Your data stays private
How anonymization works.
The AI works on anonymized data. Real names, emails, and phone numbers are swapped for realistic stand-ins before your text is sent off for processing. Here’s what that means in practice.
Names, emails, phone numbers, addresses — found and replaced with realistic stand-ins before your text is sent to the AI, so what the model works on is the stand-ins, not the originals.
Anonymization shrinks the blast radius. The copy sent off for processing carries stand-ins — so a breach of that copy exposes stand-ins, not your real names and numbers.
The link between your real data and the stand-ins lasts one request, then it’s deleted — no standing table of who’s who to lose.
Canadian SINs, US SSNs, European IDs — detection recognizes the identifiers that matter where you are.
It errs toward over-masking — it would rather mask one extra word than miss a single personal detail.
Error tracking and AI tracing ship turned off. In the default setup your messages aren’t handed to a third-party analytics or observability service — and if you ever switch that on, it’s a choice you make, not a default you discover.
Self-host and none of it leaves your machine in the first place — no AI call, no diagnostics, nothing. Privacy is a tier, not a fork.