Free tool

Anonymize ChatGPT prompts before you hit send

Paste the prompt below. Every name, email address, phone number, card number and ID is swapped for a consistent placeholder, so the question still makes sense and the people in it stay private. The replacement happens in this browser tab, not on a server.

Try it on your own prompt

Runs in this tab. Nothing you type is uploaded or stored.

404 characters
Safe to send5 values replaced
Draft a firm but polite follow-up email. Context: our client A__________ at B_____________ has not paid invoice INV-2083 for $48,900, now 21 days overdue. She confirmed on the phone that the transfer was approved. Her email is user101@example.com and her direct line is +1 581 470 3692. Copy our CFO C_________ so he has a record. Keep it under 150 words and offer to resend the receipt.

Your key, kept on this device

Paste the placeholders into ChatGPT, then swap the real values back into its answer. The extension does this step for you with Alt + R.

TypeFound in your promptSent to ChatGPT instead
NameOlivia GrantA__________
NameHorizon FreightB_____________
Emailolivia.grant@horizonfreight.comuser101@example.com
Phone+1 415 555 0132+1 581 470 3692
NameMarc KellerC_________

This preview uses the same categories and placeholder style as the extension, in a single pass over the text. Inside ChatGPT the extension also watches what you paste, lets you mark extra values by hand, and restores the originals in the reply. Always read the result before you send: automated detection is a safety net, not a guarantee.

Placeholders, not deletions

The instinct is to delete the sensitive parts. That is what breaks the prompt.

Take the example above. Strip the two names out and the request collapses: ChatGPT no longer knows who owes the money, who is being copied, or which of them should be addressed in the draft. Replace them with A__________ and C_________ instead and every relationship in the text survives. The model writes the email, and you put the real names back before you send it.

Two details make this work. The same value always becomes the same placeholder, so a person mentioned four times is recognisably one person. And the placeholder keeps the rough shape of what it replaced, so a phone number still looks like a phone number rather than a hole in the sentence.

What gets picked up

  • Names

    People and companies, including names written with an honorific. Each one keeps its own placeholder.

  • Email addresses

    Replaced with a working-looking address so the model still treats it as an email.

  • Phone numbers

    North American and international grouping. The country code and spacing survive, the digits do not.

  • Payment card numbers

    Sixteen-digit numbers in any of the usual spacings.

  • National ID numbers

    Social security style identifiers, with the invalid ranges excluded so real text is not over-matched.

  • Anything you add yourself

    In the extension you can mark a project codename, a salary or an address so it is masked from then on.

Three ways to do this

The tool on this page is the middle option. It is the right one for an occasional prompt, and the wrong one for the fortieth prompt of the week.

ApproachEffortWhat goes wrongContext for the model
Find and replace by handTwo to three minutes per promptYou miss the second mention, or the one inside a pasted email threadOften lost, because people delete the detail instead of replacing it
Paste into an online anonymizerA copy, a paste, and a second tabYour text has now been sent to one more company, unless the tool is client-sideKept, but you have to map the values back yourself
A browser extension that sits in ChatGPTNone after the installAutomated detection can still miss an unusual formatKept, and the original values come back in the reply

Every prompt, not just this one

Put the same check inside ChatGPT

Copying text into a tool works until you are in a hurry, which is exactly when the customer list gets pasted. The Caviard extension runs this detection as you type in ChatGPT and DeepSeek, masks what it finds before the prompt is submitted, and puts your real values back into the reply with one shortcut. Everything stays on your machine.

  • Detection runs on the device. No prompt is sent to Caviard.
  • Alt + R toggles the whole conversation between masked and real values.
  • Free for 10 values per document. Unlimited for $9 once per device, with no subscription.

Is anonymizing enough?

It removes the part that matters most, which is the link between the text and a real person. It does not change what OpenAI stores, how long it keeps it, or whether your conversations train future models. Those are account settings, and they are worth ten minutes of your time.

The companion guide, Is ChatGPT safe? What happens to your data, covers what is stored, who can read it, and the seven settings that change it. For the team version of this problem, read redacting personal data in ChatGPT for enterprises, and for the technique itself, anonymizing AI prompts without losing context.

Frequently asked questions

How do I anonymize a prompt before sending it to ChatGPT?
Replace every identifying detail with a consistent placeholder rather than deleting it, so the model still understands the relationships in your text. You can do it by hand, paste the text into the tool on this page, or install a browser extension that does it automatically each time you type in ChatGPT.
Is this prompt anonymizer free?
Yes. The tool on this page is free and unlimited, and it runs entirely in your browser. The Caviard extension is free for up to 10 protected values per document; removing that limit is a one-time $9 licence per device, not a subscription.
Does my text get uploaded when I use this page?
No. The detection and replacement run as JavaScript in the tab you have open. Your text is never sent to caviard.ai or to any other server, which you can confirm in your browser network tab.
Why replace personal data with placeholders instead of deleting it?
Deleting the details breaks the prompt. If you remove two names, ChatGPT can no longer tell who owes what to whom. A consistent placeholder keeps the structure: the same person is the same token every time they appear, so the answer stays correct and you swap the real values back afterwards.
Does anonymizing a prompt make ChatGPT GDPR compliant?
It helps significantly, because data that cannot be linked back to a person is no longer personal data in the sense the GDPR means. It is not a complete answer on its own. If you process personal data at work you still need a lawful basis and, for real identifiable data, a processor agreement with OpenAI through a business plan.
Will ChatGPT still give a useful answer with placeholders in the prompt?
In practice yes. Models handle consistent tokens well, and the surrounding context tells them what each one is. Ask for the reply in the same placeholder form, then substitute the real values back in. The extension does that last step automatically with Alt+R.
Does this work for Claude, Gemini or DeepSeek?
The tool on this page works on any text you paste, whatever you plan to send it to. The Caviard extension currently runs inside ChatGPT and DeepSeek; support for more assistants is in progress.