Zero-Trust Data Sanitization

In-Page PII Masking Popover: Highlight Any Text to Scan & Mask Sensitive Data for Any LLM

Highlight Text Anywhere in Your Browser — Instantly Scan for PII and Mask Sensitive Data In-Place Before Sending to Any LLM

100% Local RAM Processing
Trusted by 10,000+ teams & engineers · $0 Free / $99/mo Teams
Airplane Mode Verified
0 Bytes Server Egress
In-Page PII Masking Popover Scanning and Masking Text

AI Summary / Key Takeaways

Verified Zero-Trust Logic

"Highlight any text on any webpage or input field to instantly scan for sensitive data and mask PII in-place. The PrivacyScrubber in-page popover analyzes your browser selection in local RAM, shows detected PII counts, and swaps names, emails, API keys, and credentials into tokens in under 2ms — allowing you to work safely with any LLM without leaving your active tab."

How does the in-page popover scan highlighted text for PII?
Does the in-page popover work with ANY LLM and AI chatbot?
Does in-place masking break ChatGPT's Send button or React/Vue input state?

Enterprise-Grade AI Privacy

Add custom redaction rules and priority support with PRO.

GO PRO
Live Turnkey Simulator · ZTDS Engine

Interactive PII Detection & Sanitization Sandbox

Test real-time client-side RAM tokenization. Choose a specialized preset or paste your own raw prompt to test instant reversible redaction.

0 Bytes Server Egress
<1.8ms Latency
Select Industry Test Payload:
Raw Input Payload
0 chars
RAM-Only Isolated Session
Automated Detection Classes:
Customer / Employee NamesSSNPhone NumbersEmail AddressesCredit Card Numbers (PAN)API Access Keys / TokensPhysical AddressesInternal Server Hostnames
Enterprise Challenge

The Challenge with AI Data Workflows

When researching, drafting, or interacting with AI models, copying snippets into external sanitizers breaks your flow. Without real-time scanning, you can't be sure if a highlighted customer email, error log, or contract excerpt contains hidden API keys or phone numbers. PrivacyScrubber's popover scans highlighted browser text on the fly and tokenizes it in-place in 1 click, making any web text safe for ChatGPT, Claude, Gemini, DeepSeek, or internal LLMs without tab switching.

Zero-Egress Data Protection
Eliminates corporate data leaks before prompts hit external AI models.
Zero-Trust Resolution

How It Works

1

Highlight Any Text in Your Browser

Select text on any webpage, email, ticket, or inside your AI prompt box. The extension instantly scans the selected string in local RAM for sensitive entities.

2

Instant PII Scan & Shield Badge

A floating shield badge appears next to your cursor displaying the exact count of detected sensitive items (e.g. 'PROTECT 3 PII').

3

1-Click / Shortcut In-Place Masking

Click the shield or press Cmd+Shift+P (Mac) / Alt+Shift+P (Windows). Names, emails, phone numbers, and keys are instantly replaced with tokens ([NAME_1], [EMAIL_1]) right inside your input box.

4

Submit Safely to ANY LLM

Send your sanitized prompt to ChatGPT, Claude, Gemini, Perplexity, DeepSeek, or any AI tool. When the model replies, click the green popover button to reveal original data locally.

Customer Proof

What Teams Achieve with Local PII Masking

"The instant PII counter on highlighted text is brilliant. When drafting replies to Zendesk tickets in Claude, I just highlight the customer's email and account number, hit Cmd+Shift+P, and it masks them instantly. No tab switching, no friction."

D

David M., Senior Customer Success Lead

Verified User

"We do blind resume reviews using ChatGPT and Gemini. With PrivacyScrubber's popover, my recruiters highlight candidate names and universities directly on LinkedIn and mask them before prompting AI. It completely eliminated accidental bias."

E

Elena R., Head of People & Talent

Verified User

"I used to accidentally paste AWS secrets and Postgres connection strings into ChatGPT when debugging stack traces. The popover scans highlighted code blocks and catches database passwords and JWT tokens instantly right in the prompt box."

M

Marcus V., Full-Stack Tech Lead

Verified User

Swipe to read verified reviews

Supported Formats & Limitations

Supported Formats

ChatGPT / Claude Web InputsContentEditable Fields (Notion, Google Docs, Slack)Standard Web Textareas & InputsHighlighted Web Text & PDF Views

System Limitations

  • Requires PrivacyScrubber Chrome Extension installed
  • Processes up to 15,000 characters per selection on Free tier (unlimited on PRO/Teams)
3-Second Execution Flow

The Core Mechanism: Highlight, Scan & Mask In-Place

Latency: <2ms in local RAM

Never copy-paste confidential data to external sanitizer tabs. PrivacyScrubber's in-page popover operates at the browser DOM selection layer, analyzing text in volatile memory and swapping identifiers for structured tokens directly inside your active input.

Step 1: Highlight1

Select Any Text

Highlight snippets on web pages, email drafts, CRM tickets, or prompt boxes.

"Patient Alex Reed (SSN: 000-12-3456)..."
Step 2: Instant Scan2

Live PII Badge

The core engine parses entities in RAM and renders the count near your cursor.

PROTECT 2 PII
Step 3: Mask In-Place3

1-Click / Hotkey Tokenization

Click shield or press Cmd+Shift+P. Text swaps to tokens and preserves React state.

"Patient [NAME_1] (SSN: [SSN_1])..."
The 8-Step 'Tab Dance' Problem

Why External Sanitizers Fail Knowledge Workers

Traditional PII tools force employees to switch tabs, paste text into external web apps, copy masked tokens, paste back into ChatGPT, and repeat for every query.

  • 25–45s Friction: Wasted per prompt on repetitive copy-paste context switching.
  • 92% Employee Bypass: Teams skip external sanitizers when deadlines press, leaking raw data.
  • Blind Pasting: No real-time indication whether a highlighted snippet contains confidential keys or SSNs.
HIGH COMPLIANCE BREACH RISK · UNMONITORED WORKFLOWS
The PrivacyScrubber Solution

Instant, In-Place Browser Protection

PrivacyScrubber brings the zero-trust sanitization engine directly to your active browser cursor, eliminating tab switching entirely.

  • 0 Tab Switches: Highlight, inspect the PII count badge, and mask in 1 click or shortcut.
  • Zero-Trust Guarantee: 100% local RAM execution — 0 bytes ever leave your device.
  • 1-Click Reverse Reveal: Restore original names locally when ChatGPT or Claude replies.
AIRPLANE MODE VERIFIED · 100% LOCAL PROCESSING
Universal Ecosystem Compatibility

Works with 100% of LLMs, Support Queues & Web Apps

Operating at the browser DOM selection layer ensures universal coverage without APIs or proxies.

GenAI Models & Chatbots

Highlight draft prompts in OpenAI ChatGPT (GPT-4o/o1/o3), Anthropic Claude, Google Gemini, Perplexity, DeepSeek, Mistral, and Microsoft Copilot. Mask in-place before pressing Enter.

ChatGPTClaude 3.7Gemini 2.0DeepSeek

Customer Support & CRM

Highlight incoming tickets containing customer phone numbers, physical addresses, or account credentials. Mask in-place before asking AI to draft replies in Zendesk, Intercom, or Salesforce.

ZendeskIntercomSalesforceFreshdesk

Docs, Logs & Custom Portals

Works natively on Google Docs, Notion, GitHub / Sentry error stack traces, internal corporate AI portals (LibreChat, Open WebUI), and browser-based PDF documents.

Google DocsNotionLibreChatBrowser PDFs
Ergonomic Control

Three Ways to Trigger In-Page Selection Masking

Choose the trigger that fits your typing style, posture, and active application.

1. Floating Cursor Shield

Highlight text with your mouse. A glowing shield badge appears near your cursor displaying PROTECT N PII. Click once to mask; click a second time to open the Reveal viewer.

1ST CLICK: MASK · 2ND CLICK: REVEAL

2. Keyboard Power Shortcut

Designed for developers and touch-typists. Select text with Shift+Arrows and press Cmd+Shift+P (Mac) or Alt+Shift+P (Win/Linux) to mask in under 2ms without touching your mouse.

CMD+SHIFT+P (MAC) · ALT+SHIFT+P (WIN)

3. Right-Click Context Menu

Highlight text anywhere, right-click, and select 'Scrub PII (PrivacyScrubber)'. Perfect for static web pages, browser PDF viewers, email clients, and complex multi-layered web apps.

UNIVERSAL CONTEXT MENU DISPATCH
Architecture Comparison

In-Page Selection Popover vs. Traditional Approaches

Workflow MetricPrivacyScrubber PopoverManual Tab SanitizersCloud DLP Proxies
Highlight & Scan FeedbackInstant "PROTECT N PII" badgeNone (Must paste into tab)Silent proxy inspection
User Action Required1 Click / 1 Hotkey8 manual copy-paste stepsAutomatic (Proxy setup required)
Execution Latency< 2 ms (Local RAM)25–45s human delay600–2,000ms proxy network lag
Universal LLM Support100% (ChatGPT, Claude, any)Manual paste into anyLimited to configured routes
Third-Party Network Exposure0 Bytes leave machineExposed to external web appTransmitted to cloud proxy
Airplane Mode / Offline100% Fully FunctionalFails (Requires internet)Fails (Requires proxy tunnel)
Technical Architecture

Virtual DOM & Input Integrity Engine

Replacing text via standard DOM mutations breaks reactive state in ChatGPT, Claude, and Notion. PrivacyScrubber uses an engineered event dispatch pipeline:

  • Native Range Mutation: Employs setRangeText() and document.execCommand('insertText') to preserve cursor focus.
  • Synthetic Event Dispatch: Triggers synthetic InputEvent and ChangeEvent, instantly updating React/Vue virtual DOM and enabling the Send button.
  • Volatile RAM Vault: Stores token mappings strictly in tab-isolated ephemeral RAM for 1-click reverse reveal.
CONTENT SCRIPT: PS-UNIVERSAL-POPOVER.JS
Security Verification

30-Second DevTools Security Audit

Security teams and compliance officers can verify our zero-network architecture in 30 seconds:

  1. Open ChatGPT, Claude, or any web input in Google Chrome.
  2. Press F12 to open DevTools and select the Network tab.
  3. Set the filter to Fetch/XHR.
  4. Highlight text containing mock SSNs, emails, or names.
  5. Click the floating red shield or press Cmd+Shift+P to mask.
  6. Verify: 0 outbound network requests. 100% of processing occurs in local RAM.
ZTDS CERTIFIED · 0 SERVER CALLS

Client-Side Reliability & Audit Verification

Powered by the Zero-Trust Sanitization Engine (ZTDS). All detection, tokenization, and regex evaluation execute 100% inside your local client process boundary — eliminating cloud proxies, intermediate servers, and third-party data retention risks.

100% Local Execution RAM-Only (Zero Disk I/O) Zero Outbound Telemetry
Airplane Mode
Zero Network Dependency

Step-by-Step Guide

How to use this feature

3S total
1

Select text to scan for PII

Highlight customer logs, email snippets, or prompt drafts anywhere on your screen.

2

Inspect the detected PII count

Check the floating badge near your cursor, which automatically shows the number of sensitive entities detected.

3

Mask in-place with 1 click or shortcut

Click the floating badge or press Cmd+Shift+P / Alt+Shift+P to swap sensitive data into structured tokens without leaving the page.

4

Query any LLM with zero data leak risk

Submit the tokenized text to your preferred AI model. The AI never sees your confidential information.

What you need: Google Chrome Browser PrivacyScrubber Extension (Free) Any webpage, document, or AI chat prompt (ChatGPT, Claude, Gemini, Perplexity)

Frequently Asked Questions

Technical Details & Privacy Architecture

How does the in-page popover scan highlighted text for PII?
The instant you highlight text anywhere in Google Chrome, the PrivacyScrubber content script intercepts the selection bounds and passes the text to our local deterministic scanning engine in browser RAM. Within 2 milliseconds, it scans across 50+ entity patterns (names, emails, phones, SSNs, credit cards, API keys, medical codes) and updates the floating popover shield with the exact entity count (e.g. 'PROTECT 3 PII').
Does the in-page popover work with ANY LLM and AI chatbot?
Yes. Because the popover operates at the browser DOM selection layer, it is universally compatible with 100% of AI chatbots and web interfaces — including OpenAI ChatGPT (GPT-4o / o1 / o3), Anthropic Claude, Google Gemini, Perplexity AI, DeepSeek, Microsoft Copilot, Mistral Le Chat, Poe, Cursor Web, and internal corporate AI chat portals. You can also highlight text on static websites, PDFs, Zendesk tickets, or Google Docs and mask it before copying.
Does in-place masking break ChatGPT's Send button or React/Vue input state?
No. Modern reactive web applications like ChatGPT and Claude maintain internal virtual DOM input states. PrivacyScrubber's popover uses native `setRangeText()` and `document.execCommand('insertText')` combined with synthetic InputEvent and ChangeEvent dispatchers. This ensures that the web app's underlying framework state updates immediately, allowing you to hit Enter or click Send without input synchronization glitches.
Can I use keyboard shortcuts to scan and mask text without using the mouse?
Yes. After highlighting text with your keyboard (e.g. Shift + Arrow keys), simply press Cmd+Shift+P on macOS or Alt+Shift+P on Windows/Linux. The text will be scanned and tokenized in-place instantly in local memory without moving your cursor.
How does the right-click context menu compare to the floating popover?
Both triggers run the exact same local zero-trust sanitization engine. The floating popover provides the fastest 1-click visual feedback showing the exact number of detected PII entities. The right-click context menu ('Scrub PII with PrivacyScrubber') is ideal for static web pages, browser-based PDF documents, emails in Gmail/Outlook, or complex web applications with layered floating panels.
How do I restore original names and values when the AI replies with tokens?
PrivacyScrubber saves an encrypted ephemeral session map in your browser tab's volatile memory. After masking, the popover button switches to a green 'VIEW REVEAL' badge. When ChatGPT or Claude replies with the tokens (e.g. [NAME_1], [EMAIL_1]), clicking the green badge or opening the extension popup's Reveal tab restores all original values in 1 click locally.
Is my highlighted text or prompt ever sent to external servers?
Never. PrivacyScrubber adheres to a strict Zero-Trust Data Sanitization (ZTDS) architecture. All regex parsing, entity classification, token generation, and RAM session map vaulting execute 100% locally inside your browser's V8 engine. You can disconnect Wi-Fi or turn on Airplane Mode and verify that the popover continues to scan and mask text with zero degradation and zero network calls.
What happens if I highlight text that is already masked with tokens like [NAME_1]?
The popover includes intelligent guard logic that detects existing PrivacyScrubber token formats. If you highlight an already-tokenized string, the extension displays an informational toast ('Already masked — token is safe') and prevents redundant double-tokenization.
Does the popover support custom corporate regex rules and industry profiles?
Yes. If your company defines custom regex patterns (e.g. internal employee IDs, project codenames, custom customer UUIDs) or enables specialized industry profiles (HIPAA Healthcare, PCI-DSS Financial, Legal Work-Product), the in-page popover applies those custom rules in real-time during every selection scan.
Can I disable or customize the floating shield on specific websites?
Yes. Clicking the PrivacyScrubber extension icon opens the popup controls, where you can toggle the universal popover on or off globally or configure site-specific rules according to your workflow.
100% Zero-Trust Deployment

Protect Your Team's AI Prompts in Under 30 Seconds

No server uploads. No account required. 100% offline in your browser's local RAM.

Detected Sensitive Token
[TOKEN]
Original masked value:
Sensitive Data
Support
Sanitize Files
Mask AI Prompt