ON-DEVICE VS CLOUD

On-device redaction vs cloud redaction APIs

There is a structural oddity at the heart of cloud redaction: to have your sensitive data removed, you must first send your sensitive data somewhere. That may be an acceptable trade for your organisation, but it should be a decision, not an accident.

Side by side

The differences that matter.

Compared at the level of the category, not a specific vendor's current feature list.

DimensionCloud redaction APIDataAnonymiser
Where detection runsOn the vendor's servers, after your text is transmittedOn your own device
What the vendor receivesThe full raw text or document, including the identifiersNothing — no content is transmitted for detection
New processor relationshipYes — the redaction vendor becomes a processor of personal dataNo new processor for the content itself
Works offlineNoYes, once it is activated and set up
Cost modelUsually metered per document, per token, or per API callFlat subscription, no per-document metering
Breach surfaceVendor logs, request history, and stored copiesYour device only

The transmission is the risk

A cloud redaction service cannot remove an identifier it has not seen. That means every document you want de-identified must first travel, in full, to a third party — and once it has, you are relying on that vendor's retention policy, log hygiene, sub-processors, and breach record rather than on anything you control.

For a lot of workloads that is fine, and cloud redaction vendors run serious security programmes. But it means the redaction step itself is a data-sharing event, which is exactly what many teams adopt redaction to avoid.

What changes when detection is local

DataAnonymiser sets itself up on your machine after activation. Text, PDFs, office documents and images are handled inside the app, the placeholders are put in locally, and the mapping that lets you restore the original values afterwards stays on the device for the current session.

The practical consequence is that the redaction step stops being a transfer. There is no request body containing your document, no vendor-side log line, and nothing that can later be subpoenaed or breached from our side, because we never held it.

Metering versus flat cost

Cloud redaction is typically billed by volume — per API call, per document, or per thousand tokens. That creates a quiet incentive to redact less, and makes the cost of a large one-off cleanup hard to predict.

Local processing has no marginal cost per document. A folder scan across thousands of files costs the same as a single paste, which is what makes bulk work practical in the first place.

The honest trade-off: your hardware does the work

Working locally uses your own machine. A cloud API has effectively unlimited hardware behind it and can be faster on very large batches, and it needs no install and no per-device management.

DataAnonymiser is built for ordinary laptops and runs comfortably on one. But if your workload is a continuous high-throughput server pipeline rather than a person working with documents, a server-side tool is the better shape.

Questions

Common follow-ups.

Is on-device redaction less accurate than cloud redaction?

Not inherently — accuracy depends on how good the detection is, not on where it runs. What is true is that a laptop has less power behind it than a data centre. DataAnonymiser's detection is best-effort either way, and it produces a residual-risk report so a person can review the output before sharing it.

Does using a cloud redaction API count as a data transfer under GDPR?

Sending personal data to a third-party service is generally a disclosure to a processor, and if that service is outside your region it may also be a cross-border transfer. Local processing avoids creating that relationship for the content itself. This is general information, not legal advice — check your own obligations.

Can I use both?

Yes. Some teams redact on-device at the point a person handles a document, and keep a server-side tool for automated pipelines. The two address different points in the data flow.

Related

Other comparisons.

DESKTOP VS BROWSER-ONLY

Desktop app vs browser-extension-only redaction

Why the browser is the right place to catch a leak and the wrong place to do the redaction.

APP VS LIBRARY

A finished app vs a self-hosted redaction library

Open-source toolkits are free and flexible. This compares the total cost of owning one against a finished local app.

REDACTION VS SETTINGS

Redaction vs relying on the AI vendor's privacy settings

Opting out of training is a promise about what happens to your data after it lands. Redaction changes what lands.

DataAnonymiser is a best-effort redaction tool, not legal advice. It does not guarantee detection or removal of all personal data, nor compliance with GDPR, CCPA or any other law. Always validate outputs against your own obligations.