REDACTION VS SETTINGS
Redaction vs relying on the AI vendor's privacy settings
Most AI tools now offer a switch that stops your conversations being used for training, and enterprise plans usually promise more. Those controls are worth using. They also do not change the fact that the data arrived.
Side by side
The differences that matter.
Compared at the level of the category, not a specific vendor's current feature list.
| Dimension | Vendor privacy settings | DataAnonymiser |
|---|---|---|
| Data reaches the vendor | Yes — the setting governs later use | Only the redacted version does |
| Protection type | Contractual and policy | Technical, before transmission |
| Retention windows | Vendor-defined; often kept for abuse review | Not applicable to values that were never sent |
| Breach exposure | Your raw text is in scope | Only placeholders are in scope |
| Applies across tools | Per vendor, per account, per setting | Once, before you paste anywhere |
| Effort | One-time toggle | A redaction step in your workflow |
A setting is a promise, not a boundary
Opting out of training is a commitment about how a vendor will use data they already hold. It does not stop transmission, it does not always stop retention — many providers keep conversations for a period for abuse monitoring regardless — and it does not survive a breach, a subpoena, or a mistaken account configuration.
None of that makes the setting useless. It makes it a different kind of control from removing the identifier before you press send.
Filtering out is not the same as never sending
Several providers offer their own PII filtering. It runs after your data has left your network, which means the filter is a service you are trusting with the raw material, not a boundary you enforced.
Redacting locally inverts that: the identifying values never form part of the request in the first place, so there is nothing for a downstream filter, log, or retention policy to handle.
One step, every tool
Vendor settings have to be found, enabled and re-checked per product, per account, and again whenever someone signs up for something new. A local redaction step happens once, on your side, and the resulting text is safe to paste into whichever tool you choose.
Questions
Common follow-ups.
If I turn off training, is my data safe in ChatGPT?
It is better protected, but it has still been transmitted and may still be retained for a period under the provider's own policies. Turning off training limits one downstream use; it does not undo the transfer.
Should I do both?
Yes. Use the vendor's privacy controls and remove the identifiers before you send. They protect against different failure modes.
Does redaction make the AI's answer worse?
Usually not, because consistent labelled placeholders preserve the structure of the task — the AI can still tell that the same person appears in three places. It does prevent tasks that genuinely need the real values, such as looking up a specific customer.
Related
Other comparisons.
ON-DEVICE VS CLOUD
On-device redaction vs cloud redaction APIs
Why sending data to a cloud service to have it de-identified creates the exposure you were trying to avoid.
DESKTOP VS BROWSER-ONLY
Desktop app vs browser-extension-only redaction
Why the browser is the right place to catch a leak and the wrong place to do the redaction.
APP VS LIBRARY
A finished app vs a self-hosted redaction library
Open-source toolkits are free and flexible. This compares the total cost of owning one against a finished local app.
DataAnonymiser is a best-effort redaction tool, not legal advice. It does not guarantee detection or removal of all personal data, nor compliance with GDPR, CCPA or any other law. Always validate outputs against your own obligations.