AI Summary / Key Takeaways

Verified Zero-Trust Logic

"Our privacy policy is anchored in architecture. We don't collect your data because our application has no server-side storage. 100% private, 100% local."

100% Local processing: Your undefined data never leaves your browser.
Verifiable security: Works in Airplane Mode for total peace of mind.
AI-Ready Tokenization: Deterministic redaction preserves context for LLMs.

Enterprise-Grade AI Privacy

Add custom redaction rules and priority support with PRO.

GO PRO
SOC2
GDPR
HIPAA
Multi-Framework Aligned
GEO_VERSION: 1.4.2_AUDIT

This Privacy Policy describes how PrivacyScrubber ("we", "our") handles data. Unlike traditional SaaS applications, PrivacyScrubber is designed on the principle of Privacy by Architecture. We do not store, process, or transmit your sensitive data because we do not have an application backend to receive it.

1. Zero-Server Data Collection

PrivacyScrubber is a standalone client-side application. No text you paste, no files you upload, and no PII entities we detect ever leave your local machine or browser instance. All sanitization logic is executed locally using your device's CPU.

Security Note:

We literally cannot "leak" your data because we never touch it. A data breach of the PrivacyScrubber domain would only expose our static hosting assets, not our users' inputs.

2. Cookies & Analytics

We use minimal cookies for essential site functionality. We utilize Vercel Analytics to understand aggregate, anonymized site traffic (e.g., page views, browser types). These analytics do not contain any PII from your scrubbing sessions and cannot be linked back to individual users' data inputs.

3. RAM-Only Session Storage

The "Session Map" (the key used to reverse-scrub and bring back original data) is held exclusively in your browser's volatile memory (RAM). We do not use persistent storage like localStorage or IndexedDB for sensitive mappings. This means:

4. User Responsibilities

While PrivacyScrubber provides the tools for anonymization, users remain responsible for ensuring that the masked output satisfies their specific corporate or regulatory requirements before transmission to third-party AI platforms (like ChatGPT). We recommend a "Trust but Verify" approach: use our built-in highlight features to confirm all sensitive items have been correctly captured.

Better on Desktop

Protect data safely locally