Skip to content
Make it yours

Filtering sensitive text

Configure outbound filtering and understand what the filter can and cannot cover.

In this topic

Privacy Filter replaces detected sensitive text with placeholders in supported requests to remote model providers. Mellow keeps the mapping locally so it can restore values in the displayed response. This can reduce accidental disclosure, but detection is experimental and a review remains valuable for important material.

The filter is not a universal network proxy. Search queries, messaging sends, plugin traffic, file uploads, and every possible binary attachment should not be assumed covered simply because the model filter is enabled.

Set up a realistic test

Open Privacy → Filter and enable Scrub PII before sending to cloud providers. Begin with synthetic data rather than a real password or personal record.

Draft a greeting for Example Person at [email protected]. Keep the address as a contact field.

Select a remote model provider and inspect the review sheet. Check what was detected, what remains visible, and whether any needed context was incorrectly removed. The final displayed answer can restore local values; it is not necessarily a literal view of what the provider saw.

Local inference routes do not need this remote-request transformation. A local agent can still send data through other enabled tools, which must be considered separately.

Choose detection layers

LayerUseful forMain limitation
Built-in patternsStructured values such as emails and account-like identifiersShape-based matching can miss unusual formats or match harmless text
Regional presetsIdentifiers relevant to selected countries or regionsEnable the relevant region; not every preset is on by default
Custom rulesOrganization-specific labels or identifiersPoor rules can overmatch or miss important variants
On-device classifierLess structured entities such as names or addressesRequires its model and can produce false positives or misses

The current model options include the OpenAI privacy-filter model and Rampart. Use the size and readiness shown in Mellow when installing; a downloaded file is not sufficient if the model cannot load. Installing an optional classifier changes coverage, not the destination of the classification step: it runs on the device.

Read the review sheet

The review presents detected spans and the outgoing text transformation. Check whether a value is truly sensitive, whether the replacement keeps the task understandable, and whether unmarked text contains information you intended to hide.

Approve only after checking the result. Adjust a detection or rule when needed, then inspect the updated preview. A provider override can bypass the filter for that provider; make that decision deliberately rather than using it as a generic fix for a stalled request.

The always-approve preference changes review behavior but does not make detection more accurate. For unattended requests, the separate background-review setting determines whether detections hold the request instead of silently continuing.

Placeholder lifecycle

Mappings are scoped to a conversation and held in memory. Repeated use of the same detected value can be represented consistently inside that session. Example placeholders include [EMAIL_1], [PHONE_1], and [PERSON_1].

Do not rely on these temporary mappings as a long-term encryption or storage format. Restarting the app can discard the in-memory mapping. A provider response containing a placeholder is also not proof that it understood the original value; it only had the transformed context.

Configure the tradeoffs

SettingEffect
Master scrub toggleEnables the remote-request filtering path
AI detectionAdds the selected local classifier
Skip Code BlocksExempts fenced and inline code spans from detection; review code for secrets separately
Always Approve by DefaultReduces repeated review according to session behavior
Require Review for Background RequestsHolds detected background requests when review cannot be completed
Detection patterns and region presetsDetermine which categories and formats are detected
Custom rulesAdd task- or organization-specific matching
Provider overridesEnable or bypass filtering per configured provider

Disabling a category affects both its detection and the corresponding post-scrub check. If you intentionally allow phone numbers, the filter should not later block the same category as an unexplained leak.

Failure behavior

When a configured detection stage is required but unavailable, the pipeline can stop rather than silently send the original text. A request waiting for review is different from a model or network timeout. Inspect the filter's readiness and pending review before retrying the entire task.

Large text can be processed in chunks. Text fields in multimodal requests, tool arguments, and other supported request context can pass through the filtering pipeline, but that does not make image pixels or arbitrary file formats safe to transmit. Review attachments separately.

Detect or redact a file

In a supported local working-folder chat, detect_pii scans text and reports findings without writing. redact_file creates a deterministic redaction operation that can participate in the file-change and undo workflow. Use the read-only scan first, review the categories and locations, then request a redacted result.

Task-specific custom rules can be supplied without permanently changing the global rule set. When only pattern detection is available, read the coverage warning instead of assuming classifier coverage. File redaction is restricted for external callers; an HTTP integration should not assume it has the same privileges as an attended local chat.

Troubleshooting

Nothing was flagged: confirm the provider override, master setting, enabled categories, and whether the value sits in an excluded code block.

Too many false positives: narrow a custom expression or disable an irrelevant regional preset, then retest with representative synthetic text.

Requests stop after a model change: inspect classifier readiness and the filter error; do not bypass protection before understanding the failed stage.

A scheduled request never reaches the provider: inspect whether background review is required and pending.

The answer shows the real value: local restoration may have occurred. Use the supported request diagnostics to inspect the transformed payload rather than judging only the final message.

A value in an image was not hidden: the text filter is not an image-redaction guarantee. Review screenshot masking and attachment handling separately.

Settings are stored in the profile's privacy-filter configuration; classifier bundles live in auxiliary-model storage. Back up custom rules with the rest of your configuration. See Security and Computer Use for the other boundaries involved.

Continue exploring · Make it yoursData and encryption →Locate stored data, manage protection and plan backups or cleanup.