Skip to content
Back to blog

How to Mask Personal Data Before Pasting into ChatGPT

PiiBlocker Team

chatgptprivacyhow-topii masking

To mask personal data before pasting into ChatGPT, replace every identifying value (names, emails, phone numbers, account and ID numbers) with a placeholder such as [PERSON_A], send the masked text, then swap the real values back into the reply. You can do this by hand in a text editor, or let a Chrome extension do it at the moment you paste. PiiBlocker does it for free on ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek and Kimi, with all detection running in your browser. This guide covers both methods step by step, and where each one falls short.

Disclosure: PiiBlocker is our product. The manual method below needs no tools at all.

What to mask

Anything that identifies a person, or that someone could misuse if it leaked:

  • Names of people and organisations
  • Email addresses, phone numbers and postal addresses
  • Card numbers, bank account numbers and IBANs
  • Social Security, National Insurance, passport and other ID numbers
  • Dates of birth
  • API keys, passwords and access tokens
  • Medical details, salaries and anything else tied to a named person

The test is simple: could someone reading the prompt work out who it is about?

Pasted text is a bigger risk than typed text. An email thread, a spreadsheet row or a log file carries details you did not put there on purpose, such as a phone number in a signature or a key in a config line. You check what you type. You rarely check what you paste.

Method 1: Mask it by hand

This works anywhere and needs nothing installed.

  1. Paste into a plain text editor first, not into ChatGPT.
  2. Find each identifying value and replace it with a placeholder. Use find and replace so every occurrence changes, not only the first.
  3. Use one placeholder per real value and keep it consistent. [PERSON_A] for the first person, [PERSON_B] for the second. ChatGPT needs to tell them apart to give a useful answer.
  4. Keep a note of which placeholder stands for what. Keep it out of the chat.
  5. Read the masked text top to bottom once more, then paste it into ChatGPT.
  6. Copy the reply back into your editor and reverse the replacements.

The manual method costs nothing and fails in a predictable way. You mask the names you were thinking about and miss the ones you were not, like a reference number in a subject line. It suits a one-off. It does not hold up as a daily habit.

Method 2: Mask it automatically with PiiBlocker

PiiBlocker is a free Chrome extension that does the same job at the point of sending.

  1. Install it from the Chrome Web Store. There is no account to create.
  2. Open chatgpt.com and paste or type as you normally would. PiiBlocker highlights the personal data it finds in the message box.
  3. Press send. Before the message goes, a dialog shows what was found. Card numbers, Social Security numbers and API keys are masked automatically. Names, addresses and emails wait for one click from you.
  4. Fix anything it missed. Select the text, right-click and mask it. Names and terms specific to you can go in a personal dictionary so they are caught next time.
  5. Read the reply as normal. ChatGPT receives placeholders, and PiiBlocker swaps the real values back in on your screen.

It detects 15 or more types of personal data. Detection runs locally and the free version makes no network calls. If PiiBlocker cannot check a message, it blocks the send instead of letting unchecked text through.

What ChatGPT sees

Here is a prompt as you would write it:

Write a polite reply to Sarah Johnson ([email protected],
020 7946 0958) telling her the refund has been approved.

And here is what is sent after masking:

Write a polite reply to [PERSON_A] ([EMAIL_A], [PHONE_A]) telling
her the refund has been approved.

ChatGPT writes a reply addressed to [PERSON_A]. With the manual method you swap the name back yourself. With PiiBlocker the reply reads "Sarah Johnson" on your screen, while OpenAI's servers only ever held the placeholder.

The answer is as good as it would have been with the real details. For drafting, rewriting, summarising and analysis, the model needs the shape of the request, not the identity of the person in it.

Which method to use

By hand PiiBlocker
Cost Free Free
Setup None One install, no account
Effort per prompt Find, replace and reverse each value One click to confirm
Catches values you forgot No Yes, for the 15 or more types it detects
Real values back in the reply You reverse them yourself Automatic
Works in Any app or browser Chrome, on the seven supported sites

Mask by hand for an occasional prompt, or when you are in an app an extension cannot reach. Use an extension if you paste real-world text into ChatGPT most days.

Other tools that do this

PiiBlocker is not the only extension that masks data before it is sent. Caviard, ChatWall, PrivacyScrubber and PasteSecure all run locally too, and they differ mainly in what the free tier covers. Caviard's free plan stops at 10 protected values per document, and ChatWall's free tier leaves out card numbers, ID numbers and API keys. PrivacyScrubber also has a web version for documents, which is useful if your data is in a file and not a prompt.

We compare six of them side by side in Best Chrome Extensions to Hide Personal Data from ChatGPT (2026).

What masking does not cover

  • Apps and uploads. A Chrome extension protects what you type or paste into a supported chat in Chrome. It does not cover the ChatGPT desktop or mobile apps, other browsers, or files you upload. Mask those by hand.
  • Context. Masking removes identifiers, not clues. A prompt about "the only cardiologist in" a named small town still points at one person with the name masked. Read the prompt for details that survive masking.
  • Privacy settings. Turning off "Improve the model for everyone" stops your chats being used for training. Temporary Chat keeps them out of your history. In both cases the text is still sent to OpenAI, and Temporary Chats are kept for up to 30 days. Masking is the only one of the three where the real data never arrives. For more on what is kept, see what ChatGPT remembers about you, and how to check.

Frequently asked questions

Does ChatGPT still give a good answer when the data is masked? Yes, for drafting, rewriting, summarising and analysis. It cannot do tasks that need the real value, such as looking up a named company.

Is masking the same as anonymising? Not quite. Masking swaps identifiers for placeholders and keeps a way to swap them back. Anonymising removes that link for good. With masking, the link stays on your device and ChatGPT never receives it.

Can I mask personal data in a file I upload to ChatGPT? Not with PiiBlocker. Mask the file before you upload it, or paste the text into the chat so the extension can check it.

Does Temporary Chat mask my personal data? No. A Temporary Chat is not saved to your history or used for training, but the text is still sent to OpenAI and kept for up to 30 days.

Does this work for Claude and Gemini too? Yes. The manual method works in any chatbot. PiiBlocker works on ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek and Kimi.

Is PiiBlocker free? Yes. Core detection and masking is free with no account and no usage limits.

Sources


Install PiiBlocker free from the Chrome Web Store, or see every supported site and detected data type at piiblock.com.