Privacy filter

How meinGPT replaces personal data with placeholders before every request to an AI model and puts it back in the answer

The privacy filter replaces personal data with placeholders before a request reaches an AI model, and puts the real values back in the answer. The AI model sees, for example, [PERSON_W_1] instead of a name; you read the name again in the answer.

Note

meinGPT enables the privacy filter per workspace; in the settings it is called PII filter. If it is not active in your workspace, requests go to the AI model unchanged. The earlier browser filter with its levels for models outside the EU is gone. How to request it is described below.

What the filter does

Detect

Before every request to a language model, meinGPT checks the text for personal data. Detection runs on meinGPT's servers: fixed rules for formats such as IBAN, email address or phone number, keywords such as "Vertragsnummer" (contract number), and a detection model for names and addresses. Your text is not sent to any additional provider for this.

Replace

Detected details are replaced with placeholders such as [PERSON_W_1], [EMAIL_1] or [IBAN_1]. The same value gets the same placeholder throughout the conversation, so the model keeps the context. Salutations such as "Ms" or "Mr" stay in place.

Put back

When the model writes a placeholder in its answer, meinGPT puts the real value back while the answer is still appearing.

The link between placeholder and real value is not stored; it is rebuilt for every request. Your chat history stays stored in meinGPT as usual, with the real values, just as you see them.

Where the filter applies

The filter sits at the point through which meinGPT calls language models. It therefore applies to every language model, inside or outside the EU, and to every way of reaching one: chat, assistants, projects, workflows, the API, regenerate and edit, switching models mid-chat, and every intermediate step in which an assistant uses tools. It checks your messages, the chat history so far, files that enter the request as text, and the results of tools, such as passages from data pools.

Tools such as Microsoft 365, Google Workspace, databases or the code sandbox receive the real values so they keep working. Tools that send data to public services on the internet, such as web search, maps or image generation in chat, only receive the placeholders.

Knowledge base: search queries against your data pools also reach the service that turns them into vectors for meaning-based search in protected form; keyword search still uses your text, so names and numbers are found. The documents themselves are indexed unfiltered, through our provider in the EU.

What admins configure

As a workspace admin, you find the settings under Settings → PII filter. You confirm every change in the Apply for all members? dialog, and it applies immediately to every request in the workspace.

Who is protected

Without a choice of your own, the filter is Always on for everyone. Under Who is protected you set what applies to Everyone else (Always on or Optional) and give individual teams their own setting: Always on, Optional or Off. Off sends that team's requests unfiltered and needs an explicit confirmation. Members of several teams get the stricter setting. Requests through the API and automations always count as Always on.

With Optional, members can switch the filter off per chat. Each switch-off is recorded once per chat in the audit log, and Where it gets in the way shows in how many chats it happened. Unfiltered requests carry no filter surcharge.

Protection level

LevelWhat happens
OffRequests reach the AI model unchecked. The page warns you before saving, and the change is logged.
RecommendedReplaces names, contact details, bank details and identifiers. Companies and places stay readable. Credentials are never sent.
StrictAlso replaces health information, companies and places, and never sends bank details.

Without a choice of your own, Recommended applies. Under Recommended, some placeholders carry a hint that does not reveal the value, such as the age instead of the date of birth, or the country and validity of an IBAN instead of its digits. This lets the model keep calculating and checking. Under Strict there are no such hints.

Under Recommended, the name of a public official also stays readable when it directly follows their title, such as “Richterin am Amtsgericht Weber”, “Notar Dr. Kühn” or “Bürgermeisterin Albers”; a case handler only when an authority is named in the same sentence. Parties, witnesses, applicants, patients and insured persons in the same document are still replaced. Under Strict, officials are replaced too.

Invoice, order, job, delivery-note, ticket, article and part numbers are not personal data and stay readable under both levels. Customer, contract, policy, insured-person, personnel and claim numbers and file numbers are replaced. To protect such a business number anyway, add it under Always protect or create a custom category.

Categories

Under Categories you decide what happens for five groups: People, Contact details, Bank details, Identifiers and Health. Credentials such as passwords and API keys are always blocked; that row is locked. If you deviate from the protection level, the page shows Customized.

  • Replace: the model sees a placeholder; the answer contains the real value again.
  • Block: the model sees a placeholder; the real value is not put back in the answer either.
  • Allow: the value reaches the model unchanged.

If you set People, Contact details or Bank details to Allow, you must explicitly confirm in the dialog that these details reach the model unprotected. The sentence at the top of the page then says so permanently, for example “Names are not protected.”

The same list holds Release requests: with With confirmation (the default) the AI model may ask for single protected details when a task needs them, for example to search the web for a person. Members decide per message. With Off the model does not ask and briefly says what it cannot do without the real value instead. Credentials are never released.

It also holds Images: the filter cannot check what an image shows. With Block (the default) no images reach the AI model. With Send unchecked images go to the model as they are, in chat and as reference images in image generation. Personal data in them is then not protected; you have to confirm this explicitly in the dialog, and the sentence at the top of the page says "Images are sent unchecked." The statistics count how many images were sent this way. The setting does not affect PDFs and Office files: they are always checked through their text.

Always keep readable

Terms in this list are never replaced, such as your company or product name. This helps when the model needs a name that the filter would otherwise take for a person.

Always protect

Terms in this list are always replaced or blocked, such as internal project or client names that no detection model would recognize as personal. Case does not matter, and only whole words count. New terms are replaced; you can switch each term to Block. In the chat they are called Protected term.

Custom categories

For information only your company has, such as broker or client numbers, you create custom categories: a Name, keywords the value usually follows (Usually follows), and up to three Examples. meinGPT derives one pattern that covers all of them, so you don't write a rule. As the Action you choose Replace or Block.

Without a keyword, the pattern applies anywhere in the text. If it would also match ordinary numbers such as years or amounts, for example with the example “2024”, meinGPT rejects the category. Then add a keyword the number follows.

What takes precedence

Where rules overlap, this order applies: credentials, Always protect, custom categories, fixed formats such as IBAN, email address, phone number and card number, Always keep readable, and last the automatic detection. So protecting always wins over allowing: a term in both lists is protected, and an email address stays replaced even if it is listed under Always keep readable.

Try it and overview

In the Try it field you see, for a test text, what the AI model would receive and why each detail was detected. With a test text in place, the confirmation dialog of a change shows what would change in that text, for example With your change: 2 places differ; the affected places are outlined. The test text is not stored.

Under Last 30 days you see how many requests the filter protected, how many details it replaced, split by kind, and how many requests it refused instead of sending them unchecked. Where it gets in the way names what stands out, such as names that are often released or a number format reported as missed, and takes you straight to the matching setting. It shows only numbers, categories and formats such as AA-0000, never content, names or chats.

What users see

There is no pop-up before sending anymore. Instead:

  • Below a sent message there is, for example, 3 details protected. A click opens the list of Protected details with category, value and action (Replaced or Never sent). Credentials that are never sent appear there only as ••••. If the filter missed something, report it there with Report missed data: only the kind of data and the filter version are stored, never your text.
  • Protected values are marked in your own message. Hovering over one explains that the AI model never saw the value.
  • In the answer, values that were put back are subtly underlined: Put back by the privacy filter – the AI model only saw a placeholder.
  • If a task needs the real value, the AI model asks in the chat: a card shows the detail and the model's reason. Release for this message lets the model see the value for this answer only; Continue without keeps it protected. Afterwards a line such as “Person “Erika Mustermann” released for this answer” remains. Released values are underlined with a solid line in the answer: Released for this answer – the AI model saw this value. Every decision is recorded in the audit log, without the value.

If your filter is Optional, the chat's + menu has a Privacy filter switch. It is on in every new chat; switch it off and that chat's messages reach the AI model unfiltered, with Filter off shown next to the input. If your admin requires the filter, the menu says Set by your admin.

If the filter cannot fully check a message, the message is not sent and an error appears in the chat. Details are under Privacy filter could not check your message.

Limits

Attention

The privacy filter pseudonymizes; it does not anonymize. Plan it into a data protection impact assessment as an additional safeguard, not as proof that no personal data reaches the model.

  • Detection is not complete. Rules and the detection model find most details, but not all, especially unusual spellings or number formats that only your company uses. Custom categories are meant for such numbers.
  • Some things remain recognizable from context. Under Recommended, companies and places stay readable, and the filter does not replace a description such as "our managing director".
  • Instructions are checked too. An assistant's instructions, your personal instructions and the workspace context go through the filter like your messages. Only meinGPT's own fixed instructions stay unchanged.
  • Images are not sent to the model unless your admin chose Send unchecked under Images. The filter cannot check what an image shows. If you attach an image, the message is not sent; remove the image or describe its content in words. PDFs reach the model as extracted text, not as a file, and are checked on the way.
  • Images are only generated without personal data. A placeholder in an image cannot be turned back into the real value. If an image generation prompt contains personal data, no image is generated, and the message names the kind of data that was found.
  • Features that don't run through language models are not covered, such as the transcription of recordings.
  • Very long texts. A single message you write is checked up to about 30,000 characters. If it is longer, such as a whole pasted contract, it is not sent. Split the text in that case. Attached documents, tool results and instructions are checked up to about 120,000 characters of new text per request; anything already checked does not count again.
  • Tasks that need the real value, such as a web search for a person who was replaced, work only if you release the detail for that answer. Without a chat, for example through the API or in automations, the model cannot ask.

Requesting the filter

Write to enterprise@meingpt.com or use the Get in touch button on the PII filter page. On request, meinGPT first runs the filter in measuring mode: it checks along but changes no request. Once the filter is active, the PII filter page shows its settings. You keep deciding which models your workspace may use through model enablement.

Was this page helpful?