Local PII detection
Use a local detection model and deterministic rules to find sensitive values without sending the original content to a separate scanning service.
MASK_PERSONMASK_CONTACTMASK_SECRETMASK_ACCOUNTMASK_CUSTOMRemask detects and replaces personal or confidential data before it leaves your device—then sends the protected request to the AI provider you already use.
One privacy layer for the tools you already use
Keep existing AI workflows while applying one clear privacy policy across apps, providers, and API clients.
Use a local detection model and deterministic rules to find sensitive values without sending the original content to a separate scanning service.
MASK_PERSONMASK_CONTACTMASK_SECRETMASK_ACCOUNTMASK_CUSTOMChoose PII categories, add custom patterns, include system or history content, and pause protection only when you mean to.
Review protected fields, token use, latency, and recent activity in masked local logs.
Keep stable typed placeholders in the AI request and optionally restore protected values in supported responses.
Configure several AI providers and apply the same protection model instead of rebuilding privacy controls for each client.
Use a Remask API base URL, local proxy, or protected app launch. Your AI provider and client stay the same.
Remask applies your policy locally and swaps sensitive values for stable, typed placeholders.
Inspect masked request history and confirm exactly which protected content reached the AI service.
Protect code, desktop, browser, and server-side workflows with the connection method they already understand.
Change the base URL in an SDK, script, or internal service. Remask selects the configured provider and protects structured AI requests.
Launch an app with local HTTP/HTTPS or SOCKS5 proxy settings. Only configured target domains are inspected and masked.
Remask is explicit about which traffic it protects, what remains on your device, and what an AI provider still receives.
Original detected values are not sent to a separate cloud scanner during normal protected operation.
Requests must match a configured provider or protected target. Unmatched proxy traffic passes through unchanged.
Masked logs, retention, and cleanup are configurable. Raw or debug capture is explicit because it can contain sensitive content.
The proxy's local CA private key remains on the device. Managed provider credentials are kept locally and excluded from request logs.
Use the core gateway for free. Upgrade when your policies, models, or deployment scope need more control.
For personal AI workflows
For professional and internal use
Prices are in USD. Your AI provider usage and fees remain separate.
No. PII detection and masking run locally on your device during normal protected operation. The AI provider receives the rest of your prompt and typed placeholders, not the detected original values.
Remask works with API clients that can change their base URL and applications that support HTTP, HTTPS, or SOCKS5 proxy settings. Protected launch options cover common AI coding tools, browsers, terminals, and other installed apps.
No. Remask masks requests that match a configured provider or protected target. Unmatched proxy traffic is forwarded transparently without inspection or masking.
Typed placeholders preserve the role of a value—such as a person, email, account, or secret—so the model can usually reason about the structure without receiving the identity itself.
Yes. The free edition includes the core local protection workflow, built-in detection, both gateway modes, protected launch, masked logs, and one custom rule.
Release packages are provided for macOS and Windows. The download button checks your operating system and selects the matching asset from the latest GitHub release when available.
Download Remask and test your first masking policy locally.