Privacy Shield

Anonymize your prompts before they reach ChatGPT, Claude or Gemini: detected names, emails, phone numbers, IBANs and IDs are swapped for placeholders, then your real data is restored in the answer you read. Opt-in, available on every plan, controlled from Settings. It reduces exposure — it does not guarantee anonymity.

Use Privacy Shield free

Anonymize your data before ChatGPT, Claude or Gemini

Provider privacy settings and contracts govern what happens after you submit a prompt. Privacy Shield adds a separate, earlier control: strip common identifiers out of the text before the request is sent to ChatGPT, Claude, Gemini or any other supported model.

When enabled, detected values are replaced with placeholders before provider inference. The mapping is kept on the client for supported flows so the displayed answer can be restored.

This reduces exposure; it does not guarantee anonymity. Context, attachments or undetected formats can still contain personal data.

Before and after: a redacted prompt

This is what a supported provider receives once Privacy Shield has replaced the identifiers it detected. You still see the original values in the answer.

You type

“Can my client Marie Dubois (marie.dubois@example.fr, +33 6 12 34 56 78) contest the invoice paid from IBAN FR76 3000 1007 9412 3456 7890 185?”

Model receives

“Can my client [NAME_1] ([EMAIL_1], [PHONE_1]) contest the invoice paid from [IBAN_1]?”

Detection is automated and language-dependent; unusual or contextual identifiers can be missed.

How your prompt is anonymized before AI

Your question

You choose when to enable Privacy Shield for a supported text flow.

Common identifiers replaced

Detected names, emails, account numbers and addresses are replaced with placeholders before model calls.

Models receive the minimized text

The selected providers receive the text after supported identifiers have been replaced.

Real data re-injected on your side

Satcove maps placeholders back to your real values in the verdict you read.

What personal data gets redacted

Full names

First names, last names, initials in formal contexts.

Email addresses

Personal and professional, including aliases.

Phone numbers

International formats, EU, US, mobile, landline.

Postal addresses

Street, city, postal code combinations.

Bank details

IBAN, BIC, card numbers, account numbers.

Government IDs

Social security, national ID, passport, tax IDs.

Medical identifiers

Patient IDs, lab reference numbers, dates of birth in clinical context.

Credentials

API keys, tokens, passwords that slip into a paste.

Detection coverage

Direct identifiers

The detector looks for common names, emails, phone numbers and postal addresses.

Financial and government identifiers

Pattern matching covers formats such as IBAN, payment cards, social security and reference numbers.

Medical context

The detector covers several patient and lab identifiers, but contextual health details may still identify someone.

Private AI for lawyers, doctors and accountants

Lawyers & in-house counsel

Reduce direct client identifiers before asking the panel about a contract clause, dispute, or regulatory question.

Doctors & nurses

Reduce direct identifiers before asking for informational context on a lab result or symptom set.

Accountants & advisors

Replace detected IBANs, tax IDs and account references before a supported tax or compliance request.

Anyone with a private question

Reduce unnecessary identifiers in personal questions before they are sent for inference.

Infrastructure

  • Managed hosting and database controls with access restricted to operational services.
  • Encrypted transport and managed encryption-at-rest controls.
  • Passwordless authentication. No password stored, none to leak.
  • Plan-based conversation retention and in-app history/account deletion controls.
  • Satcove does not train its own foundation model on your conversations; provider API terms still apply.

See /security for the full security posture and /gdpr for our GDPR commitments.

Frequently asked questions

Can I use ChatGPT privately for legal or medical questions?

You can reduce what you disclose. With Privacy Shield enabled on a supported text flow, detected names, contact details and reference numbers are replaced with placeholders before the prompt reaches ChatGPT, Claude or Gemini, and restored in the answer you read. It does not replace your organization's rules on what may be sent to a third-party processor, and it cannot remove context that identifies someone indirectly.

What does Privacy Shield actually do?

When enabled on a supported text flow, Privacy Shield attempts to replace common identifiers with neutral placeholders before model calls. The placeholders are restored locally where supported. Detection is automated and can miss unusual or contextual identifiers.

How is Privacy Shield different from ChatGPT's privacy mode?

Provider data controls govern how submitted content is retained or used. Privacy Shield adds data minimization before supported model calls, reducing the direct identifiers submitted rather than replacing provider privacy terms.

Is Privacy Shield available on the free plan?

Yes. Privacy Shield is available at no extra cost on all plans, including Free. It is an opt-in setting so you can decide when placeholder-based anonymization is appropriate.

What types of personal data are detected?

The detector covers many names, email addresses, phone numbers, postal addresses, payment and government identifier formats, credentials and medical reference formats. Coverage varies by language and context.

Does Privacy Shield make a request GDPR compliant?

No single product control makes a use case compliant. Privacy Shield supports data minimization, while the lawful basis, notices, access controls, retention and processor terms still depend on the organization and use case.

Does Privacy Shield cover images and every Satcove tool?

No. The current control is designed for supported text flows. Images, attachments and some tools may require separate processing; remove sensitive details that are not needed for the request.

Remove unnecessary details, enable Privacy Shield, then ask the question you need answered.

Available on every plan, including Free.

Satcove — A product by Abyssal Group