Purplelink
← All guides

Best tools to redact personal information before you use ChatGPT and other AI chats (2026)

What each option does, what it costs, where the checking happens and what it misses, for anyone who keeps pasting client, patient, student or personal details into an AI chat. Three of the options are not software you install: provider settings, a local model and find-and-replace.

Disclosure up front: I make one of the tools on this list (Outbound Veil, a Mac menu-bar app). I have tried to write the comparison honestly, and in several cases a competitor is the better choice. Predact is free and handles files, which Outbound Veil does not. PrivacyScrubber works on Windows and Linux, which Outbound Veil does not. If your data cannot leave your machine at all, a local model beats every redaction tool here. Prices and platforms were read on each vendor's own page on October 4, 2026, and they change. Where a vendor says its software runs on your device, I write "says": I have not audited that.

What you actually need to stop leaking data into AI chats

Redaction means replacing specific details in your text, such as a name, a date of birth or a card number, with a placeholder before the text goes to the AI. The model still answers, because it sees "[PERSON_1] was seen on [DATE_1]" and can work with that. You put the real details back yourself, or a tool does it from a saved mapping.

There are four places to intervene, and the tools here sit in different ones:

  1. As you type or paste. A menu-bar app or browser extension watches the text box and flags or replaces details before you press send. This is where the mistake usually happens.
  2. Before you paste. An app or web page where you drop in text or a file and paste the clean copy. It works on the days you remember it.
  3. At the account. The provider's settings and plan decide whether what you send is used for training. This removes nothing from their servers.
  4. Off the cloud. A model that runs on your own computer, so nothing is sent.

All of them share two limits, covered in what redaction cannot do: detection misses things, and a redacted note can still describe a situation someone could recognize.

The shortlist

  1. Outbound Veil: $29 once, a Mac menu-bar app that checks the text field you are typing in.
  2. Predact: free, Mac and Windows, drop in documents, images or text.
  3. PrivacyScrubber: browser-based, free tier, extension for 12 chat and work sites.
  4. Microsoft Presidio: free open-source library for developers.
  5. The provider's own controls: ChatGPT settings, Temporary Chat, business plans and the API.
  6. A local model: Ollama or LM Studio, so nothing leaves your machine.
  7. Find and replace by hand: free, slow, and still useful.

Those seven cover most situations. Seven more tools and seven narrower ones follow.

Outbound Veil

Cost: $29, one-time, updates included, after a free 7-day trial with no account. Platform: macOS 14 or later, Apple silicon and Intel. Mac only. Status: version 1.0.1.

Outbound Veil lives in the menu bar and reads the text field that has focus, through macOS Accessibility. When it finds something it shows a badge with the number of findings and highlights the matching text where the app allows it. You can ignore a finding, or press Redact all, which rewrites the field in place with labelled placeholders such as [SSN_1] or [EMAIL_1]. In apps you choose, it can also hold the send key until you have decided. It looks for names, addresses, phone numbers, email addresses, government, tax, bank and card numbers, dates of birth, medical record numbers and IBANs.

A model that runs on your Mac does the checking. Nothing you type is stored or sent, and the app has no analytics. The model is Rampart by National Design Studio, released under CC BY 4.0, and I did not train it. Purplelink ported Rampart's processing code to Swift and added rules for dates of birth, medical record numbers and IBANs. The model file is unchanged.

What it's good at: sitting where the mistake happens, in any Mac app it can read rather than one website. I tested TextEdit, Notes, Microsoft Word, Messages and text areas in Chrome. In the ChatGPT and claude.ai prompt boxes in Chrome, Redact all works, but the whole box is outlined instead of each word highlighted.

What it lacks: Mac only, and names in Latin script only. It flags the names of public figures too, which you can ignore, and it will miss some things and flag some things that are not personal information. It checks text in fields, not files, so a PDF or an image needs another tool from this list. Some apps do not expose their text fields to macOS: in my testing the Apple Mail compose window could not be read, and Safari, Slack, VS Code and the ChatGPT and Claude desktop apps are not on the tested list. It needs the Accessibility permission, plus Input Monitoring if you turn on send hold. After Redact all it does not put the original values back into the AI's answer; you swap them back yourself. By default it does not report a bare city, state or ZIP code. It is new, with no track record, and it is not a compliance product.

Pick Outbound Veil if you write or paste client, patient or student details into chat boxes on a Mac and want a check as you send. Pick something else if you are on Windows, mostly share files or screenshots, or your data has names in non-Latin scripts. The trial is free for seven days; keeping it is $29, once.

Predact

Cost: Free, no card; you enter an email address to get the download link. Platform: Mac (macOS 14 recommended, Apple silicon supported) and Windows.

Predact is a desktop app where you drop in PDFs, Word files, text files, images and email clippings, or paste text and screenshots. It shows what it found, lets you select more words to redact, and you copy the result out or open a built-in browser linked to ChatGPT, Claude, Gemini or Perplexity. Its page says processing is local, with a Safe Mode that goes online only when you export to an AI service and a Fully Offline Mode that blocks all network use. "Persona filtering" swaps in consistent made-up details instead of tags.

What it's good at: being free, handling files and images, and running on Mac and Windows. What it lacks: it does not check what you type in other apps, so using it is a step you have to remember. The local-processing statement is the vendor's claim.

Pick Predact if your risk is documents, scans or screenshots, you are on Windows, or the budget is zero. Outbound Veil's case is that the check happens while you type, whether or not you remembered.

PrivacyScrubber

Cost: Free up to 15,000 characters per scrub; Pro is $15 a month or $110 once; Teams is $99 a month; a developer SDK is $299 a month. Platform: a web app, a Chrome extension, an MCP server and a Node.js SDK.

The Chrome extension adds a shield button to chat boxes on 12 listed sites, including ChatGPT, Claude, Gemini, Copilot and Perplexity. Click it, or press Alt+Shift+X, and the text becomes placeholders such as [NAME_1]. After the answer arrives, "Reveal Original Data" restores the real values inside the page. Its page says all of this runs in the browser tab with no server contact.

What it's good at: the full loop of redact, ask, restore, on many sites, on any system that runs Chrome. What it lacks: it lives in the browser, so it does not help in a desktop app. You press the button, so a rushed send can skip it. Larger inputs, PDF OCR and custom rules need a paid plan. I have not tested the local-processing claim.

Pick PrivacyScrubber if you use several AI sites in a browser, want the original values restored in the reply, and are on Windows or Linux or do not want an app.

Microsoft Presidio

Cost: Free, MIT license. Platform: a Python library, with Docker and Kubernetes options.

Presidio is an open-source framework for finding and anonymizing personal data in text, images and structured data, using named-entity recognition, regular expressions, rules and checksums. You can write your own recognizers, and it runs wherever you run it with no external service. The project warns there is no guarantee it finds everything. It has moved from Microsoft's GitHub organization to a community-owned one, and its documentation says that transition is under way.

What it's good at: control. You can run it over a folder of interview transcripts and keep the pipeline in your own infrastructure. What it lacks: an interface. It will not watch a chat box, and nothing happens until you write the code that calls it. How well it works on your data is yours to measure.

Pick Presidio if you write code and need to scrub a dataset or a set of transcripts before sending it to an AI service. Everyone else should pick an app.

The provider's own controls

Cost: The settings are free; business plans are priced by OpenAI. Platform: any.

This is not redaction, and it is the first thing to fix. OpenAI's help pages describe three things worth knowing. Under Settings, Data Controls, "Improve the model for everyone" decides whether chats on a personal account can be used to train its models. Temporary Chat is documented as not appearing in your history, not creating or updating memories and not being used to improve models while it stays temporary, though OpenAI may keep a copy for up to 30 days for safety. And for ChatGPT Business, Enterprise and Edu and for the API platform, OpenAI says business data is not used for training by default unless the customer opts in. For regulated health data there is a further contract, the Business Associate Agreement; the addendum OpenAI publishes names parts of its API as eligible, and which ChatGPT plans qualify is a question for OpenAI and your counsel. Claude, Gemini and the others have their own settings.

What it's good at: it covers everything you type, costs nothing at the free end and settles the training question. What it lacks: your text still reaches the provider's servers and is kept for some period. A setting is a promise, not a physical barrier: in 2025 a US court order in a newspaper lawsuit reportedly required OpenAI to preserve chats that users had deleted, for a period that reportedly ended in September 2025, with some of what was preserved still held. And a business plan does not change what you are allowed to share. Your duties to a client, patient or student are the same either way.

Fix this layer first. For a team, a business plan with a signed agreement matters more than any redaction tool.

A local model

Cost: Free to download. Platform: macOS, Windows and Linux for both Ollama and LM Studio.

Ollama and LM Studio run open models on your own computer. LM Studio's documentation says it can operate entirely offline once a model is downloaded, and its privacy policy says messages, chat histories and documents are not transmitted from your system when you run models locally; update checks and model downloads do use the network. Ollama has a catch: it also offers cloud models, whose names end in :cloud, that run on Ollama's servers. Its documentation says prompts to those are processed there, and that cloud features can be turned off. Choose a local model if the point is that nothing leaves the machine.

What it's good at: it is the only option here where redaction is not needed, because there is no recipient. You can paste the whole note. What it lacks: setup time, memory and capability. Open models that fit on a laptop are generally less capable than the largest hosted ones, which matters for hard reasoning and less for summarizing or drafting. That is my judgment, not a benchmark.

Pick a local model if the material must stay on your machine and a smaller model is good enough for the job.

Find and replace by hand

Cost: Free. Platform: any text editor.

Copy the text into a plain-text editor, replace each name with "Person A", "Person B" and each date with "Date 1", and keep a small key in a separate note. Ask your question, then reverse the replacements in the answer. It works with any AI service, no vendor sees anything, and it forces you to read every line, which a tool does not. The cost is reliability on long text: a misspelled surname, a nickname or an employer slips through. Use it for short, occasional documents, or as the read-through after a detector's first pass.

Seven more tools

Each is real and useful to someone. None is on the shortlist because one of the seven above covers the same ground for most people, or the tool addresses a different problem.

Caviard

Cost: Free for up to 10 protected values per document; a lifetime plan at $9, which the page lists as an early discount from $15.30. Platform: Chrome extension for ChatGPT and DeepSeek.

It masks details in the browser before a prompt is sent, and Alt+R toggles original and redacted text. Its page describes detection as pattern-based, which suits emails and card numbers and tends to be weaker for names; I have not tested it on names. Pick Caviard if you use only ChatGPT or DeepSeek in Chrome and want a low-priced lifetime plan.

ClipScrub

Cost: $29 once, 14-day free trial. Platform: macOS 15 or later; the AI-enhanced detection needs Apple silicon.

The closest Mac peer on price. ClipScrub redacts PDFs, Word files, screenshots, screen recordings, JSON, CSV, XML and clipboard text, on the Mac and with no internet needed, according to its page. A keyboard shortcut starts it. It does not watch your typing, and it says it is not a compliance service and does not guarantee complete de-identification. Pick ClipScrub over Outbound Veil if your material is files, screenshots or recordings rather than text typed into boxes.

Clipmask

Cost: Free to download, with no subscription and no time limit. Its page also mentions a 500-copy trial limit, after which you may decide to continue, and gives no price for that. Platform: Apple silicon Macs only, macOS 14 or later.

The clipboard-only sibling of Predact, made by QCG. You copy text as usual, and a shortcut (Option+Space) offers a redacted version to paste. Its page says detection runs on the Mac, and that the only server contact is a check that the app is a licensed current version. Pick Clipmask if you want a free Mac tool that works on whatever you copy.

RedactDesk

Cost: Free, open source (MIT). Platform: macOS 14 or later.

A Mac app for redacting PDFs, scanned ones included, with OpenAI's open-source privacy-filter model running locally. It deletes the text from the PDF rather than covering it. PDFs only. Pick RedactDesk if your whole job is PDFs.

BlurData

Cost: $79 a year or $149 once for one person; team plans are listed. No free tier is shown. Platform: macOS 13 or later, with an iOS version.

It finds and blacks out personal details in JPG and PNG screenshots and in PDFs, on the device, in batches. Pick BlurData if your leaks are screenshots.

Nightfall

Cost: By quote, per user per year, in two editions. Directories quote conflicting figures, so I give none. Platform: browser, endpoint, SaaS and AI-app coverage, run by an administrator.

Data loss prevention for organizations: a security team sets policies, and the software blocks or flags sensitive data going into AI apps, email and other services. Pick Nightfall if you have to enforce a policy across many employees.

Microsoft Purview

Cost: Depends on your Microsoft licensing, which I did not confirm. Platform: managed devices, Edge and other browsers.

Microsoft's documentation describes Endpoint DLP policies that block pasting and uploading sensitive information to AI app websites on managed devices, and Edge policies that inspect prompts typed or pasted into consumer AI apps including ChatGPT, Copilot, DeepSeek and Gemini. Pick Purview if your organization already runs Microsoft 365 security and IT can turn it on.

Seven narrower options, most of them young, with a handful of installs or stars as of this writing. ChatGPT Privacy Shield is a free Chrome extension for ChatGPT only, with Pro ($9 a month) and Team ($49 a month) plans listed as a waitlist. Rescriber is a free, open-source ChatGPT extension from Northeastern University researchers. PII Scrubber (ChatGPT, free for 5 uses a day, Pro $7 a month) and Paste Redactor (four browsers, free for 100 redactions a month, then $1 a month) are small extensions with paid tiers. PIIGuardAI is an open-source Mac menu-bar proxy that blocks AI requests containing patterns such as emails and card numbers but uses regular expressions only. Maskbase is an open-source Mac app for documents. Veil (helloveil.com, $8 a month) is a different company's meeting recorder with a privacy engine; its changelog lists nothing that checks what you type in other apps.

What redaction cannot do

Some vendors above say this plainly, and everyone should assume it. Rampart, the model behind Outbound Veil, calls itself harm reduction, not perfect protection, and Presidio says there is no guarantee it finds everything.

HIPAA, FERPA and client confidentiality

This is not legal advice, and the answer depends on who you are and what you hold.

HIPAA. The rule that defines de-identified health information (45 CFR 164.514) offers two routes: an expert's documented determination that the risk of identifying a person is very small, or removal of a listed set of about 18 identifier types, including names, geographic detail, dates tied to a person, contact numbers and record and account numbers, with no actual knowledge that what is left could identify someone. A detector that catches names and numbers is neither route, so text it has cleaned can still be protected health information. Whether you may send data to an AI service at all usually turns on a Business Associate Agreement and your organization's policy, so ask your compliance officer.

FERPA. The law gives parents, and students once they are 18 or in postsecondary school, rights over personally identifiable information in education records. If you grade, advise or write recommendations, check your institution's AI policy before pasting anything that names a student. Removing the name is a habit, not a rule.

Client and participant confidentiality. Lawyers, therapists, consultants and researchers have duties in codes of conduct and contracts. The American Bar Association's Formal Opinion 512 (July 2024) is reported to say that a lawyer's confidentiality duty applies to generative AI tools, and that tools which train on inputs call for the client's informed consent. For research, your IRB protocol and data management plan probably already say who may see participant data, and an AI service is a new recipient. For manuscripts, see what publishers allow when you run your own manuscript through AI.

Decision matrix

A routine that holds up

  1. Write down what must never go in, then fix the account: turn off the model-improvement setting or use a business plan, and use Temporary Chat for one-off questions.
  2. Put a detector where you type. A menu-bar app or an extension, or a scrubber page you open every time.
  3. Test it with fake data first. Paste a made-up record with a name, a number, an address and a date, and see what it catches. This applies to every tool here, including mine, and takes two minutes.
  4. Read what you are about to send. Look for what a detector would not know: a nickname, an employer.
  5. Ask with placeholders and restore by hand. Keep any key in a separate local note. For the most sensitive material, use a local model or skip AI.

Frequently asked

What is the best way to remove personal information before using ChatGPT?

Use layers. Set the account so chats are not used for training, or use a business plan. Put a detector where you type. Read what you are about to send. For material you cannot send at all, use a local model.

Does ChatGPT Temporary Chat keep my data private?

Only partly. OpenAI says a temporary chat stays out of your history, creates no memories and is not used to improve its models while it remains temporary, but that it may keep a copy for up to 30 days for safety. The text still reaches OpenAI's servers.

Is a redaction tool enough for HIPAA?

No. HIPAA defines de-identified data by an expert determination or by removing a listed set of identifiers with no actual knowledge that the rest could identify the person. A tool that catches names and numbers is neither. This is not legal advice; ask your compliance officer or counsel.

Do these tools send my text to a server?

Most say detection runs on your device or in your browser. That is the vendor's claim, not something I tested. Enterprise DLP and the provider's own plans involve servers by design. A local model keeps text on your machine.

Is there a free tool to redact personal information for AI chats?

Yes. Predact (Mac and Windows) is free, and Clipmask (Apple silicon Macs) is free to download, with a 500-copy trial limit mentioned on its page. RedactDesk is a free, open-source Mac app for PDFs. Rescriber is a free, open-source Chrome extension for ChatGPT. PrivacyScrubber and Caviard have free tiers with limits.

Is there a Mac app that checks for personal information as I type?

Outbound Veil, which Purplelink makes, checks the text field you are typing in, in the apps it can read. It costs $29 once with a 7-day trial. Other Mac tools work on what you copy or drop in: Clipmask, ClipScrub and Predact. I found no other that watches the typing itself, but I may have missed one. Outbound Veil is Mac only, recognizes names in Latin script only, and will miss some things.

Should I run a local model instead of redacting?

If the material must not leave your machine, yes. Ollama and LM Studio run open models on your computer. The cost is setup time and usually a less capable model. Ollama also offers cloud models that run on its servers, so choose a local one.

Related guides

From the team behind these tools

Typing client notes into AI chats on a Mac?

Outbound Veil is a Mac menu-bar app that checks the text field you are typing in for names, numbers and addresses, marks what it finds, and can redact it in one click. The checking runs on your Mac. $29 once, all updates included.

Requires macOS 14 or later. Free 7-day trial, no account. Mac only, Latin-script names only, and it will miss some things.