mask2ai
Personal data stays on your machine when you talk to an AI.
What it does
Before a message, a file or a command result leaves your machine, mask2ai replaces every email, phone number, card number, IBAN, national ID, social security number, date of birth, name and street address it finds with a placeholder such as __PII_EMAIL_ae44b4__. The model only ever works with placeholders. On your screen, in your files and in the commands that run, the real values are put back.
Nothing is sent anywhere else. There is no server, no account and no dependency beyond Node.js.
Prerequisites
- Claude Code: Node.js 18 or newer on
PATH. - claude.ai and ChatGPT: Google Chrome 111 or newer, and
gitto fetch the code.
Install
Claude Code
/plugin marketplace add serkankorkut/mask2ai
/plugin install mask2ai@mask2ai
claude.ai and ChatGPT in Chrome
git clone https://github.com/serkankorkut/mask2ai.git
chrome://extensions→ Developer mode → Load unpacked → select themask2aifolder.
Where it works
- Claude Code CLI, as a plugin with six hooks: prompts, tool output, tool input and the on-screen reply.
- claude.ai in Chrome, as an extension that rewrites the outgoing request in the page.
- ChatGPT web in Chrome, same extension, same code.
The Chrome extension is called mask2ai, version 0.3.0. It is verified on claude.ai and chatgpt.com on every change by node demo/verify-web.js, which loads it into headless Chrome, sends a chat request from the page and checks that only placeholders leave the browser and that the page restores them.
Detection covers English and Turkish formats, with checksums for cards, IBANs and TC numbers.
Verify it
Do not take the page's word for it. The repository ships three checks.
npm test # detection, restoration, request rewriting
node demo/prove.js # every byte Claude Code sends, captured and inspected
node demo/verify-web.js # the extension on claude.ai and chatgpt.com, headless
The second starts a fake Anthropic API on localhost, points the real claude binary at it and asserts that a prompt with an email produces zero requests and that a file read arrives as placeholders only.
Limits
Detection is pattern based. Structured identifiers are matched reliably. Names and addresses are matched when a label, a title, a cue or a matching email is nearby; a bare name in free text is not. Health, religion or income stated in prose is not detected. Images are not inspected.