Privacy Redactor

Use AI on everything.
Expose nothing.

Privacy Redactor detects names, IBANs, addresses, and other personal data, and replaces them with structured placeholders before anything leaves your Mac. Available for the browser and for your documents.

100% local detection No cloud, no telemetry 🇨🇭 Swiss-made

The real cost

Every document you paste into AI
gets processed on their servers.

The moment it's sent, it lives on infrastructure you don't control. Breaches happen. Legal discovery happens. Employees with access happen. Model training is just one risk buried in terms of service you scrolled past. Your client's name. Their IBAN. The contract you haven't signed yet.

1

Their servers, their rules

Their infrastructure. Their retention policies. Their staff with access. Their legal jurisdiction. A breach is one scenario — and not the only one.

2

Hidden metadata

A PDF carries author names, edit history, GPS coordinates, and deleted paragraphs. You paste more than you see.

3

No taking it back

A leaked client name isn't an "incident." It's a phone call you don't want to make.

Mac App

Document-level privacy.
On your Mac.

Import PDFs, Word files, and plain text. The on-device BERT model detects every entity, you review and adjust, then export a clean version. Built-in AI chat and an MCP server for Claude Desktop and other tools. Everything stays on your machine.

  • Multilingual document detection — BERT, fully on-device
  • Dossier management with consistent pseudonyms across files
  • MCP server for Claude Desktop, Cursor, and more
Privacy Redactor
📄 NDA_Acme_Corp.pdf 14 entities
📄 Employment_Contract.docx 23 entities
📄 Patient_Records_Q4.pdf 41 entities
📄 Board_Minutes_2025-12.md 9 entities
NDA_Acme_Corp.pdf

This Non-Disclosure Agreement is entered into between Sarah Miller ([email protected], +41 79 332 18 04) and Acme Corp AG, effective 14 March 2025. Both parties agree to keep all confidential information strictly protected and not to disclose it to any third party without prior written consent. Confidential information includes but is not limited to business plans, customer data, technical specifications, and financial details shared by Acme Corp AG. The obligation of confidentiality shall remain in force for a period of five years following termination of this agreement. Any breach by either Sarah Miller or Acme Corp AG shall be subject to civil liability under Swiss law. Disputes shall be resolved before the courts of Zürich, Switzerland.

Employment_Contract.docx

Thomas Weber, born 12.06.1988, residing at Bahnhofstrasse 42, 8001 Zürich, is hereby employed by Tech Innovations GmbH as Senior Software Engineer, commencing 1 April 2025. Annual gross salary is CHF 120,000, paid monthly to IBAN CH93 0076 2011 6238 5295 7. The probation period is three months. Overtime beyond 45 hours per week shall be compensated at a rate of 125%. Thomas Weber is entitled to 25 days of paid leave per calendar year. Either party may terminate this agreement with three months' written notice. All intellectual property created in the course of employment shall remain the exclusive property of Tech Innovations GmbH.

Patient_Records_Q4.pdf

Patient: Maria Sánchez, DOB 28.11.1993, AHV 756.1234.5678.97, insured under policy CSS-4821-09. Referring physician: Dr. James Chen, Clinique Rivoli, 75001 Paris. Initial consultation: 03.01.2025. Presenting complaint: recurring migraine episodes with photosensitivity. Prescribed: Sumatriptan 50mg as needed. Follow-up scheduled with Dr. Aiko Tanaka at Hôpital Cantonal de Genève on 17.02.2025. Patient contact: [email protected], +33 6 12 34 56 78. All records are classified and governed by cantonal data protection law.

Board_Minutes_2025-12.md

Meeting held on 18 December 2025 at the registered office of Nestlé SA, Avenue Nestlé 55, 1800 Vevey. Present: Jean-Marc Dubois (CEO), Aisha Patel (CFO), and Thomas Keller (General Counsel). Motion 1: approve transfer of EUR 2.4M to Deutsche Bank AG, IBAN DE89 3704 0044 0532 0130 00 — carried unanimously. Motion 2: renew service agreement with Acme Corp AG for fiscal year 2026 — carried. Minutes recorded by Thomas Keller and to be filed by 31 December 2025.

chatgpt.com
Send to Sarah Miller at Acme Corp. IBAN: CH93 0076 2011 6238

Safari Extension — free to start

Intercepts PII as you type into ChatGPT and Claude. Redaction happens in the browser, before the message is sent. Install and go — no configuration needed.

How it works

RedMatiq replaces sensitive values with structured placeholders. The AI gets identical context without the real data. When results come back, original terms are restored automatically.

📄
Your documents
Finder, Mail, any app
→ → →
drag in · paste
🔒
Privacy Redactor
detect · review · protect
→ → →
clean output
🤖
Any AI
ChatGPT, Claude

Pseudonymization, not deletion

RedMatiq doesn't black out text. It replaces sensitive values with structured placeholders like [PERSON_1] or [ORGANISATION_2]. This preserves document structure and meaning while removing identifying details.

The AI understands relationships and context because placeholders are consistent and structured. "Sarah Miller" becomes [PERSON_1] everywhere — in every file, every chat, every export.

Before
Please review the contract between Sarah Miller and Acme Corp. Her email is [email protected] and the IBAN is CH93 0076 2011 6238 5295 7.
What the AI sees
Please review the contract between [PERSON_1] and [ORG_1]. Her email is [EMAIL_1] and the IBAN is [IBAN_1].

What the detection actually catches

A multilingual BERT model, running entirely on your Mac. No API calls, no cloud inference, no data leaving your device.

23 entities in a two-page contract

Drop a document and the on-device model classifies every entity it finds: people, organizations, locations, emails, phone numbers, IBANs, dates, insurance IDs, and more. Each entity gets a type label and a confidence score.

The model handles mixed languages in the same paragraph. A German address next to a French name next to an English email. No pre-configuration needed.

Detection Results
23entities
Persons
5
Organizations
3
Locations
3
Emails
2
Phone
2
Dates
4
IDs / IBANs
4

Your level of control.

Some days you want speed. Other days you want to review every entity. Privacy Redactor adapts to you, not the other way around.

Quick Mode

Drop a document, get a clean file. Auto-detect everything, apply pseudonyms, export. One step from raw to safe.

1Drop document
2Auto-detect + pseudonymize
3Export clean file
🎯

Review Mode

Review every flagged entity in the Privacy Inspector. Toggle individuals on or off, add manual redactions, adjust types. Your judgment has the final word.

1Drop document
2Auto-detection flags entities
3Review in Privacy Inspector
4Toggle, adjust, add manual redactions
5Export when confident

Tune the confidence threshold

The AI model assigns a confidence score to every detection. Set the threshold lower to catch more edge cases. Set it higher for surgical precision. Adjust it per-dossier or per-workflow.

Detection Confidence72%
Catch more, review moreFewer flags, higher precision
23entities found
94%avg. confidence
2below threshold

Work your way

Drag, drop, copy, paste, export. In both directions. Mac-native.

both directions

Drag and drop

Drag files from Finder into Privacy Redactor. Drag clean files out into ChatGPT, email, or any app. The Mac way.

PDF · Markdown

Export clean files

Export sanitized PDFs or Markdown. Structurally new files. No hidden author names, no edit history, no GPS coordinates.

⌘C

Copy to clipboard

Copy pseudonymized text and paste it directly into any chat window, email, or editor. No intermediate file needed.

consistent across files

Dossier management

Group related documents. Pseudonyms stay consistent across an entire case, project, or client. "Sarah Chen" is always [PERSON_1] in every file.

MCP Server. Your documents in any AI.

Privacy Redactor runs a local MCP server. Claude Desktop, Cursor, and any MCP-compatible tool can access your documents as context. Always redacted. Always local.

Documents as AI context

Instead of copy-pasting text, your AI assistant reads your dossiers directly through the MCP protocol. The content is pseudonymized in real time. The AI gets full context. Your original data stays on your Mac.

Works with Claude Desktop, Cursor, Windsurf, and any tool that supports the Model Context Protocol. No plugins. No browser extensions. Just a local endpoint that speaks MCP.

  • Zero configuration: Toggle it on. Point your AI tool at the local endpoint.
  • Live sync: Change a redaction in Privacy Redactor, the AI sees the updated version immediately.
  • Multi-document: Expose entire dossiers as context. The AI can cross-reference between files.
Claude Desktop
Context Privacy Redactor · M&A Due Diligence
Compare the liability caps across the three acquisition agreements.
Across the three agreements in the dossier, the liability caps vary significantly. [ORG_1]'s share purchase agreement caps liability at CHF 2.5M (12 months). [ORG_2]'s asset transfer has an uncapped warranty period of 24 months. The [ORG_3] joint venture limits liability to the equity contribution amount.
All document content pseudonymized via MCP server. No real entity names transmitted.

Where redaction matters

From legal review to blind hiring, the workflow is the same. The data never travels.

AI analysis

Use Claude, ChatGPT, and other tools with confidential documents. Analyze contracts and reports without uploading client data.

Consulting

Share client documents with subcontractors and partners. Maintain NDA compliance without slowing down your workflow.

Legal

Redact contracts, briefs, and case files before sharing outside your practice. Hours of manual review become minutes.

HR & hiring

Create truly blind resumes. Names, addresses, and graduation years disappear. Reviewers evaluate candidates on skills alone.

Healthcare

De-identify patient records for research and consultations. Preserve clinical context while meeting data protection requirements.

Test data

Create realistic datasets without real personal data. Placeholders are consistent — [PERSON_1] stays [PERSON_1] across every file.

See detailed use cases

Runs where your data lives

Detection and redaction happen on your device. Nothing is uploaded. No exceptions.

No telemetry

We don't track what you do. No analytics, no usage logs, no content collection. Ever.

Verifiable privacy

Every AI interaction shows exactly what was sent. Privacy you can see, not just trust.

🇨🇭

Swiss-made

Built in Switzerland by Matiq GmbH. Data protection isn't a feature — it's the foundation.

Full AI power. Zero exposure.

Use AI exactly as you do today — except nothing sensitive ever reaches the cloud.