How to Build a Zero-Knowledge AI Prompt Anonymizer in Pure JavaScript (Two-Way PII Masking)
Every day, developers, lawyers, and founders paste confidential source code, customer records, and internal business metrics directly into ChatGPT, Claude, and Gemini . When you paste raw client data like "Sarah Jenkins from TechNova GmbH paid $45,000" into public LLM chats, that private information is sent across the internet, logged into provider telemetry databases, and potentially used to…
Every day, developers, legal professionals, and business leaders type sensitive information such as personal data, customer records, and financial metrics directly into AI chat platforms like ChatGPT, Claude, and Gemini. When they input raw client data, that confidential information travels across the internet, gets logged in the provider's telemetry databases, and could potentially be used to train future AI models.
This guide explains how to create an entirely client-side, zero-knowledge AI prompt anonymizer using pure JavaScript. This tool replaces confidential names, email addresses, and financial figures with placeholder tokens, and includes a one-click two-way restoration engine that maps real names back into AI responses without sending any data to external servers.
First, it's important to understand why server-side redaction is not a secure solution. Many online PII (Personally Identifiable Information) scrubbers work by uploading your text prompt to their own cloud servers to run machine learning models. This approach creates a serious privacy risk: to protect your data from companies like OpenAI, you're actually sending your confidential text to an unknown third-party server. This opens up the possibility of data leaks or logging at every step of the process.
The zero-knowledge client-side approach, on the other hand, completely eliminates this risk. Here's how it works:
1. Tokenize: Replace sensitive entities with typed tokens, such as [PERSON_1], [COMPANY_1], or [CURRENCY_1].
2. Send the sanitized text to the AI platform (ChatGPT or Claude).
3. The AI understands the context perfectly and returns a response containing the tokens.
4. Paste the AI reply back into your local browser tool.
5. With a single click, the in-memory dictionary swaps the tokens back into their original names.
Some common sensitive data types and their replacement patterns include:
- Custom secret words: Replace with a custom token like [CUSTOM_1].
- Client names: Use bracket notation with a unique token, e.g., [PERSON_1].
- Company names: Tokenize with [COMPANY_1].
- Corporate suffixes: Tokenize using regular expressions.
- Email addresses: Match using RFC 5322 regex pattern and replace with [EMAIL_1].
- Phone numbers: Tokenize with [PHONE_1] using international phone pattern regex.
- Financial amounts: Tokenize with [CURRENCY_1] using currency symbol regex.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.