Early access for legal and regulated teams now open Request access →

Redact PII Before Sending Prompts to ChatGPT

Personal data appears in prompts in ways that are easy to overlook. A name in a document summary. A date of birth in a case note. An email address included as context. Each one is a data protection exposure waiting to happen.

Local scanning only No data egress Chrome extension Two-minute setup
Direct answer
How to automatically remove PII from ChatGPT prompts

Ventrin is a Chrome extension that scans and sanitises employee prompts locally in the browser before they are sent to ChatGPT, Claude, Gemini or Copilot. When sensitive content is detected, Ventrin warns the employee, rewrites the prompt automatically, or blocks the send — depending on your team's policy. Sensitive data never leaves the device unintentionally. Admins see every risk event in a central dashboard.

Where PII appears in AI prompts

Personal data does not always look like a privacy risk in the moment. An employee asking ChatGPT to rewrite an email naturally includes the recipient's name. A team member summarising a case note pastes in the client's date of birth. A manager asking for feedback on an HR situation mentions the employee by name.

Under UK GDPR and international data protection rules, processing personal data through a third-party AI service is a data sharing event. Without appropriate controls, that event is invisible, unlogged and potentially non-compliant.

Full names

Client names, employee names and third-party names used as context in prompts.

Email addresses

Contact details included when asking AI to draft or reply to correspondence.

Phone numbers

Contact information in notes, records or CRM data pasted directly into prompts.

Dates of birth

Age verification, medical context and identity details included in case or HR prompts.

Home addresses

Physical addresses in legal documents, HR records or client correspondence used as prompt context.

National identifiers

National Insurance numbers, passport references and similar identifiers in administrative prompts.

How Ventrin redacts PII before prompts are sent

Ventrin's on-device detection model identifies personal data in prompts before they leave the browser. It classifies each detected item by type — name, email, phone number, date of birth, address — and decides whether to remove it, generalise it or block the prompt entirely.

The rewritten prompt preserves the user's intent. "Summarise this note about Sarah Chen, DOB 14 March 1985" becomes "Summarise this note about a named individual." The task is still complete. The personal data is not sent.

All detection runs locally. The original text stays on the device.

Ventrin runs entirely on device. No prompt content is processed by Ventrin's servers. Detection happens locally in the browser before any prompt is sent.

Key Ventrin features for this use case

PII Detection

Recognises names, emails, phone numbers, dates of birth, addresses and national identifiers.

Local-First Sanitisation

No PII leaves the device for processing. Detection and rewriting happen in the browser extension.

Intent-Preserving Rewrite

Removes specific identifiers without changing what the prompt is trying to accomplish.

Browser-Based Scanning

Works across all browser-based AI tools. No proxy, no API gateway, no network configuration.

Admin Logs

Every PII detection event is recorded with risk type, action and timestamp — no raw PII stored.

Policy Settings by Team

Configure how PII is handled per team. Stricter blocking for HR and legal. Warnings for general teams.

PII redaction before and after

This example shows a case note prompt with seven types of personal data detected and removed before sending.

Prompt entered
Please summarise the following case note and suggest next steps.

Client: Sarah Chen, DOB 14/03/1985
Address: 47 Millbrook Lane, Bristol BS4 2QR
Phone: 07712 445 890
Email: s.chen@personalmail.co.uk
Ref: MATTER-2024-4471

Sarah attended on 14 January regarding an employment dispute with her previous employer, Dexford Solutions Ltd. She alleges constructive dismissal following a restructure in Q4 2023.
Ventrin scanning
Prompt sent
Please summarise the following case note and suggest next steps.

Client: [individual], [date of birth]
Address: [address]
Phone: [phone number]
Email: [email address]
Ref: [matter reference]

[Individual] attended on 14 January regarding an employment dispute with a previous employer, [employer name]. They allege constructive dismissal following a restructure in Q4 2023.
Detected and replaced
Name Sarah Chen [individual]
Date of Birth DOB 14/03/1985 [date of birth]
Address 47 Millbrook Lane, Bristol BS4 2QR [address]
Phone 07712 445 890 [phone number]
Email s.chen@personalmail.co.uk [email address]
Matter Ref MATTER-2024-4471 [matter reference]
Company Dexford Solutions Ltd [employer name]

Built for teams that cannot afford a data incident

Local-first detection

The scanning model runs in your browser, not on our servers. Sensitive content never leaves the device for analysis.

No data egress

Ventrin does not receive, store or process your team's prompt content. Only risk event metadata is logged.

Configurable policy controls

Warn, sanitise or block based on content type and team role. Full control over how the extension behaves.

Admin event logs

Every flagged event is recorded with risk type, action and timestamp. Provides the audit trail your compliance process needs.

Protect your team's AI use from the browser

Ventrin deploys as a Chrome extension. No proxy, no network change, no IT project. Most teams are protected on the same day.

Frequently asked questions

Let your team use AI without leaking sensitive data.

Join legal and professional teams already using Ventrin to protect their AI use. Browser-based, locally detected, fast to deploy.