Text or a PDF travels over HTTPS to this application.
See exactly where your data goes.
Text and PDFs are processed as short-lived request data. You review the result before anything leaves your control.
Rules and local NER inspect the content. No external LLM receives it.
Select, deselect or add manual protection before export.
The anonymized output is returned to your browser.
No document store
Submitted text is not inserted into the application database or Redis. Review state is encrypted and short-lived.
No uploaded PDF retention
PDF bytes are opened from memory and are not written to disk, Redis, the database, session data or a server-side temporary file.
No external AI inspection
Detection runs inside the application using deterministic rules and locally installed language models.
Human review remains required
Automatic detection can miss context. The review tools let you add or remove protection manually.
Security boundaries
This service reduces accidental disclosure; it does not guarantee that every sensitive value will be found. Always review the result. HTTPS termination, secret management, Redis access controls, software updates and backups remain deployment responsibilities.
PDF uploads are parsed through an in-memory request stream under the configured request-size cap, rather than Werkzeug's default spooled temporary-file stream. The browser keeps the chosen PDF during review and reuses it automatically for export. Selected source text is permanently removed from the exported PDF and replaced with reversible placeholders.
The matching PDF restore map is built in the browser and contains the original values plus page positions. It intentionally contains no SHA-256 or source-file fingerprint. Protect that JSON like a secret.
Read the security notes or start with PDF anonymization.