PiiBlocker Detection Settings: Categories Explained
Detection settings is the list of data categories PiiBlocker checks for: names, emails, phone numbers, addresses, card numbers, national IDs and so on. Each one can be switched off if it is causing more noise than protection for the way you work. Turning a category off means that type of data goes through unmasked, so make that decision deliberately and rarely. If names are giving you false alarms, try the Allowlist first. This guide covers the categories, when switching one off is reasonable, and what managed plans change. Short version: the Detection settings entry on our support page.
What the categories cover
PiiBlocker sorts what it detects into categories, and Detection settings lists them. They fall into two groups that the extension treats differently.
Critical data is masked automatically. Credit card numbers, Social Security and other national ID numbers, medical record numbers, bank account numbers, passwords, and API keys and secrets. These have fixed formats, detection is precise, and there is rarely a good reason to send one to a chatbot.
Personal details are shown to you for a decision. Person names, addresses, phone numbers, email addresses, dates of birth, ages, salary and income, medical conditions and employers. These depend on context. Your own employer in a cover letter is fine. A client's employer in a case summary may not be.
Each category has its own switch. With a category on, that type of data is detected and handled as above. With it off, PiiBlocker does not look for it at all, in any prompt, on any of the seven supported sites.
When switching a category off is reasonable
There are honest reasons to turn a category off. Most of them come down to one test: you never handle that type of data about other people, and the detector keeps firing on your own.
A developer who pastes code all day may find that age or date detection fires on version numbers and timestamps. A recruiter writing job adverts may not want salary figures flagged, because the figures are the point of the text. A writer working on fiction may find that every character name stops the prompt.
In each case the category produces noise and protects nothing, because there is no real person behind the match. Switching it off makes the remaining alerts more meaningful, and alerts that mean something get read.
The weaker reason is impatience. If a category fires correctly and often, that usually says something about what is being pasted. Switching it off hides the pattern and leaves the data flowing.
What you give up
Turning a category off means that type of data goes through unmasked. A category is either on or off, with nothing in between. And because a category that is off raises no alerts, it is easy to forget that it is off.
Two situations catch people out. The first is a change of work. A category that was safe to disable on a coding project is not safe three months later when the same person is drafting HR letters. The second is pasted content. You may never type a phone number yourself, but an email thread pasted for summarising can contain a dozen of them in signature blocks, and with phone detection off they all go through.
A sensible habit is to treat Detection settings like any other security setting. Change it for a reason you could explain to a colleague, note what you changed, and look at it again when your work changes. The critical categories deserve the most caution.
Try the Allowlist first
Most requests to turn off name detection are really about three or four specific words. A ward named after a person. A product that reads like a surname. The name of your own firm. Name detection is working as intended everywhere else. It is just wrong about those terms.
The Allowlist fixes that without giving anything up. It exempts only the terms you list and keeps name detection on for everyone else, so the next real client name is still caught. Entries match the whole term exactly, which keeps each exemption narrow. Our guide to the Allowlist covers what to add and what to leave off.
The opposite problem has its own fix too. If PiiBlocker misses a term, the answer is the Personal dictionary, not a settings change. Between the two lists, most tuning can be done one term at a time, with every category left on.
Managed plans and other approaches
On an organisation-managed plan, these settings are controlled by your administrator and shown as read-only. The reasoning is the same as for any managed security control. A policy that each person can switch off is a suggestion, and an organisation answering to a regulator needs to be able to say which categories were enforced. If a category is causing real friction, the route is to raise it with whoever manages the deployment, who can change the policy for everyone.
PiiBlocker is one way to control what reaches an AI service, and it is fair to name the others. Network DLP and secure web gateways enforce policy for every application by inspecting traffic at a proxy, at a much higher cost. Dictionary-only extensions skip categories entirely and mask only listed words. Our posts on DLP versus browser extensions and masking extensions compared go through the trade-offs.
Frequently asked questions
What happens when I turn a detection category off? Turning a category off means that type of data goes through unmasked. PiiBlocker stops looking for it until you switch the category back on.
Names keep causing false alarms. Should I turn name detection off? Try the Allowlist first. It exempts only the terms you list and keeps name detection on for everyone else.
Why are my Detection settings greyed out? On an organisation-managed plan, these settings are controlled by your administrator and shown as read-only. Ask your IT team if a category needs changing.
Which categories does PiiBlocker mask automatically? The critical ones: credit card numbers, Social Security and other national ID numbers, medical record numbers, bank account numbers, passwords, and API keys and secrets. Personal details such as names and addresses are shown to you for a decision first.