Guide

PHI Mask vs. browser privacy extensions

Prompt-scrubbing extensions act on the chat box; document masking acts on the file. Where each one's coverage ends, and why running both is reasonable.

Last reviewed

Prompt-scrubbing extensions watch the box you type into and swap sensitive values out before the message is sent. They are genuinely useful for that job. The difference worth understanding is where each approach sits: one works on the prompt at the moment of sending, the other works on the document before it becomes a prompt.

What a prompt-scrubbing extension does

The category is real and active. These tools install into the browser, watch supported assistant pages, and replace detected values with placeholders as the prompt is composed. Several are explicit that detection runs on the device rather than on a server, and several restore the original values when the assistant's reply comes back carrying the placeholders, which makes the substitution reversible within the session.

That is a sound design for the case it targets. If your risk is typing a client name into a chat box out of habit, a tool that intercepts at the box is well placed to catch it, and it catches it without you remembering to do anything.

Where the two approaches differ

The distinction is not which one is careful. It is which surface each one can act on, and how far that reach goes.

QuestionPrompt-scrubbing extensionDocument masking
What it acts onThe text in a supported assistant's input boxThe document itself, before you decide where it goes
Documented inputsPrompt text, and in some tools local files they are pointed atPasted text, screenshots, and PDFs in one workflow
Where the work happensIn the browser, for tools that state on-device processingIn the browser tab you opened
Getting the real values backSome restore placeholders in the assistant's reply automaticallyA map held in that tab restores them when you choose
Where it worksThe assistant pages it supports, and the input boxes it hooksAny destination: an assistant, an email, an upload, a portal
Best fitCatching habitual typing into a chat boxPreparing a file to send somewhere, including by email or upload

The question to ask about either one

Ask what happens to an attachment. A screenshot of an intake form or a scanned PDF is not text until something reads it, so any tool that matches on text needs a separate step before it can act on that content at all. Whether a given extension performs that step is a question for its own documentation, and the honest answer for most of the category is that their documentation describes text rather than images.

Ask where the substitution map lives and how long it survives. Reversibility is a feature, and it means a route back to the original exists somewhere. Knowing where is the difference between a considered choice and an assumption.

Ask what happens on an unsupported surface. An extension bound to specific assistant pages is not present in a webmail compose window, a support ticket, or a form on a portal, and those are the places sensitive text actually tends to go.

They are not mutually exclusive

Running both is a reasonable arrangement, and they fail differently, which is the point. An extension is a standing net over the boxes you type into. Document masking is a deliberate step you take when you have a file to prepare. Neither removes the need to look at the result before it leaves.

Where PHI Mask fits

PHI Mask does both. Its browser extension masks names, dates, and identifiers as you paste them into an assistant, and puts the real values back when the reply comes. Its document lane takes text, a screenshot, or a PDF and gives you a covered copy to send anywhere else the content needs to go: an email, an upload, a portal, a colleague.

The second half is the one most of the category does not have. A screenshot of an intake form is not text until something reads it, and PHI Mask reads identifiers inside an image or a PDF rather than requiring the content to be text first. Detection runs on your device in both lanes, and the map between real values and stand-ins stays in the tab you were working in. Detection results by document type are published openly on the benchmark.

Review before sharing.

Start with text, a PDF, or a screenshot.

Sources and review notes

This page describes the extension category by mechanism rather than naming individual products, because the tools in it are small and frequently updated and a per-product table would go stale between reviews. Statements here reflect a review of published extension documentation on the date shown at the top of this page.

Common questions

Do prompt-scrubbing extensions work?
For the job they target, yes. They watch a supported assistant's input box and replace detected values as you compose, and several state that detection runs on your device rather than on a server.
Do they handle a screenshot or a PDF?
Their documentation generally describes text. Anything matching on text needs a separate step to read an image at all, so treat attachment handling as a question for the specific tool's own documentation.
Can the original values be recovered?
In several tools, yes, by design: they restore the real values when the assistant's reply comes back carrying the placeholders. That means a route back exists, so it is worth knowing where the map lives.
What happens outside a supported site?
An extension bound to specific assistant pages is not present in a webmail compose window, a support ticket, or a portal form, which are places sensitive text also tends to go.
Should I use an extension or a masker?
They fail differently, so running both is reasonable. An extension is a standing net over boxes you type into; document masking is a deliberate step when you have a file to prepare.