ON-DEVICE VS CLOUD
On-device redaction vs cloud redaction APIs
There is a structural oddity at the heart of cloud redaction: to have your sensitive data removed, you must first send your sensitive data somewhere. That may be an acceptable trade for your organisation, but it should be a decision, not an accident.
Side by side
The differences that matter.
Compared at the level of the category, not a specific vendor's current feature list.
| Dimension | Cloud redaction API | DataAnonymiser |
|---|---|---|
| Where detection runs | On the vendor's servers, after your text is transmitted | On your own device |
| What the vendor receives | The full raw text or document, including the identifiers | Nothing — no content is transmitted for detection |
| New processor relationship | Yes — the redaction vendor becomes a processor of personal data | No new processor for the content itself |
| Works offline | No | Yes, once it is activated and set up |
| Cost model | Usually metered per document, per token, or per API call | Flat subscription, no per-document metering |
| Breach surface | Vendor logs, request history, and stored copies | Your device only |
The transmission is the risk
A cloud redaction service cannot remove an identifier it has not seen. That means every document you want de-identified must first travel, in full, to a third party — and once it has, you are relying on that vendor's retention policy, log hygiene, sub-processors, and breach record rather than on anything you control.
For a lot of workloads that is fine, and cloud redaction vendors run serious security programmes. But it means the redaction step itself is a data-sharing event, which is exactly what many teams adopt redaction to avoid.
What changes when detection is local
DataAnonymiser sets itself up on your machine after activation. Text, PDFs, office documents and images are handled inside the app, the placeholders are put in locally, and the mapping that lets you restore the original values afterwards stays on the device for the current session.
The practical consequence is that the redaction step stops being a transfer. There is no request body containing your document, no vendor-side log line, and nothing that can later be subpoenaed or breached from our side, because we never held it.
Metering versus flat cost
Cloud redaction is typically billed by volume — per API call, per document, or per thousand tokens. That creates a quiet incentive to redact less, and makes the cost of a large one-off cleanup hard to predict.
Local processing has no marginal cost per document. A folder scan across thousands of files costs the same as a single paste, which is what makes bulk work practical in the first place.
The honest trade-off: your hardware does the work
Working locally uses your own machine. A cloud API has effectively unlimited hardware behind it and can be faster on very large batches, and it needs no install and no per-device management.
DataAnonymiser is built for ordinary laptops and runs comfortably on one. But if your workload is a continuous high-throughput server pipeline rather than a person working with documents, a server-side tool is the better shape.
Questions
Common follow-ups.
Is on-device redaction less accurate than cloud redaction?
Not inherently — accuracy depends on how good the detection is, not on where it runs. What is true is that a laptop has less power behind it than a data centre. DataAnonymiser's detection is best-effort either way, and it produces a residual-risk report so a person can review the output before sharing it.
Does using a cloud redaction API count as a data transfer under GDPR?
Sending personal data to a third-party service is generally a disclosure to a processor, and if that service is outside your region it may also be a cross-border transfer. Local processing avoids creating that relationship for the content itself. This is general information, not legal advice — check your own obligations.
Can I use both?
Yes. Some teams redact on-device at the point a person handles a document, and keep a server-side tool for automated pipelines. The two address different points in the data flow.
Related
Other comparisons.
DESKTOP VS BROWSER-ONLY
Desktop app vs browser-extension-only redaction
Why the browser is the right place to catch a leak and the wrong place to do the redaction.
APP VS LIBRARY
A finished app vs a self-hosted redaction library
Open-source toolkits are free and flexible. This compares the total cost of owning one against a finished local app.
REDACTION VS SETTINGS
Redaction vs relying on the AI vendor's privacy settings
Opting out of training is a promise about what happens to your data after it lands. Redaction changes what lands.
DataAnonymiser is a best-effort redaction tool, not legal advice. It does not guarantee detection or removal of all personal data, nor compliance with GDPR, CCPA or any other law. Always validate outputs against your own obligations.