Redact PII before ChatGPT: the complete guide
To use ChatGPT on sensitive documents safely, redact personally identifiable information (PII) on your device before the prompt is sent — replace names, emails, phone numbers, IBANs and internal terms with placeholders like [PERSON_1], keep the mapping local, and restore the real values in the answer on your screen only. This is called reversible redaction: the AI works on the structure of your text, with every detected identifier replaced by a marker — and a pre-send review shows exactly what leaves.
Why redact before sending — not after
Once a prompt reaches the provider, you have no technical control left: retention, logging, review and training policies are contractual promises that vary by plan and change over time. Redacting before the data leaves your machine is the only control you can verify yourself. Under the GDPR this is data minimisation (art. 5) applied to AI. One precision matters: pseudonymised data generally remains personal data under the GDPR — the marker↔value mapping exists, even though it stays on your device (see the CNIL's guidance on pseudonymisation). Redaction therefore reduces the risk and the exposure surface of a transfer; it does not lift the rules that govern it.
What counts as PII in a prompt
- Direct identifiers: names, email addresses, phone numbers, postal addresses.
- Strong identifiers: IBANs, card numbers, national IDs, case or client references.
- Technical secrets: API keys, tokens, URLs with credentials.
- Quasi-identifiers: a rare job title plus a city plus a date can identify someone just as surely as a name.
- Your own confidential vocabulary: client names, project code names, unreleased products.
Manual redaction doesn't survive contact with reality
Find-and-replace works for one prompt. It fails at prompt fifty: people forget a phone number in a signature, paste a PDF with names in a footer, or reuse yesterday's text. Worse, manually restoring answers introduces errors in the other direction. Redaction has to be automatic, local, and reversible to be used every day.
How reversible redaction works
Detection runs on-device (deterministic rules for structured data like emails and IBANs, a local recognition model for names and organisations, plus your own dictionary). Each value becomes a numbered marker; the marker↔value vault stays encrypted on your machine. The AI answers using the markers — “For [PERSON_1], follow up at [EMAIL_1]…” — and the app swaps the real values back on screen. The values that were detected and neutralized do not leave your machine, and the pre-send review shows exactly what does (automatic detection has a measured recall — 97.4% on our test corpus — not 100%). The answer stays fully usable.
Verify what was sent — every message
Trust needs a receipt. Look for tooling that shows, per message, exactly what left your device, lets you correct a missed entity in one gesture, and can export an audit report (GDPR) or an EU AI Act transparency attestation. If you cannot audit the provider, audit what you send it.
The free way to start
Neutralyse runs this whole pipeline in your browser, with a fully local AI mode that is free and unlimited — nothing leaves the machine at all. Cloud models (Claude, GPT, Gemini, Mistral) are available behind the same redaction layer when you need more power.
Try it on a real example. Neutralyse redacts sensitive data on your device before it reaches ChatGPT, Claude or a fully local AI, then restores the answer on screen. Free locally, no credit card.
Open the protected chat →Last editorial review: September 1, 2026 — internal Neutralyse review (AIGENGO team), no external legal validation to date. This article is general information, not legal advice.