Swaps Names, Phones, Emails, SSN, Credit Cards, URLs & IPs with safe tokens before AI ingestion.
Paste AI responses back to reveal original client data locally in browser RAM without server leaks.
Zero servers, zero telemetry, zero logs. Verified offline in Airplane Mode with sub-millisecond speed.
- In-Page Shield & Web App
Use via keyboard hotkey
Alt+Shift+Xdirectly in ChatGPT, Claude, Gemini or full web app. - Free Volume & Single File Trial
15,000 chars general + 5,000-char trial across all 30 Specialized Profiles. Single document sanitization (.pdf/.docx/.xlsx).
Redact PII from AI Prompts, Files & Documents Before ChatGPT, Claude or Gemini See It
The Air-Gapped AI Data Loss Prevention (AI DLP) Engine. Redact sensitive entities like [FINANCIAL_DATA] before LLMs store it.
AI models never forget — data in training weights or RAG vector lakes cannot be deleted. PrivacyScrubber executes 100% in local RAM with zero network packets, zero server logs, zero subprocessors.
PII Sanitization Tool
Input
Tap to upload document or photoDrag & drop documents or photos
Sanitized in volatile RAM — zero data ever leaves your device.
Free tier: 1 file (up to 15k chars) · 100% in local RAM ·
Sanitize Before AI
Document Sanitizer Standby
Select a document or snap a photo above to strip PII instantly.
Sanitized locally in volatile RAM. Pre-prompt compliance maintained under GDPR & SOC 2.
Open in AI
Tokens active in RAM — click Reveal Original Data to auto-paste from clipboard & reveal.
"We run this before every ChatGPT session. Our InfoSec team was satisfied in one audit."
— Marcus T., Lead Compliance Engineer · European Fintech (400 employees)
"Finally — a PII tool that doesn't route my data through someone else's cloud."
— Jordan K., Senior DevOps Engineer · US Healthcare SaaS
"Used this to pass our SOC 2 AI-prompt review. The offline verification is the proof point."
— Priya N., Head of Legal Ops · Series B SaaS, 200 seats
Zero-Egress Security Proof100% Client RAM
Verify mathematical zero network transmission in Chrome DevTools or Airplane Mode
Sanitize High-Liability Documents
Before Submitting to Enterprise AI Models
Eliminate PII, PHI, financial ledgers, and trade secrets in local RAM. Select your document type below for verified field-by-field redaction matrices and safe AI prompts.
Finance, Underwriting & Banking
Prevent customer account numbers, SWIFT MT103 instructions, and payroll records from leaking into training corpora.
Legal Counsel & Court Discovery
Preserve attorney-client privilege under Federal Rule of Evidence 502. Neutralize case numbers and party names.
Healthcare & Life Sciences
Comply with HIPAA 45 CFR § 164.514 Safe Harbor. Mask MRNs, patient names, and dates while preserving clinical symptoms.
HR, Recruiting & Compensation
Conduct blind resume screening and salary benchmarking without injecting protected class identifiers or leaking payroll.
DevOps, Secrets & Autonomous AI Coding Agents
Protect internal API keys, database dumps, and cloud infrastructure secrets from entering LLM context windows in Cursor, Windsurf, Claude Code, and Copilot.
Zero-Metadata Engine Breakdown:
What PrivacyScrubber Strips Beyond Visible Text
Visual redaction alone leaves organizations exposed to court subpoenas and LLM data extraction. Real enterprise documents store deep internal XML structures, revision histories, and hidden text layers that cloud AI parsers automatically ingest.
OpenXML Package Dissection
Word and Excel files are ZIP archives storing internal XML trees. Naive text deletion leaves metadata intact.
\\corp-nas\payroll). Vector Stream & Text Layer Erasure
Court discovery exhibits and medical records demand the Anti-Manafort standard: 0 underlying text traces.
Raster Burn-In & Hardware EXIF Purge
Mobile snapshots of driver licenses, invoices, and hospital intakes contain latent geolocation and hardware stamps.
| File Security Vector | Legacy / Cloud Redaction Tools | PrivacyScrubber ZTDS Engine |
|---|---|---|
| Visible PII Text (Names, SSNs, Accounts) | Replaced visually on screen | Replaced in-memory with reversible AI tokens or blackouts |
| Underlying PDF Text Layer (Anti-Manafort) | Retained under black rectangles (extractable by AI) | Physically destroyed from Tj/TJ vector streams |
| DOCX/XLSX Author & Company Metadata | Preserved in docProps/core.xml | Purged 100% prior to native file export |
| Track Changes & Deleted Comments | Stored in hidden XML revision tags | Completely stripped from ZIP container |
| Camera EXIF & Smartphone GPS Data | Kept in image headers, leaking coordinates | EXIF dropped, raster burned in on HTML5 Canvas |
| Network Egress & Server Storage | Uploaded to remote cloud proxy / API server | 0 bytes sent to network • 100% in local RAM (Airplane Mode) |
Direct File Format Engines (Zero Cloud Upload)
Which Side of AI Security Are You On?
Paper Promises vs Physical Data Sovereignty
Not your RAM, not your data. The fundamental divide between signing legal contracts to allocate post-breach liability versus enforcing mathematical zero-egress before generative models ever see raw text.
Paper Compliance
Organizations rely on Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), and trust declarations from cloud proxy vendors (Skyflow, Presidio Cloud, AWS Comprehend).
Continuous Third-Party Egress
Unredacted prompt text, client IDs, and financial records transit across external fiber cables to intermediary vendor cloud servers.
Residual Cloud Custody & Subpoena Risk
Ephemeral cloud caches, server crash logs, and worker heaps remain vulnerable to insider threats, infrastructure compromises, and CLOUD Act warrants.
Procurement Drag (6–8 Weeks)
Requires exhaustive InfoSec supplier questionnaires, subprocessor chain audits, and legal review of third-party indemnification caps.
Reactive Financial Exposure
When a cloud subprocessor leaks, the DPA only defines who pays the lawyers. Average IBM Cost of a Data Breach: $4.88M.
Physical Data Sovereignty
Organizations rely on deterministic CPU tokenization isolated in local workstation RAM (IETF draft-sibiryakov-ztds-protocol).
Strict Zero-Byte Network Transmission
Raw text never hits the network adapter. All tokenization, Luhn checks, and redactions complete inside browser V8 RAM in <2ms.
Mathematical Immunity to Subpoena & Leaks
No cloud server holds your cleartext session map. It is mathematically impossible to breach, leak, or subpoena data that was never transmitted.
0-Day Procurement (DPA Legally Waived)
PrivacyScrubber is not a Data Processor under GDPR Art. 4(8) or HIPAA. InfoSec and Legal grant immediate clearance without 6-week vendor delays.
Empirical Verification (Airplane Mode)
Fully functional with Wi-Fi disabled. Inspect Chrome DevTools Network tab: exactly 0 requests and 0 bytes transferred.
Deep Zero-Metadata Office Sanitization
Beyond visible text, our in-RAM engine purges hidden XML properties (docProps/core.xml, wb.Props), wiping authors, corporate tags, and revision history in DOCX and XLSX before download.
Why Data Deletion from Frontier LLMs is Impossible
Once sensitive data enters an AI model or enterprise RAG vector store, it cannot be selectively deleted—machine unlearning remains unsolved. Network gateway DLPs miss encrypted WebSockets and streaming SSE tokens. PrivacyScrubber enforces source-level sanitization in local RAM before transmission, satisfying EU AI Act governance and DORA resilience mandates.
Do Not Trust Our Word. Audit Your Own RAM in 60 Seconds.
Press F12 → Disconnect Wi-Fi → Scrub any document or prompt. Prove zero bytes leave your machine.
Sanitize AI Prompts Before They Leave Your Browser
In-Page Real-Time Protection on ChatGPT, Claude & Gemini
Automatically detect and tokenize customer names, API keys, medical notes, and financial data directly inside your AI chat window. 0ms network latency — 100% local browser RAM processing.
Zero-exfiltration prompt sanitization directly in your AI chat window
Intercepts names, emails, cards, and keys in local RAM before prompt transmission to LLMs. Zero server logs.
In-Page Prompt Sanitizer for ChatGPT, Claude & Gemini
Air-gapped client-side interception inside your AI text inputs. Customer identities, credentials, medical notes, and financial records are sanitized in local RAM before prompt transmission.
In-Page Auto-Detection (9 LLMs)
Native injectors for ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity, Poe, HuggingFace, and Mistral.
1-Click Reverse Reveal in Chat
Instantly swaps tokens in the AI response back to original names and data directly in your browser.
100% Offline RAM & ZTDS Receipts
30 industry profiles (HIPAA, GDPR), custom regex rules, and cryptographic audit receipts with zero server telemetry.

Step 1: Detection
Step 1 of 4Type or paste your text normally. The extension instantly detects sensitive data like names, emails, or IDs right inside the text box.
Verify Zero Data Transmission in 60s & Comply with
GDPR, HIPAA, SOC 2 & EU AI Act
No auditor or vendor trust needed. Open DevTools to prove PrivacyScrubber sends zero network requests with your data — backed by turnkey statutory compliance for enterprise LLM deployments.
60-Second Proof of Zero Transmission
Independent DevTools verification protocol for InfoSec & SecOps
Press F12 or right-click → Inspect
Click the Clear icon to reset active request log
Cut Wi-Fi — engine runs 100% offline
Watch Network tab as text is tokenized
Zero bytes egressed to external endpoints — full mathematical guarantee of zero data leakage.
6 Tough Questions Security Architects Ask Us
Direct technical answers addressing the core questions evaluated by CISOs, security researchers, and enterprise review committees.
01Why not Presidio or cloud NER models?
02How is browser memory protected from extraction?
script-src 'self') with zero external scripts. The volatile sessionMap is strictly tab-isolated, never stored on disk or cookies, and wiped on tab close. 03What happens if generative AI alters synthetic tokens?
04How does InfoSec audit compliance without central servers?
05Why use ZTDS if our enterprise signed an Azure OpenAI or ChatGPT Enterprise BAA?
06What if our documents contain rare or proprietary PII?
Automated pre-AI sanitization for European teams. Prevents high-risk data leakage into generative models without proxy latency or vendor risk.
De-identify PHI before sending prompts to any AI tool. Engineered for §164.514 Safe Harbor de-identification directly in browser RAM.
Names, addresses, and IDs replaced before any AI prompt is sent. Technical measure supporting Art. 25 (Privacy by Design) and Art. 32.
Zero-server model eliminates vendor data exposure — your auditor sees zero third-party data flows because there are none.
PII sanitized before it reaches any AI system. Automates Annex A.8.11 data masking control at the client endpoint without cloud proxy overhead.
Luhn-validated PAN and CVV tokenization before financial prompts leave the workstation. Eliminates cardholder data transmission to LLM servers.
Paper Contracts vs Physical Immunity: Local RAM vs Cloud DLP
Sign a DPA to allocate liability after an incident, or isolate memory so a breach is physically impossible. Why enterprise security architects choose in-memory client-side ZTDS over cloud DLP proxies.
Cloud DLP Proxies & Gateways
- Network Egress: Transmits unredacted prompt payloads over the internet to intermediate cloud proxy servers.
- High Latency: 250ms – 600ms latency penalty per AI query due to multi-tenant cloud roundtrips.
- Probabilistic NLP: Cloud LLM redactions risk hallucinating tokens, skipping entities, or rewriting prompt semantics.
- Procurement Overhead: Requires 6–8 week legal reviews, BAAs, DPAs, and third-party vendor risk questionnaires.
PrivacyScrubber Client-Side ZTDS
- 0-Byte Transmission: 100% volatile local RAM processing. Fully functional offline in Airplane Mode.
- Sub-2ms Latency: Near-zero latency overhead (<2ms local CPU tokenization). Zero network queues.
- Deterministic Precision: Rigorous pattern engines (Luhn, RFC 5322, RegExp). Zero token hallucinations.
- 0-Day Clearance: Zero third-party data processing — DPAs and BAAs are legally non-applicable.
100% reproducible RAM tokenization
HIPAA Safe Harbor, GDPR, PCI DSS
Air-gapped scanned PDF processing
Transparent Pricing. Zero Subprocessor Risk.
Sanitize enterprise prompts locally in browser RAM before sending to ChatGPT, Claude, Gemini, or Cursor. Zero servers, zero per-seat tax, 100% GDPR, HIPAA & SOC 2 compliant.
No character limits across all 30 specialized industry profiles (HIPAA, Legal, Finance, W-2, Logs).
Air-gapped stdio secret & PII stripping directly inside AI IDEs and code assistants.
Unlimited batch processing (.pdf, .docx, .xlsx, .csv). Full zero-metadata XML purge, vector erasure & offline OCR.
Inject custom rules for internal project codenames, client codes & proprietary identifiers.
Cryptographic certificates with SHA-256 session digests proving zero raw PII egress.
Single flat license covering every employee. Zero per-user tax, headcount tracking, or seat tiers.
Share sanitized prompts and batch document sessions between colleagues via encrypted P2P zero-server handoff.
Distribute proprietary project codes, client lists, and custom regex policies across all staff browsers.
Cryptographic PDF receipts proving 0-byte server egress to satisfy SOC 2, HIPAA, and GDPR auditors.
100% client-side architecture bypasses multi-month vendor security reviews with a pre-cleared CISO memo.
Acts on behalf of users at the API boundary, quashing PII before ingestion to fulfill GDPR, CCPA/CPRA, and statutory privacy duties automatically.
Deterministic, syntax-preserving tokens maintain 100% LLM reasoning fidelity; exact cleartext is restored exclusively in local Node/WASM memory.
100% in-process execution in your own memory space. Completely eliminates cloud DLP brokers (Skyflow, Lakera) — zero data touches third parties.
Intercept PII before vector embedding into Pinecone, Qdrant, Chroma & agent loops, permanently solving GDPR Art. 17 right-to-be-forgotten.
High-throughput linear RAM stream (8.4 MB/s). 250x faster than cloud DLP with zero network hops, zero egress fees, and master key custody.
The True Cost of AI Privacy: Breach vs. DIY vs. ZTDS™
Average cost of a GenAI corporate data breach according to the IBM Security Report.
- Up to €20M or 4% turnover (GDPR & EU AI Act Art. 50).
- $50,000/violation statutory HIPAA willful neglect fines.
- 6–12 week enterprise procurement stalling for vendor reviews.
Internal engineering salary to build, test and maintain custom regex DLP logic.
- $500–$2,000/mo server bills for centralized cloud proxy nodes.
- 200–500ms network roundtrip latency on every developer prompt.
- Ongoing regex drift, edge-case false positives & triage drag.
Flat-rate team protection with 100% in-memory client-side sanitization.
- 0-Day Approval: Zero subprocessors, no DPA paperwork needed.
- <2ms local RAM execution with 0 bytes network egress.
- Turnkey compliance proofs: SOC 2 Type II & ISO 27001 mapping.
How PrivacyScrubber Licensing Actually Works
We refuse to store your passwords or track your identity in a central database. Privacy is an engineering guarantee, not a marketing promise.
1. Zero Accounts & No Passwords
You never create an account, set a password, or trust us with login credentials. There is no cloud user database to be breached, scraped, or subpoenaed.
2. Offline Cryptographic Keys
Paid tiers (PRO, TEAMS, SDK) activate via an offline cryptographic license key. Validation occurs mathematically in your local RAM without cloud telemetry or pingbacks.
3. 1-Year G2 Reviewer Pass
Solo practitioners and engineers can claim a full 1-year PRO license key ($180 value) 100% free by publishing an honest, verified practitioner review on G2.
Traditional Cloud DLP vs. PrivacyScrubber TEAMS — 94% Cost Reduction
Cloud DLP vendors charge $30–$50/user/mo ($18,000–$30,000/yr for 50 seats), introduce 250ms+ network latency, and require months of vendor security assessments. PrivacyScrubber TEAMS costs $99/mo flat ($1,188/yr) for unlimited seats with zero server-side subprocessor liability.
Complete on-premise source code licensing, 100% air-gapped sovereign deployment, proprietary patent-pending architecture (U.S. & Int'l Patents Pending), custom SIEM log integration, dedicated GRC support & bilateral DPA for healthcare systems, banks, defense, and 10,000+ seat organizations.
What You Get & Why It MattersRole & feature entitlements across Free, PRO, TEAMS, and Enterprise tiers
Compare All Specifications →Hide Specifications ←
Role & feature entitlements across Free, PRO, TEAMS, and Enterprise tiers
Frequently Asked Questions
Everything you need to know about browser-based PII redaction, compliance scope, and AI safety.
Features & FilesHow does the Zero-Trust Agentic Guard work in practice when AI agents run shell commands or edit code?
Security & ZTDSDoes PrivacyScrubber send my data to any server?
Security & ZTDSDoes dropping or uploading a transcript or document into PrivacyScrubber transmit my file to a server?
Features & FilesWhich AI platforms does the browser extension support?
Pricing & TeamsWhat does the free version include?
@privacyscrubber/sdk) and IDE MCP Server (@privacyscrubber/mcp-server) with built-in session quotas — zero credit card, zero passwords, and zero accounts required. For solo practitioners and developers, you can also claim a 1-Year PRO Reviewer Pass ($180 value) 100% free with an honest review on G2. Features & FilesDo I need to create an account or provide a password?
Features & FilesCan PrivacyScrubber sanitize W-2 forms, paystubs, and payroll documents?
Features & FilesCan I get my original data back after the AI responds?
Compliance & LegalDoes this help with HIPAA, GDPR, or SOC 2 compliance?
Compliance & LegalWhat is the CISO Procurement Memo and how do enterprise teams use it?
Security & ZTDSHow does PrivacyScrubber prove zero network egress and lightweight memory usage?
Security & ZTDSWhat happens to the session map when I close the tab?
Features & FilesWhat is the difference between AI Tokens mode and Blackout mode in PrivacyScrubber?
Features & FilesWhy do standard PDF blackout tools leak data, and how does PrivacyScrubber prevent it?
Features & FilesWhat file formats can I sanitize, and what do I get back?
Features & FilesDoes PrivacyScrubber sanitize hidden document metadata (author, company name, revision history) in Word (DOCX) and Excel (XLSX) files?
docProps/core.xml, docProps/app.xml, and workbook properties. PrivacyScrubber's in-RAM sanitizer intercepts these archives in local browser memory, wipes original author and organization tags, eliminates custom metadata, and overwrites properties with anonymous synthetic signatures (PrivacyScrubber (Zero-Trust)) before export. Your exported files are completely clean both visibly and metadata-wise, with zero network transmission. Features & FilesWhy does the Chrome extension convert uploaded files (PDF/DOCX) into .txt, and how do file upload quotas work?
Security & ZTDSWhat is AI DLP and how does client-side browser sanitization differ from a legacy cloud proxy?
Security & ZTDSWhat is the AI data irreversibility problem and why must PII redaction happen at the client endpoint?
Pricing & TeamsHow does TEAMS encrypted session handoff work?
Security & ZTDSHow does Shadow DOM sandboxing protect against malicious scripts?
Features & FilesCan I use PrivacyScrubber as an MCP server in Cursor, Windsurf, or Claude Desktop?
Pricing & TeamsIs there a developer SDK for integrating PII sanitization, and is it free to try?
Features & FilesHow do developers integrate @privacyscrubber/sdk out of the box, and what are the operational capabilities and state risks?
Features & FilesDoes changing the detection profile reset my session?
Security & ZTDSHow does PrivacyScrubber prevent data residue in system RAM?
Pricing & TeamsCan enterprise or accounting teams pay via invoice or wire transfer?
Security & ZTDSDoes PrivacyScrubber load any third-party analytics or tracking scripts?
Compliance & LegalHow are TEAMS admin roles managed without a backend?
Compliance & LegalWhat rights does a Team Administrator have compared to Managed Team Members in TEAMS?
Features & FilesWhat is the difference between Custom Regex Rules and Token Labels?
Security & ZTDSHow does PrivacyScrubber detect PII without AI hallucinations or latency?
Pricing & TeamsHow does license key custody, non-transferability, and emergency revocation work without user tracking?
Pricing & TeamsWhat are the exact operational boundaries between Personal PRO, Team Workspace, and Developer SDK licenses?
Security & ZTDSIs the PrivacyScrubber MCP Server completely air-gapped, and is it free to use?
Features & FilesHow can solo coaches, therapists, and executive consultants sanitize client meeting transcripts (Zoom, Teams, Google Meet) without cloud exposure?
Features & FilesHow does PrivacyScrubber handle European names with initials and national identity numbers like Dutch BSN, German Steuer-ID, or French NIR?
Compliance & LegalHow does PrivacyScrubber protect enterprise RAG vector databases and prevent GDPR Article 17 re-indexing costs?
@privacyscrubber/sdk into your ingestion pipeline, raw PII is swapped with deterministic cryptographic tokens in Node.js heap (<0.065ms) before vector embedding. When a deletion request arrives, organizations simply purge the local key mapping, achieving instantaneous O(1) mathematical erasure at $0 infrastructure cost. Compliance & LegalWhy does PrivacyScrubber NOT require a Data Processing Agreement (DPA) or Business Associate Agreement (BAA)?
Security & ZTDSWhy deterministic rules instead of cloud NER models like Microsoft Presidio or BERT?
Security & ZTDSHow is browser heap memory protected against local memory extraction, XSS, or process dumping?
script-src 'self') with zero external scripts or analytics trackers. Session maps exist strictly in volatile, tab-isolated RAM, are never written to disk, localStorage, or cookies, and are permanently wiped on tab close. Host RAM dumping requires prior OS root compromise, which affects all workstation secrets regardless of software. Security & ZTDSWhat happens if generative AI models alter, drop, or hallucinate synthetic tokens?
[NAME 1]), and markdown formatting. If a model completely omits a token from its response, the local audit view immediately flags the missing identifier without corrupting surrounding text. Compliance & LegalHow can an enterprise CISO or SOC audit compliance without central servers?
Compliance & LegalWhy do organizations need ZTDS if they already have Azure OpenAI or ChatGPT Enterprise with a BAA?
Features & FilesWhat if our organization handles rare, proprietary, or highly specialized PII formats?
No matching questions found
Try searching for other keywords or reset the filter.
Supported AI Platforms & Workflows
Compare Zero-Trust Alternatives
See how client-side RAM sanitization compares against cloud DLP proxies and server-side NLP models.
PrivacyScrubber vs Every Major PII Masking & AI DLP Tool
Compare PrivacyScrubber and ZTDS™ standard conformance side-by-side against 12 leading cloud DLP APIs, proxies, and SDKs...
PrivacyScrubber vs CamoText
Compare PrivacyScrubber vs CamoText for local AI data masking. Discover key differences in ChatGPT support, speed, and H...
PrivacyScrubber vs Justee AI
Compare PrivacyScrubber vs Justee AI. ZTDS™ local RAM execution eliminates cloud server transit risk for enterprise Chat...
Need CISO, Legal, or Procurement Clearance?
Our 100% in-RAM architecture eliminates DPA negotiations, vendor risk questionnaires, and third-party data processor audits.
