AI & LLM Tools

AI Prompt Redactor

Before you paste logs, code or customer messages into an AI chat, strip out what should stay private. This redactor applies pattern rules in your browser to mask email addresses, phone numbers, IPv4 addresses, JWT-like and bearer tokens, API-key-like strings, private-key blocks and credit-card-like numbers that pass a checksum. Each match becomes a clear placeholder, and a count summary shows what was changed. It is a convenience for common patterns, not a guarantee, so you still need to review the output.

Your workspace

Runs locally in your browser

Automatic detection can miss sensitive information. Review the redacted text before sharing it.

Detections

Result

Your input is processed locally in your browser and is not sent to Flutters servers. Inputs are not saved by this tool.

How to use this tool

Paste your text, choose which detections to keep on, then choose Redact. Review the result carefully before copying and sharing it.

Example

Input

Contact ada@example.com from 192.168.1.10 with Bearer abcdefghijklmnop

Output

Contact [EMAIL_REDACTED] from [IP_REDACTED] with Bearer [TOKEN_REDACTED]

What does this tool do?

Prompts, logs and support transcripts often contain emails, tokens or keys that should not be pasted into a third-party chat. This tool scans your text locally with pattern rules and replaces matches with labelled placeholders such as [EMAIL_REDACTED], then summarizes how many items of each kind it masked.

Common mistakes and limitations

Automatic detection can miss sensitive information. Names, addresses, internal project names, secrets in unusual formats and context-dependent personal data are not detected, and some harmless text, such as a version number that looks like an IP address, may be masked. Review the redacted text before sharing it, and remove secrets at the source whenever possible.

What it looks for

The redactor uses patterns for email addresses, phone-like numbers, IPv4 addresses, JWT-like strings, bearer tokens, common API-key prefixes and assignments such as api_key=value, private-key blocks and card-like numbers that pass a Luhn checksum. Each detection can be switched off if it produces false positives in your text.

Authorization: Bearer abcdefghijklmnop
-> Authorization: Bearer [TOKEN_REDACTED]

Limits of pattern matching

Patterns cannot understand context. A customer's name, a street address, an internal hostname or a secret with no recognizable prefix will pass through untouched, while an ordinary number may occasionally be masked. Read the whole result and delete anything sensitive that remains. If a live credential has been pasted anywhere, rotate it; masking a copy does not make the original safe.

Related: JWT Decoder, Base64 Encoder and Decoder

Safer habits for AI workflows

Share the minimum text needed, use fake sample values when you can, and keep real secrets in a password manager or environment store rather than in prompts. Generate fresh test credentials when you need an example.

Related: Password Generator, Prompt Template Builder

Frequently asked questions

Does it guarantee that sensitive data is removed?

No. It catches common patterns only. Always read the result yourself before sharing it.

Is the text uploaded for detection?

No. Detection runs in your browser with regular expressions, and the text is not sent to Flutters servers.

What if a real key was already exposed?

Redaction does not undo exposure. Revoke and rotate any credential that was pasted somewhere it should not have been.

Related tools