PrivaPrompt
Security & Privacy

How PrivaPrompt protects sensitive details.

PrivaPrompt is local-first. It detects sensitive data on your machine, replaces it with placeholders before any prompt is sent to the AI provider, receives a response that still contains those placeholders, and then restores the original values locally so the user sees a seamless, readable answer.

This page explains the public security model. It does not expose private source code or detection-rule internals.
Provider-bound prompt preview
Original prompt — local only

Draft a reminder for Sarah Johnson. Her email is sarah.johnson@email.com and phone is 555-291-8847.

Sanitized prompt — sent to provider

Draft a reminder for [NAME_1]. Her email is [EMAIL_1] and phone is [PHONE_1].

AI receives placeholders instead of raw private values.
How the privacy engine works

Six protection steps before AI sees the prompt.

The live security page explains this as a layered local process: original prompts stay local, detection runs on the user’s machine, values become placeholders, and restoration happens locally during the session.

1. Original prompt stays local

You type naturally. Raw input is processed locally before any provider call.

2. BERT NER detection

Local named-entity recognition helps identify people, organizations, locations, and context-based values.

3. Structured pattern filters

Pattern checks catch emails, phones, account IDs, SSNs, routing numbers, cards, and similar values.

4. Custom privacy rules

Additional local rules help catch business-specific or high-risk sensitive patterns.

5. Placeholder sanitization

Matched values are replaced before anything is sent to the AI provider.

6. Local restoration

The response returns with placeholders, then PrivaPrompt restores original values locally.

Session-only memory in RAM: active placeholder mappings are kept only during the open session so responses can be restored. When the app closes, the session is discarded and the next launch starts fresh.
What filters are applied

Multiple local protection layers.

PrivaPrompt combines local protection layers before sending a sanitized prompt to the AI provider. Detection is continuously improved, and exact detection rules may evolve to reduce missed data and false positives.

NamesEmailsPhone numbersAccount IDsAddressesCredit cardsRouting numbersMedical IDsPasswordsMore
BERT NER context detection

Helps catch likely sensitive entities based on language context.

Structured pattern detection

Looks for precise formats like emails, phones, SSNs, cards, and account-like values.

Custom privacy rules

Adds extra local checks for product-specific and business-specific sensitive patterns.

Placeholder mapping + local restoration

Replaces sensitive values with placeholders, then restores original values locally after the placeholder-based response returns.

What the AI provider sees

Sanitized prompt, not the original values.

The provider receives the sanitized version with placeholders, not the original private values. The AI response returns with placeholders and PrivaPrompt restores values locally.

Original prompt — stays local
Draft a follow-up appointment reminder email for my patient Sarah Johnson (MRN 8847291). Her email is sarah.johnson@email.com and phone is 555-291-8847. Her SSN on file is 523-88-4401.
Sanitized prompt — sent to provider
Draft a follow-up appointment reminder email for my patient [NAME_1] (MRN [ACCOUNT_ID_1]). Her email is [EMAIL_1] and phone is [PHONE_1]. Her SSN on file is [SSN_1].
What stays local

Private values stay on the user’s machine.

Sensitive values are detected locally

Detection happens on the user’s machine before the prompt is sent.

Placeholder map stays local during the active session

Mappings are used to restore the response while the session is open.

Original values are restored locally

The user sees a readable answer after the AI response returns.

PrivaPrompt starts fresh by default

By default, the app starts fresh when it reopens.

User API keys are entered inside PrivaPrompt

Provider API keys are not stored on PrivaPrompt cloud servers.

What PrivaPrompt does not intentionally store

No intentional cloud storage of raw sensitive content.

×
Raw prompts on cloud servers

PrivaPrompt is designed to avoid storing raw customer prompts on its cloud servers.

×
Uploaded file contents on cloud servers

Uploaded file contents are not intentionally stored on PrivaPrompt cloud servers.

×
AI chat transcripts containing raw sensitive data

Raw sensitive prompt transcripts are not intentionally stored on PrivaPrompt cloud servers.

×
Provider API keys on cloud servers

Provider keys are entered inside PrivaPrompt and not stored on PrivaPrompt cloud servers.

×
Permanent session history by default

Active session mappings are discarded when the app closes by default.

Important boundaries

Clear limits build trust.

PrivaPrompt is designed to reduce exposure risk before prompts reach the AI provider. It should be explained clearly and honestly.

Reduces exposure risk

PrivaPrompt is built to minimize what leaves the user’s device.

Not a perfect guarantee

No privacy tool should be presented as detecting every possible sensitive detail in every prompt or document.

Not every DLP control

PrivaPrompt is not a replacement for every enterprise DLP, legal, or compliance process.

Policies still matter

Organizations should still follow their own legal, security, and compliance policies.

Privacy you can trust. Answers you can rely on.

Questions about security, rollout, or trials? Email sales@privaprompt.com.

Start free