your main control hub. Switch between 22+ industry profiles (HIPAA, GDPR), customize Token Labels & Custom Regex Rules, and use 1-click restore to swap placeholders back to original data natively.

100% Offline Session Sync

Seamless cryptographic sync with the web platform. Download secure offline HTML receipts of your scrubbing sessions for compliance audits without any server logs.

Natively Supports

ChatGPT Gemini Claude Copilot DeepSeek
gemini.google.com
STEP 1 of 4
PrivacyScrubber detects 6 PII items in Gemini prompt with shield overlay

Step 1: Detect

User types a clinical note with real patient PII into Gemini. The shield icon detects 6 sensitive items.

How to Use the Extension (60s Guide) Live Demo
How to Use PrivacyScrubber Chrome Extension - Video walkthrough
Watch Extension Tutorial1:04
Regulatory Coverage

Client-Side PII Scrubbing That Satisfies EU AI Act, HIPAA, GDPR & SOC 2

Zero-setup composable AI privacy. Drop-in client-side data sanitization — 100% in local browser RAM. No vendor lock-in, no BAA required, zero third-party audit surface.

5 Frameworks · 0 Bytes Transmitted · 0 Third-Party Exposures
All Compliance Guides
Verifiable Security

Verify Zero Data Transmission in 60 Seconds

No auditor needed. Verify our zero-server architecture yourself using tools built into your browser.

1
Open DevTools

Right-click → Inspect or press F12

2
Network Tab → Clear

Click 🚫 to reset the request log before testing

3
Airplane Mode opt

Disconnect — the tool keeps working from RAM

4
Paste Text → Protect Info

Watch Network tab while the engine processes

5
Confirm: Zero Network Requests

Network tab shows 0 new requests — all data processing occurs securely inside your browser's local RAM.

Network |0 requests| 0 B
Airplane Mode Verified No Server Logs Zero Tracking
Zero-Server Data Sanitization

Trusted by Innovators. Verified by Security.

See how compliance officers, developers, and security leaders use local PII tokenization to protect clinical, financial, and legal records.

Trusted by 10,000+ developers & compliance professionals on the Chrome Web Store →

* Note: The case studies and scenarios presented above are composite profiles synthesized from actual user feedback and industry compliance standards to protect original organization privacy.

Join 10,000+ security professionals using PrivacyScrubber

Local AI Privacy Plans. Zero Recurring Debt.

Instantly redact names, emails, and confidential client records before pasting into ChatGPT, Claude, or IDEs. 100% in-browser RAM execution — zero cloud transmission.

Free
$0
For testing and occasional prompts
  • Stop Accidental PII LeaksInstantly swaps real names, emails, and phone numbers with anonymous tokens before you paste into AI.
  • Decode AI Answers in 1 ClickPaste AI responses back to automatically restore real names and client details right inside your browser.
  • 100% Volatile RAM ExecutionZero cloud server proxy, zero telemetry logging, and zero disk writes. Ephemeral session state.
  • Standard Entity RecognitionPre-configured detection for Names, Email addresses, Phone numbers, Credit Cards, and National IDs.
  • Free Daily Testing LimitsUp to 15,000 characters per prompt, 3-page PDF test, and 3 image OCR scans per session.
Best Value
PRO
$15/mo
or $110 for Lifetime Access
1 User License
Web App + Chrome Extension + IDE MCP
Avg. Data Breach Fine: $4.9M
Complete Prevention: $15/mo
TEAMS
$99/mo flat
Unlimited seats for your entire team. Whether you have 5 people or 50, the price never changes.
Cards, PayPal, Apple/Google Pay & Wire Invoices
Effective:$50/person
2 people
Break-even at 7 people ($14/person)
Custom
ENTERPRISE
Custom
1,000+ to 10,000+ seats · Air-gapped · No cloud, no telemetry
Custom PO, Wire Transfer & Corporate Invoicing
Enterprise Hub
Accepted Payment Methods
Wire / Invoice
PCI-DSS Compliant
Compare All Pro Features
Answers & Security FAQ

Frequently Asked Questions

Everything you need to know about browser-based PII redaction, compliance scope, and AI safety.

Does PrivacyScrubber send my data anywhere?
No. All detection and masking happens locally in your browser's memory. You can verify this yourself by opening your browser's Network tab or disconnecting from the internet — the tool keeps working.
What AI tools does it work with?
ChatGPT, Claude, Gemini, Copilot, Grok, Llama, Perplexity, Mistral, and Hugging Face Chat. The browser extension adds in-page masking directly inside each of these.
Is the free version good enough for regular use?
The free tier covers core PII types (names, emails, phone numbers) up to 15,000 characters per scrub, with a 3-page PDF limit. Batch processing, OCR, and industry-specific detection profiles (legal, medical, finance, etc.) require PRO.
Does this satisfy HIPAA, GDPR, or SOC 2 requirements?
PrivacyScrubber is designed to support de-identification under HIPAA Safe Harbor, GDPR Article 25/32, and SOC 2 CC6-series controls by removing identifiers before data reaches a third-party AI tool. It is a technical control, not a substitute for a full compliance program — check with your compliance team on whether it fully satisfies your specific obligations.
Can I get my original data back after the AI responds?
Yes. Paste the AI's response back into the tool and click "Reveal" — it swaps the tokens back to your real data locally, with no server round-trip.
Is PrivacyScrubber a local or cloud PII scrubber?
PrivacyScrubber is a 100% local, browser-based PII scrubber. Unlike cloud DLP solutions, it performs enterprise-grade PII and PHI scrubbing entirely in your browser's RAM, ensuring zero-trust data sanitization for texts and documents (PDFs, DOCX, CSV) without ever sending data to an external server.
What happens to the session map when I close the browser?
The session map is stored exclusively in volatile browser RAM. The moment you close the tab, reload the page, or navigate away, the entire mapping — including all original PII values — is permanently destroyed.
Does PrivacyScrubber remove PII from uploaded documents, and what is the output format?
Yes. PrivacyScrubber detects and scrubs PII from local documents (.txt, .docx, .pdf, .xlsx, .csv, and images). You can download the output either as a fully sanitized, anonymized document (retaining its original file extension and structure) or copy the processed text stream directly to your clipboard.
How does the TEAMS encrypted session sharing work?
PrivacyScrubber generates an AES-GCM encrypted link locally. Your colleague can paste the AI's response and use your shared, encrypted key to safely 'reveal' the original data on their machine — no database or server involved.
How does closed Shadow DOM sandboxing protect my data from malicious scripts?
PrivacyScrubber encloses both your editor input (#inputText) and the highlighted token output within isolated, closed Shadow DOM roots. This makes the raw, unredacted text completely inaccessible to any third-party scripts, browser extensions, or key-sniffing scripts running in your main document pool, creating a hardened frontend sandbox.
Can corporate accounts or accounting firms pay via manual invoice or wire transfer (SWIFT/SEPA)?
Yes. If your corporate credit card is declined due to international banking restrictions or if your procurement department requires manual invoicing, purchase orders (PO), or bank wire transfers (SWIFT/SEPA), our team can manually issue a formal invoice with tax reverse-charge support. Contact support@privacyscrubber.com to request an enterprise invoice.
How does PrivacyScrubber prevent data residue in system RAM (V8 memory wiping)?
To prevent PII or case documents from remaining in your device's memory after sanitization, the processing engine actively overwrites all temporary parsing buffers (used for DOCX, PDF, and spreadsheet extraction) at the byte level using Uint8Array.fill(0) in local memory immediately after use, ensuring zero sensitive residue remains in RAM before garbage collection.
Does changing the detection profile reset my protected session data?
No. Changing your detection profile (e.g., from General PII to Wealth Management) does not clear your active session or reset your local token maps. This ensures that any tokens generated using your previous profile remain fully decryptable when you paste AI responses back to 'Reveal' the original text. To completely wipe your session, rotate encryption keys, and clear all memory, click the 'Clear' button at any time.
How do local Audit Receipts and Teams Handoff work without a backend database?
PrivacyScrubber operates entirely in your browser's local RAM. Compliance audit receipts and team handoffs are exclusive features of the Teams Subscription. For audit compliance, the system builds an offline cryptographic PDF receipt documenting entity counts, timestamps, and active compliance profiles. For Teams Handoff, it encrypts the tab's session map in-memory using Argon2id and XChaCha20-Poly1305. Your colleague decrypts the token map on their machine using the shared key — no central database or server ever touches your data.
Does PrivacyScrubber use third-party tracking, analytics, or review widgets?
No. To maintain a strict zero-trust data sanitization architecture, PrivacyScrubber does not load third-party analytics trackers, cookies, or reviews integrations (such as Google Customer Reviews or similar widgets). Adding dynamic third-party scripts would require relaxing our Content Security Policy (CSP) and could allow external servers to inspect page states or log user environments. We display reviews statically or link to external platforms like G2 or the Chrome Web Store to ensure zero data leakage.
Can I use PrivacyScrubber as a PII MCP Server for Cursor or Claude Desktop?
Yes. PrivacyScrubber offers an official local Model Context Protocol (MCP) server package (@privacyscrubber/mcp-server) that integrates directly with Cursor IDE, Windsurf, and Claude Desktop. It acts as a local prompt security gateway, scanning and masking PII and API keys locally in volatile RAM before they are transmitted to external LLM APIs.
How are Team Administrator roles managed without a backend server?
In our Zero-Trust Data Sanitization (ZTDS) architecture, there are no server-side accounts or traditional 'Admin' vs 'User' roles. Team Administration is handled via client-side Blueprints. A team lead sets up the required compliance profiles, custom regex rules, and organization name locally, then locks the configuration and exports a cryptographic 'Team Blueprint' URL. When workers click this URL, their local PrivacyScrubber instance activates the TEAMS license, imports the mandated configuration, and disables their ability to edit or delete rules, ensuring organization-wide compliance securely without a backend database.
What is the difference between Token Labels and Custom Regex Rules?
Custom Regex Rules and Token Labels serve distinct purposes in Zero-Trust AI sanitization. Custom Regex Rules are a pattern discovery engine used to identify new or proprietary identifiers (such as internal ticket numbers, project codes like PROJ-\d{4}, or custom account formats) that are not covered by default NER models. In contrast, Token Labels do not search for new text; instead, they rename the replacement placeholders for standard detected entities (for example, mapping NAME → PATIENT or ID → CASE_NUMBER) so that the LLM receives domain-accurate semantic context in its prompt without requiring custom regex code.
How do Custom Token Labels optimize LLM prompt comprehension?
When prompts are sanitized using generic placeholders like [NAME_1] or [ID_1], LLMs may lose contextual role differentiation in multi-party prompts. Custom Token Labels allow PRO and TEAMS users to alias standard entity categories to domain-specific terminology (such as [PATIENT_1], [CLIENT_1], [PLAINTIFF_1], or [DEFENDANT_1]). This gives the LLM precise semantic clarity about each entity's functional role while preserving 100% anonymization and enabling seamless 1-click reverse-scrubbing ('Reveal') of the AI response.

Have more technical or enterprise questions? Check our CISO Security Guide or explore Compliance Standards.