Blog

Anonymize a prompt before you ask

Swap the identifying bits for stable stand-ins so the question still makes sense.

Anonymizing a prompt means taking out the parts that point at a real person or a real secret, and leaving a shape the assistant can still follow. It is editing, not magic.

Why the stand-in should stay stable

If a message mentions the same person twice, a single stand-in is easier to read than two different fakes. “Ask [PERSON_1] to call [PHONE_1]” still tells the model what to do. “Ask Alex to call Jordan” invents people, and you might later mix those inventions up with real ones.

Tokens like [EMAIL_1] are dull on purpose. They are labels, not a disguise that looks like a new identity. Do not anonymize by borrowing a real other person’s name or email. That just points at someone else.

By hand, or in the field

Doing it yourself is always available. Read, replace, send. Vipra is the same idea sitting on the text field: it shows Name, Email, and Phone (and the other types it supports) and can replace the ones you protect. The original swap happens in the browser. The chat then sees the tokens, not the address.

It will miss things. A first name with no context, a nickname, or a story told entirely in roles may not be flagged. Anonymize the obvious parts, then decide if the rest of the paragraph should go at all.