How PrivacyScrubber Removes PII from AI Prompts
The AI data privacy tool that lets you redact PII and anonymize data in ChatGPT, Claude, and Gemini prompts — with zero trust architecture, zero bytes sent to servers, and zero data residue. See the 4-step local pipeline across all product planes.
Intercepting Data at the Local Browser Boundary
When employees paste raw client emails, medical records, or source code into cloud LLMs, the data is logged into remote model providers. PrivacyScrubber acts as an air-gapped cryptographic proxy executing inside the user's browser, replacing PII with secure tokens before network transmission.
Traditional cloud DLPs add 800–1,500ms roundtrip delays. PrivacyScrubber's deterministic AST lookaround engine runs in local browser memory at 8.4 MB/s (<1ms latency), eliminating API bottleneck delays completely.
Because 0 bytes of confidential data are transmitted to PrivacyScrubber servers, no third-party data processor relationship is created, eliminating procurement bottlenecks for Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs).
Session token maps exist strictly in browser tab memory. Closing the tab or reloading permanently overwrites memory buffers (Uint8Array.fill(0)), leaving zero forensic trails for breaches.
The 5 Zero-Trust Planes: Real Capabilities & Workflows
PrivacyScrubber operates across five distinct technical planes, delivering unified data sanitization whether you are working in a web browser, inside an AI chat, writing code in an IDE, processing backend data pipelines, or managing enterprise fleet governance.
Zero-Trust Web Workspace
A standalone, zero-installation browser workspace running entirely in local memory. Input and output containers operate within a closed Shadow DOM (#inputTextHost), preventing malicious extensions or third-party scripts from key-sniffing raw text.
.xlsx/.csv while preserving mathematical formulas, column headers, and sheet schema for ChatGPT Advanced Data Analysis.Uint8Array.fill(0) upon sanitization completion.Browser AI Shield & In-Page Injectors
A lightweight Google Manifest V3 extension that embeds native protection controls directly inside ChatGPT, Claude, and Gemini interfaces without requiring copy-pasting to separate tabs.
.ps-floating-shield) for instant in-place sanitization and inspection.Local MCP Prompt Security Gateway
An official Model Context Protocol server (@privacyscrubber/mcp-server) running locally over stdio JSON-RPC. It connects natively to Cursor IDE, Windsurf, Cline, and Claude Desktop.
Headless SDK & Pre-Commit Guard
An ultra-fast, in-memory Node.js & WASM library (@privacyscrubber/sdk) and standalone binary CLI (ps-guard) engineered for backend microservices, ETL pipelines, and AI RAG vector stores.
cat prompt.txt | ps-guard or install pre-commit git hooks to intercept hardcoded API keys, JWTs, and AWS tokens before repository push.npx @privacyscrubber/sdk memo generates a formal zero-server statutory clearance brief for security committees.Decentralized Fleet Governance & CISO Cockpit
Department-wide security governance that enforces uniform PII sanitization baselines across thousands of browser endpoints without a central database, delivering signed compliance receipts for SOC 2, HIPAA, and GDPR auditors at a flat $99/mo unlimited seats.
The 4-Step Zero-Trust Pipeline
How sensitive data moves from input to AI and back without ever leaving your computer.
Because PrivacyScrubber has zero back-end servers processing customer prompt data, there is no user database, no password hashing, and no employee credential tracking. You never create an account or sign up for a trial to sanitize data.
Source Input
Data enters via direct text paste, document upload (.docx, .pdf, .xlsx, .csv), browser text selection popover, or typing natively inside ChatGPT/Claude via our Chrome Extension.
Supports: Text, DOCX, PDF, XLSX, MCPIn-Memory Scrub
The local Javascript client detects PII, financial metrics, and credentials offline. Sensitive entities are securely swapped with cryptographic tokens like
[NAME_1]or[PATIENT_1].Speed: ~13ms · 0 Server RequestsSafe AI Dispatch
You submit the sanitized prompt (containing only safe tokens) to ChatGPT, Claude, Gemini, or local models. Neural networks analyze the problem without logging real corporate PII.
Result: Zero PII in Remote Model LogsLocal Reveal
The AI's generated response is pasted into Reveal Originals. PrivacyScrubber re-hydrates tokens with original data locally using the ephemeral session map stored in browser RAM.
1-Click Symmetric Recovery in RAM
Two Distinct Modes for Two Distinct Workflows
PrivacyScrubber separates generative AI prompt sanitization from legal document redaction. Select the exact output format your task requires.
AI Tokens Mode
LLMs, Prompts & Teams Replaces sensitive entities with structured, context-preserving surrogate badges like [NAME_1], [EMAIL_1], and [PHONE_1].
- Context Preserved: AI models understand syntactic roles and actor relationships without knowing real identities.
- 1-Click Symmetric Restore: Paste AI output back into Reveal to re-hydrate real data in browser RAM.
- Team Handoff Ready: Encrypt session maps with Argon2id + XChaCha20 for colleague collaboration.
Classic Blackout Mode
Legal, Court & FOIAApplies solid black rasterized bars directly over sensitive pixel coordinates, obliterating underlying text layers, vector fonts, and hidden document metadata.
- Zero Underlying Text: Destroys vector characters to prevent copy-paste leaks via
Cmd+Aorpdftotext. - Court & FOIA Compliant: Satisfies Federal Rules of Civil Procedure 5.2 and HIPAA Safe Harbor redaction guidelines.
- Metadata Stripped: Purges author names, modification timestamps, and revision tags from PDF headers.
Interactive Execution Simulator
Three professionals. Three tiers. One zero-trust engine. Test how each plan protects real workflows.
Sarah — Marketing Manager
40-person SaaS startup · Uses ChatGPT daily for client emails and campaign copy
Need to sanitize complex spreadsheets (.xlsx), PDFs, or custom corporate codes?
Batch document parsing, offline OCR, spreadsheet table masking, and unlimited custom regex rules are unlocked under PRO.
Marcus — Compliance Analyst
Mid-size financial services firm · Reviews NDAs, vendor spreadsheets, and deals
Need to enforce organization-wide policies across 10+ employees?
Encrypted session handoff (Argon2id + XChaCha20-Poly1305), MDM Blueprint locking, and CISO SHA-256 PDF audit receipts are included in TEAMS.
Diana — VP of Information Security
500-person fintech · Board mandate: "Zero raw PII in any external AI tool"
Require full air-gapped on-premise source code deployment?
Enterprise Source License provides complete on-premise execution behind internal VPNs for defense and banking sectors.
Ready to Remove PII from Your AI Prompts?
Zero accounts because there is no server. No expiring trial needed because the Community Tier is free forever. Paste your text and scrub immediately in local RAM.
Frequently Asked Questions
Comprehensive technical answers on how PrivacyScrubber sanitizes data across all 5 planes.
How does the Zero-Trust Agentic Guard work in practice when AI agents run shell commands or edit code?
guard_exec) or inspect configuration files (via guard_read_file), the output is intercepted in volatile RAM, scanned across 30 industry detection profiles, and all API keys, database credentials, and customer PII are replaced with anonymous tokens (e.g. [API_KEY_1], [EMAIL_1]). The cloud LLM reasons only over sanitized placeholders. When the agent writes a patch or updates code (via guard_apply_patch), the tokens are reversed back to authentic local secrets in RAM and written safely to disk with an automatic .bak backup. Zero secrets ever touch cloud servers. Does PrivacyScrubber send my prompt or file data to any server?
Why doesn't PrivacyScrubber require a user account, password, or free trial signup?
What happens to the session map when I close or reload the browser tab?
What is the difference between AI Tokens mode and Blackout mode?
[NAME_1], [EMAIL_1]). This allows AI models (ChatGPT, Claude, Gemini) to comprehend entity roles and logical flow while preventing personal data ingestion, and enables 1-click original recovery via Reveal. Blackout mode is designed for court filings, legal discovery, and FOIA disclosures: it renders permanent, solid black raster bars over pixel coordinates and completely purges the underlying vector text layer to ensure zero copy-paste leakage. Why do standard PDF blackout tools leak data, and how does PrivacyScrubber prevent it?
Cmd+A → Copy, or extract it with command-line tools like pdftotext. PrivacyScrubber executes true Secure Raster Flattening: each page is rendered onto an off-screen graphics canvas in local RAM, PII coordinates are overwritten at the pixel level (either with solid blackout bars or contextual AI Tokens), and a brand-new PDF is synthesized from clean raster bitmaps. The original text layer is physically destroyed and cannot be recovered. Do I need a HIPAA BAA or GDPR DPA with PrivacyScrubber?
What is the CISO Procurement Memo and how do enterprise teams use it?
What is the difference between the Free and PRO tiers?
How does the Excel Spreadsheet Scrub work without corrupting table formulas?
How does the Chrome Extension In-Page Selection Popover work?
.ps-floating-shield). Clicking it immediately tokenizes the selected text in-place and opens a clean popover showing all identified entity chips with 1-click false-positive unmasking. Can I use PrivacyScrubber as a PII MCP Server for Cursor or Claude Desktop?
@privacyscrubber/mcp-server that integrates directly with Cursor IDE, Windsurf, Cline, and Claude Desktop. It acts as an offline pre-flight prompt security gateway, intercepting API keys, connection strings, and PII locally in RAM before they leave your workstation. How does TEAMS encrypted session handoff work without a server database?
What rights does a Team Administrator have compared to Managed Team Members in TEAMS?
[PATIENT_ID]), and default compliance profiles in the Teams Dashboard. When the Admin exports a cryptographically signed Blueprint with Lock Rules enabled, Managed Team Members receive a locked, read-only configuration across their Web App and Chrome Extension (badged as Enterprise), preventing employees from altering or bypassing corporate DLP policies. How does closed Shadow DOM sandboxing protect my data from malicious scripts?
How does PrivacyScrubber prevent data residue in system RAM (V8 memory wiping)?
Uint8Array.fill(0) in local memory immediately after use, ensuring zero sensitive residue remains in RAM before garbage collection. What is the difference between Token Labels and Custom Regex Rules?
NAME → PATIENT or ID → CASE_NUMBER) so that the LLM receives domain-accurate semantic context in its prompt without custom regex code. Can corporate accounts pay via manual invoice or wire transfer (SWIFT/SEPA)?
How does license key custody, non-transferability, and emergency revocation work without user tracking?
Why does the Chrome extension convert uploaded files (PDF/DOCX) into .txt, and how do file upload quotas work?
.txt payload into the AI input. This eliminates 100% of hidden binary metadata while allowing LLMs to parse the content natively. The Free tier includes a daily quota of 3 document uploads per 24 hours (and up to 15,000 characters per scrub), while the PRO and TEAMS plans provide unlimited document processing and custom rules. What are the exact operational boundaries between Personal PRO, Team Workspace, and Developer SDK licenses?
- PRO ($15/mo or $110 Lifetime): Single-user personal license valid on up to 3 personal devices (Web, Chrome, IDE MCP). Strictly non-transferable.
- TEAMS ($99/mo flat): Organization-wide internal workspace covering unlimited internal staff with Master Key Isolation. Staff access the tool via encrypted Magic Links or managed Chrome policies without exposing master credentials.
- DEVELOPER SDK ($299/mo or $2,990/yr): Headless execution across unlimited internal backend nodes, microservices, ETL pipelines, and internal RAG vector databases. Embedding into customer-facing commercial SaaS for third-party resale requires an OEM/Enterprise contract.
How do developers integrate @privacyscrubber/sdk out of the box, and what are the operational capabilities and state risks?
wrapOpenAI(new OpenAI()), or via standalone sanitize() and restore() in under 1ms local RAM latency. It intercepts outbound prompts before network transmission, tokenizes PII and infrastructure secrets into semantic placeholders ([NAME_1], [AWS_KEY_1]), and rehydrates LLM responses locally—including streaming SSE tokens via sliding window reconstruction. Operation is completely plug-and-play with zero background servers or Python/spaCy daemons. The primary operational risk to manage is state custody in distributed microservices: tokenMap is volatile and RAM-only, requiring stateless microservices to preserve or pass the token map between pre-processing and post-processing nodes. Is the PrivacyScrubber MCP Server completely air-gapped and zero-network?
@privacyscrubber/mcp-server package executes strictly in local machine memory over standard stdio JSON-RPC transport. It makes zero outbound network requests, transmits zero telemetry, and performs all PII sanitization and token mapping exclusively in your local volatile RAM, satisfying stringent IDE security policies across Cursor, Windsurf, and Claude Desktop. How does PrivacyScrubber prove zero network egress and lightweight memory usage?
Does dropping or uploading a transcript or document into PrivacyScrubber transmit my file to a server?
How can solo coaches, therapists, and executive consultants sanitize client meeting transcripts (Zoom, Teams, Google Meet) without cloud exposure?
[NAME_1], [ORGANIZATION_1]) in volatile RAM. Third, submit the sanitized transcript to Claude or ChatGPT to extract themes, check coaching quality, or draft session summaries. Finally, click Reveal in PrivacyScrubber to rehydrate original client names locally. Zero client personal data ever touches third-party servers. How does PrivacyScrubber handle European names with initials and national identity numbers like Dutch BSN, German Steuer-ID, or French NIR?
How does PrivacyScrubber protect enterprise RAG vector databases and prevent GDPR Article 17 re-indexing costs?
@privacyscrubber/sdk into your ingestion pipeline, raw PII is swapped with deterministic cryptographic tokens in Node.js heap (<0.065ms) before vector embedding. When a deletion request arrives, organizations simply purge the local key mapping, achieving instantaneous O(1) mathematical erasure at $0 infrastructure cost. 