LLM Masker
On-device prompt privacy

The secrets in your prompt, masked before you hit send.

You paste code, logs or a message into ChatGPT — and an API key or card number sneaks in with it. LLM Masker catches it inside your browser and swaps it for a safe placeholder, the instant before the prompt leaves your machine.

Nothing uploadedNo accountFree forever
Try it — live Runs in your browser
Loading the detector catalog…

This demo runs the extension's actual detector catalog — 90+ patterns — right here on the page. Every match becomes [REDACTED_BY_LLM_MASKER], exactly as it does in your chats.

How it works

Three things happen, all before the network request

No magic, no cloud. Just a fast pass over your prompt in the moment between you sending and the browser transmitting.

01

It watches the box

The moment you paste, press Enter or click send, LLM Masker reads the prompt in the page — before the request goes out. Optionally, it masks while you type too.

02

It swaps in a placeholder

Each secret becomes [REDACTED_BY_LLM_MASKER]. Everything else in your message is left exactly as written.

03

It sends the safe version

Only the masked prompt leaves your browser. The AI answers with full context; your secret never travels. If a secret somehow can't be masked, the send is blocked instead.

90+ patterns · 13 groups

The things people actually paste into AI chats

Every detector is on by default and has its own switch. Each is anchored to a vendor's key shape, a checksum, or an assignment context — so ordinary prose and code sail through untouched.

AI provider API keys

OpenAI, Anthropic, Google (Gemini AQ.Ab… & AIza…), ElevenLabs, Hugging Face, Groq, Perplexity, xAI, OpenRouter, Replicate, Pinecone, LangSmith, Tavily

sk-proj-9f3aQ27bXsT1…→masked

Cloud credentials

AWS keys & secrets, Google OAuth tokens & client secrets, Azure client secrets & storage keys, DigitalOcean, Alibaba, HashiCorp Vault, Terraform Cloud

AKIAJ7QXMPLE4NDEV22Q→masked

Developer platform tokens

GitHub, GitLab, npm, PyPI, Docker Hub, Vercel, Sentry, New Relic, Postman, Grafana, Databricks, Linear, Notion, Figma, Atlassian, Supabase and 10+ more

ghp_A1b2C3d4E5f6G7h8…→masked

Payment & commerce keys

Stripe / Clerk secret keys, Stripe webhook secrets, Razorpay, Square, Shopify, PayPal / Braintree

sk_live_51H8xQ2eZvKYlo…→masked

Messaging & webhooks

Slack tokens & webhook URLs, Discord bot tokens & webhooks, Telegram bot tokens, Twilio, SendGrid, Mailgun, Mailchimp, Meta, X

xoxb-2049-8123-callmemaybe…→masked

Passwords, keys & connection strings

password=, "api_key": "…", Authorization: Bearer, x-api-key headers, private-key blocks, postgres://user:pass@…

DB_PASSWORD=Tr0ub4dor&3→masked

Personal & financial data

Emails, phone numbers, JWTs, credit cards (checksum-verified, spaced or not), IBANs (country + mod-97)

4242 4242 4242 4242→masked

National ID numbers

US SSN, India Aadhaar (checksum-verified) & PAN, UK National Insurance, Canadian SIN. Public IP addresses are an opt-in extra.

ABCPD1234E→masked

Formats are cross-checked against the open-source gitleaks and TruffleHog rulesets. Full list in the user guide; how it stays precise in the security write-up.

Built to be trusted

Nothing you type is ever uploaded.

A privacy tool you have to trust with your secrets should be the easiest thing to verify. So there's nothing hidden to trust.

On-device only

Detection runs entirely in your browser. Your prompts never touch a cloud — not even ours. There is no scan server to send them to.

No account, ever

Nothing to sign up for, no login, no email collected. Install and it just works. Free users make zero network requests.

Counts, not content

The dashboard records how many secrets were caught and of what kind — never the secrets themselves.

Verify it in one minute

Open DevTools → Network on any AI chat, paste a secret, watch: no requests. The whole privacy claim is falsifiable on the spot. Technical details →

Proof, not promises

See every mask it made

A local dashboard shows what was caught, when, and where — storing counts only, never the values themselves. Quiet confirmation it's doing its job.

  • Catches on paste, on Enter, and on the send button
  • Placeholders keep the AI's context intact
  • Counts stored locally — export or wipe them any time
  • Works on ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity & Google AI Mode
Pricing

Free to protect. PRO to power up.

Every detector, every site, forever free. PRO adds control for people who want the masker to fit their exact workflow.

Free
$0forever
No account needed
  • All 90+ detectors, on by default
  • Works on all 7 supported AI tools
  • Mask on paste, on typing, on send
  • Local dashboard, counts & JSON export
Add to Chrome
PRO POWER
$1.99/mo · or $19/yr
₹49 / mo · ₹499 / yr in India
Everything in Free, plus
  • Custom detection rules (text or regex)
  • Allowlists — values that must never be masked
  • Private audit log — 1,000 events, 12 months, per-site
Go PRO

Cancel any time · 7-day money-back · licence code, no account · full pricing & checkout →

FAQ

Questions, answered

Does anything I type get uploaded?
No. All detection and masking runs locally in your browser. There is no account, no server reading your text, and nothing is ever sent to us. The only network request the extension can ever make is an optional 24-hour licence check for PRO users — and it carries the licence code, nothing else.
Which AI tools does it work with?
ChatGPT, Claude, Gemini, Microsoft Copilot, DeepSeek, Perplexity and Google AI Mode. On google.com it touches only the AI Mode composer, never ordinary Search.
What exactly does it detect?
AI provider API keys, cloud and developer platform tokens, payment keys, messaging tokens and webhooks, private-key blocks, connection strings with passwords, password/API-key assignments and Authorization headers, JWTs, emails, phone numbers, checksum-valid cards, IBANs and national IDs — 90+ patterns in 13 toggleable groups. Every pattern is anchored to a vendor's key shape, a checksum or an assignment context, so normal prose and code aren't touched.
Will the AI still understand my prompt?
Yes. The secret becomes a clearly-labelled placeholder — [REDACTED_BY_LLM_MASKER] — so the model keeps the surrounding context and knows a value was there; it just never sees the value itself.
What if something isn't caught, or is caught wrongly?
Detection is pattern-based, so it can't recognise a free-form secret written as a plain word. If a secret is detected but somehow can't be masked, the send is blocked instead of sent raw. Anything over-eager can be switched off per group in Settings — and PRO's allowlist exempts specific values.
Is it really free?
Yes. Every detector on every supported site is free forever, with no account. PRO adds custom rules, allowlists and a private audit log for $1.99/month or $19/year (₹49/₹499 in India), paid through Razorpay with a 7-day money-back guarantee.

Put the mask on.

Free forever, no account. Your secrets stop at your browser.

Add to Chrome

Free on the Chrome Web Store. New here? Read the user guide.