Written for the reviewer who signs off on tools before a clinician or a lawyer uses them. It states what happens to the files and text you mask, what PHIMask.com receives and never receives, and what PHI Mask does not claim.
Local processing
Detection, optical character recognition, replacement, and restore run in your browser, in the page or in the extension. The masking path sends no request carrying your text, your files, or anything derived from them.
Masking uses no large language model and no generative AI. There is no prompt, no inference request, and no model provider in the masking path. The detection models ship inside the product and run in the browser, which is why masking works offline.
Detection is not complete. The person masking reviews the result before sharing it, and handwriting is never read.
What we receive, and what we never receive
PHIMask.com never receives the files and text you mask. It does receive content-free operational metadata and what you deliberately submit, both described in full in the Privacy Policy and the Data Usage Policy.
Never received by PHIMask.com
Text you paste into the online masker or into a covered website.
Files you upload, attach, or drop.
Masked output, in text or in file form.
Individual detected values, and any per-value data tied to them.
Filenames and file metadata.
The reversible stand-in map used to restore values.
Page content, browsing history, and keystrokes.
Received by PHIMask.com
Free-use meter metadata: IP address, request timestamp, user agent, request path, standard request metadata used to count public free uses, and two yes/no device-state flags (whether the page load was a reload and whether the tab observed the browser offline) used only to decide whether offline loading is worth building.
Site analytics: page views, clicks, referrer, device and browser type, approximate location derived from IP address, and a visitor identifier. Session replay masks all text and inputs and blocks visual media.
A content-free masker session summary: aggregate document and detection-category counts, manual-mask count, a duration bucket, detector version, locale, result flags, and an unexpected-request count. It carries no text, filenames, mappings, or per-value data.
Advertising measurement: on eligible public marketing pages, /mask-data, and /tools/* pages, the Reddit Pixel sends PageVisit and standard browser, referrer, and page URL signals to Reddit. It carries no pasted text, files, detected identifiers, filenames, or masking results, and health-topic articles and other redaction routes are excluded.
Standard hosting logs: IP address, user agent, request path, and timestamp.
What you deliberately submit: a license or pilot request, a security report, a feedback rating and comment, and an optional masked or redacted attachment that is off by default.
From the online masker we receive how many detections fell into a category, never which values they were.
The Chrome extension runs no analytics, no advertising pixel, no free-use meter, and no PHIMask.com logging.
HIPAA posture
PHI Mask is HIPAA-compatible. Your file is masked in your browser and never sent to us, so there is no BAA to sign, and without a signed BAA we cannot claim HIPAA compliance. A business associate agreement covers a vendor that creates, receives, maintains, or transmits protected health information on your behalf, and PHI Mask does none of those things. Masking is also not automatic HIPAA Safe Harbor de-identification: the person masking reviews the result, handwriting is never read, and sending a masked copy to a model provider is still a disclosure to that provider.
Your file is masked in your browser and PHIMask.com holds none of it, so there is no business associate relationship for an agreement to govern.
Whether your organization needs its own agreement with the assistant you send a masked copy to is a separate question from PHI Mask.
Zero Data Retention
PHIMask.com retains no copy of your files or text, because it never receives them. There is no retention period to disclose, no backup, no archive, and no deletion request to make.
Retention does apply to the operational metadata and voluntary submissions listed above. Meter metadata and hosting logs are kept as long as abuse prevention, security, and debugging need them; license, support, and report records are kept while we respond to them. The Privacy Policy carries the current periods.
The extension keeps settings and whole-number masking counts in chrome.storage.local, and, on supported conversations, delivered stand-in pairs in chrome.storage.session for up to 24 hours of inactivity. Both live in your browser; the toolbar popup deletes them.
Data residency
Your files and text are processed in your browser, in the country and on the network you are working in. They are never sent to us and never stored by us, so they do not cross a border on their way to PHIMask.com.
PHIMask.com operates no processing or storage location for that content in any region, so there is no region to select and no transfer mechanism to arrange. Whether that satisfies your organization's residency requirement is your review to make.
Content-free metadata and voluntary submissions are processed on Google Cloud Platform and by the providers named in the Privacy Policy. If your requirement covers operational metadata, read that list before you approve the tool.
The assistant you send a masked copy to has its own residency posture; PHI Mask does not speak for it.
Certifications, and what we are not
PHI Mask holds no SOC 2 report, no ISO/IEC 27001 certificate, and no HITRUST certification, and it displays no third-party security badge.
SOC 2 and ISO 27001 attest to a vendor's handling of customer data in the vendor's systems. Nobody asks whether an offline text editor holds them, because the vendor never receives the text. Masking is in that class: your files and text never enter our systems.
What our systems do hold is the metadata and submissions listed above. If we pursue an attestation, the scope would be build and release integrity, extension permissions, the update mechanism, and the handling of those records.
PHIMask.com offers no business associate agreement, for the reason under HIPAA posture above.
Safeguards over website and support data: limited retention, restricted access to private submissions, encryption in transit and, where our providers support it, at rest, and a standing rule against training foundation models on feedback or customer content.
Report a suspected vulnerability through the private intake at phimask.com/security.
Offline attestation
The statements below are the ones a reviewer usually needs on file. Print this section or save it as a PDF for your records.
PHI Mask vendor attestation
Scope: the PHI Mask browser extension and the online masker at phimask.com/mask-data.Issued by: PHIMask.com.Last reviewed: 2026-08-28.
Statements
Masking runs in the user's browser. Detection, optical character recognition, replacement, and reversal of stand-ins are performed by code delivered to the browser and executed there.
Masking uses no large language model and no generative AI.
The masking path sends PHIMask.com no request carrying the user's text, files, or anything derived from them.
PHIMask.com does not receive pasted text, uploaded files, masked output, detected real values, filenames, file metadata, or the reversible stand-in map.
Zero Data Retention: PHIMask.com keeps no copy of the user's files or text, because it receives none. There is no retention period, backup, or archive of that content.
The user's files and text are processed in the browser, in the country the user is working in. PHIMask.com operates no processing or storage location for that content in any region.
HIPAA posture: PHI Mask is HIPAA-compatible. Your file is masked in your browser and never sent to us, so there is no BAA to sign, and without a signed BAA we cannot claim HIPAA compliance.
PHIMask.com is not a business associate. A business associate agreement covers a vendor that creates, receives, maintains, or transmits protected health information on your behalf, and PHI Mask does none of those things.
Masking is not automatic HIPAA Safe Harbor de-identification, and it is not expert determination. The person masking reviews the result before sharing it.
PHI Mask holds no SOC 2 report, no ISO/IEC 27001 certificate, and no HITRUST certification, and PHIMask.com claims none.
PHIMask.com does not use feedback, prompts, files, masked content, diagnostics, or customer content to train foundation models.
Scope and exclusions
These statements cover the files and text the user masks. They do not cover the content-free operational metadata phimask.com receives: free-use meter metadata, hosting logs, site analytics with text and inputs masked in replay, advertising measurement on eligible public pages, and a content-free masker session summary.
They do not cover what a user deliberately submits: a license or pilot request, a security report, support correspondence, a feedback rating and comment, or an optional masked or redacted attachment that is off by default.
They do not cover the assistant, model provider, or website a user sends a masked copy to. That disclosure is governed by that provider's terms and by any agreement the user's organization holds with it.
They do not cover the user's own browser, operating system, other extensions, network, device management, or backup software, and they are not a statement about the security of that environment.
Detection is not complete and no detection rate is claimed. Handwriting is not read. The person masking reviews the result before sharing it.
There are no certifications or audit opinions to report.
What this document is
This is a vendor attestation: PHIMask.com's statement about its own product, made on the date above. It is not a certification, an audit report, or a third-party opinion.
Verification
The current version of this attestation is published at https://phimask.com/compliance. Check that page's last-reviewed date against your printed copy. Questions and evidence requests go through the form at https://phimask.com/#apply.