Privacy-first AI infrastructure.

Velum

A 5-minute privacy check before pasting into any AI

Aug 3, 20265 min read

Most data leaks into AI tools are not dramatic. No hacker, no breach. Just a busy professional pasting a real email, a real contract, or a real support ticket into a chatbot to save ten minutes. The text helps you get an answer. It also travels to a server you do not own, where it may be stored, logged, or used to train a future model.

You cannot un-paste. So the only reliable moment to protect someone is before you hit enter. Here is a check you can run in your head in under five minutes, every time, until it becomes a habit.

Start with one assumption

Assume the prompt could be stored forever.

That single assumption does the heavy lifting. Once you treat every paste as permanent and potentially readable by strangers, the right behaviour gets obvious. You stop asking "is this tool safe enough" and start asking "what in this text would I regret leaving in a public place." The first question depends on a vendor's promises. The second depends only on you.

The 60-second scan

Before you paste anything, read the text once and look for the items below. If any of them are present, the text is not ready yet.

  • A name, including initials or a nickname that points to one person
  • An email address or a phone number
  • A national ID, passport, tax, or social security number
  • A home or work address, or anything narrowing down a location
  • Account numbers, case numbers, invoice numbers, or reference codes
  • Health details, financial details, or anything about a person's private life
  • Dates of birth, employment dates, or other dates tied to an individual
  • Anything that, combined with the rest, could identify a person or a client

That last point is the one people miss. A job title on its own is harmless. A job title plus a company plus a city plus a project name can point to exactly one human being. Personal data is not only the obvious identifiers. It is any combination that narrows the field to a single person. When you scan, think about the pieces together, not just one at a time.

If you find something, mask it first

You usually do not need the real values for the AI to help you. The model can draft a reply, summarise a thread, or fix the tone of a paragraph just as well with placeholders in place. So replace the sensitive parts before you paste.

A few quick ways to mask:

Swap names for roles or labels. "Maria Gomez" becomes "the client." "Dr. Patel" becomes "the physician."

Replace numbers with shapes, not real digits. An account number becomes "[ACCOUNT]." A case reference becomes "[CASE-REF]." Keep the structure if the format matters, drop the actual value.

Cut details you do not need. If the city, the date, or the exact amount is not required for the task, remove it rather than mask it. The safest data is the data that is not there.

Keep a small map for yourself. If you need the real values back in the output, note that "[CLIENT]" meant Maria, on paper or in a local file, not in the prompt. Then put the real names back into the AI's answer on your own machine.

The goal is simple. The model gets enough context to be useful. It never gets enough to identify anyone.

A worked example

Here is a raw prompt many people would paste without thinking:

"Draft a firm but polite reply to John Mercer (john.mercer@acme.test) about invoice 88421, which is 30 days overdue for 14,500 dollars."

Run the scan. There is a name, an email, an invoice number, and a financial detail tied to a person. Now mask it:

"Draft a firm but polite reply to [CLIENT] about [INVOICE], which is 30 days overdue for [AMOUNT]."

Same draft comes back. The chatbot never learned who John is, what he owes, or how to reach him. You drop the real values into the finished reply yourself.

Make it a habit, not a project

You will not do this if it feels like a chore. So shrink it to a reflex. Three beats, every paste:

Assume it is permanent. Scan for the list above. Mask anything that points to a person.

Five minutes the first few times, under a minute once it sticks. The habit costs far less than a single disclosure of a client's data, and it keeps the decision in your hands instead of in a privacy policy you will never read.

Or let the check run itself

Doing this by hand works, but humans get tired, rushed, and distracted, which is exactly when the mistakes happen. A tool can run the same scan every time without skipping the day you are busy.

That is what Velum does. It spots the names, emails, numbers, and other identifiers in your text and masks them for you, locally on your own device, before anything is sent to an AI. The raw text never leaves your machine, and the real values are restored only in the answer you get back. The check still happens. You just stop having to remember it.

If you want a whole team running this check rather than one person, Annex D of the free AI usage policy template is a one-page version written to be circulated as it stands.

See how Velum handles it, or request a demo and try the masking on your own text.

Share this article
XLinkedIn

Keep reading