Privacy-first AI chat

Ask anything. Reveal nothing.

Scrubd AI is a complete chat interface for leading AI models. Sensitive values in your message are replaced with typed placeholders before it reaches the model, then restored on your device. Same answer. None of the exposure.

What you type

Can you check this reconciliation? Maria Delgado at Brightline Studio was invoiced $12,480 on 14 March, but the account ending 5219 shows only $9,300 received. Her copy went to maria@brightline.studio.

What the model sees

Can you check this reconciliation? [NAME_1] at [ORGANIZATION_1] was invoiced [MONEY_1] on [DATE_1], but the account ending [NUMERICAL_PII_1] shows only [MONEY_2] received. Her copy went to [EMAIL_ADDRESS_1].

the model answers in placeholders
What you see

The account is short $3,180. Treat the $9,300 as a part payment against $12,480, then follow up with Brightline Studio for the balance.

What the model returns

The account is short [MONEY_3]. Treat the [MONEY_2] as a part payment against [MONEY_1], then follow up with [ORGANIZATION_1] for the balance.

Two promises, stated plainly.

These are the only two we make. We would rather be precise than impressive.

01

Your identifiable information never reaches the AI model.

Names, addresses, email addresses, phone numbers, monetary amounts, dates, organisations, and ID and account numbers are replaced with typed placeholders before your message is sent onward. The model only ever receives the placeholder version.

02

We hold no key that can read your conversations.

Your real values live only inside an entity map that is encrypted on your device under a key derived from your passphrase. We cannot see your real values.

How it works.

The full sequence, from signing up to reading an answer.

Happens on your device
Happens on our server
Happens at the AI model
Once, when you sign up
1

You choose a passphrase.

Separate from your login password, and never sent to us. Your device uses it to build an encryption key that stays on your device.

2

We store a locked copy of your key.

Locked under your passphrase, and again under a one-time recovery code shown to you once. We hold nothing that opens either.

Because we never receive your passphrase or your recovery code, losing both means your data cannot be recovered — by you or by us. That is the cost of the guarantee, and it is deliberate.

Every time you send a prompt
3

You write naturally.

Real names, real figures, real documents. Nothing to mark up and nothing to decide about.

4

Sensitive values become placeholders.

Your text reaches our server so it can be scanned — that is how it gets protected at all. Names, addresses, organisations, dates, amounts, and ID and account numbers are replaced with typed placeholders like [NAME_1] and [MONEY_1], numbered consistently so the model can still tell who is who. You see the sanitised version before anything is sent. If any part of this fails, nothing is sent.

5

Your real values are sealed on your device.

The list linking each placeholder to its real value is encrypted on your device under your key, and only the sealed result comes back to us. Your original text is never stored anywhere — the placeholder version is all that persists on our side.

When the model answers
6

Only placeholders reach the AI model.

The model is asked about [NAME_1], with no account identifier attached — nothing ties one request to another as coming from you.

7

Your values return in the answer.

The reply comes back still containing placeholders, and your device puts your real values back as it streams in. You read a normal, complete answer. This never happens on our server.

8

And again whenever you reopen it.

Your conversation is stored with placeholders and rebuilt on your device each time — which is why signing in on a new device or browser asks for your passphrase.

The AI model never receives your real values, and we hold no key that can read them. Two separate protections, and both hold independently.

What gets replaced.

Each type keeps its meaning and its numbering, so the answer comes back coherent.

Names[NAME_1]
Addresses[LOCATION_ADDRESS_1]
Email addresses[EMAIL_ADDRESS_1]
Phone numbers[PHONE_NUMBER_1]
Monetary amounts[MONEY_1]
Dates[DATE_1]
Organisations[ORGANIZATION_1]
ID and account numbers[NUMERICAL_PII_1]

What we can read, and what we can’t.

Your text does reach our server — that is how it gets sanitised. So it matters exactly what is readable there and what is not.

Stored in readable form
  • The placeholder version of your messages
  • The model’s responses, in their placeholder form
  • Which model you chose, and when
Encrypted on your device
  • Your entity map — every real value behind every placeholder
  • Your chat titles
  • Your project names

We do not describe your messages as end-to-end encrypted, because they are not. The placeholder version is stored in readable form. What we cannot see is your real values.

A full chat interface. Nothing to change.

Scrubd AI is the chat app itself, not a plugin or a proxy you have to remember to switch on. You choose a leading model and work the way you already do.

Leading models

Pick the model you want for the task. The protection is the same whichever you pick.

Projects and history

Keep related conversations together. Chat titles and project names are encrypted on your device.

Nothing to redact

No manual scrubbing, no shorthand for real names. Write the message you actually mean.

Written for anyone with something to protect.

A letter about a diagnosis, with the diagnosis in it.

Personal and medical matters

A statement to make sense of, with the account numbers still attached.

Financial and household admin

A client’s file, under a duty of confidence you cannot waive.

Professional obligations

Pricing

Every plan starts with a 7-day free trial, and no card is required to begin.

The free trial includes a set number of credits, includes every feature, and requires no card. When it ends, nothing is charged unless you choose a plan.

Standard

Private AI for everyday use.

$19.99/mo

Enough credits for everyday use — a steady habit of questions, drafts and the occasional document.

Start free trial
Recommended

Pro

For heavier, document-driven work.

$39.99/mo

A substantially larger credit allowance for sustained daily use and regular document work.

Start free trial

Every feature, on both plans.

Automatic sanitisation of names, addresses, amounts, dates, emails, organisations and ID numbers
Leading AI models
Dual view — see exactly what the model received
Document handling, up to five files per message
Projects and standing instructions
Encrypted entity maps, chat titles and project names
Auto-deleting chats and retention controls
Per-category control over what gets detected

The difference between the plans is how much you use, never what you can do. Privacy is not a paid upgrade.

Questions worth asking.

Yes. Your message reaches our server, which is how it gets sanitised. What is sent onward to the AI model is the placeholder version, and the placeholder version is what we store.

Same answer. None of the exposure.

Start a conversation at scrubd.ai and keep your details to yourself.