Best-effort on-device checks.
Clients attempt to replace detected personal data before sending; detection can miss details.
Cloak it first.
On supported client paths, on-device checks attempt to replace personal data they detect before sending. Detection is best-effort and can miss details, so unmatched content may reach the AI provider you selected. The gateway routes request content; it does not perform server-side personal-data detection or tokenisation. A receipt, when issued, records claims in its signed envelope and does not show that every personal-data value was found.
Detection is best-effort and may miss details or flag ordinary text. Review the content your client shows before sending; file and image handling varies by client and type. See the data map →
from openai import OpenAI
# via the CloakAPI local proxy, running on your machine
client = OpenAI(
base_url="http://localhost:8799/v1",
api_key="cloak_…",
)
# Best-effort client-side checks attempt to replace detected values; details can be missed.
# Example stand-in; unmatched details may still be sent to the selected provider.
resp = client.chat.completions.create(
model="claude-sonnet-5",
messages=[{"role":"user","content":
"Summarise email from <EMAIL_482>"}]
)
Pick by who you are
Same privacy architecture, five front doors. Tap “What you get” on any card for the full detail.
Keep the AI you already use with best-effort on-device checks for detected details; checks can miss content.
SDK — change your code. Add the library and change one line. PII the native Rust engine detects is tokenised on your machine; anything it misses goes out as written. By default, the SDKs stop with an error, and send nothing, when the on-device name model is missing.
Proxy — change one setting. Point base_url at localhost:8799 and write no code at all. This is also a way in for a local setup: a model or agent running on your machine can use the proxy to reach an outside AI. The client applies best-effort checks to values it detects; unmatched details may be sent as entered. It speaks the OpenAI and Anthropic formats, so compatible tools can use it. By default, the proxy answers 503 and sends nothing while its local name model is unreachable; you can opt in to structured-only protection.
MCP — your AI app calls the tools. Add CloakAPI to Claude Desktop, Cursor, Cline or Continue. Your app calls CloakAPI's tools directly — nothing to write. The MCP server does not stop a send when the name model is missing: it uses a built-in name list, and a name that list does not know goes out as written.
Structured PII needs no AI; free-form names use an on-device name model, and what happens when it is missing differs per tool, as above.
Enterprise: run one central proxy on your network and route every app through it. The enterprise pattern →
For anyone. No code, no setup — open it and ask. Browser checks attempt to replace detected names, emails and IDs; detection can miss details, so review what the client shows.
Nothing to install — instant, on supported devices. Browser checks attempt to replace detected identifiers, but they can miss details or flag ordinary text. Review the content your client shows before sending. The gateway routes request content and does not perform server-side personal-data detection or tokenisation. Chat holds a message while the on-device name model loads, and blocks it if the model fails to load, unless you choose to send with the layers that are ready. Try it free, no signup.
▣ Power up with the desktop app for confidential and bulk files: native on-device name detection, optional local LLM-as-judge, OS-held keys, an encrypted local token store (AES-256-GCM), local-only logs. Run it in Gateway mode (tokenised locally, then any cloud model) or Complete-local (the model runs on your own hardware, without a cloud model call). The desktop app holds a message while the on-device name model loads, and blocks it if the model fails to load, unless you choose to send with the layers that are ready. Reading the release register for published desktop builds… Download →
For ChatGPT / Claude / Gemini / Grok users. Keep using them with best-effort browser checks for detected identifiers; detection can miss details.
A browser extension for Chrome. Install it, then chat normally — the extension attempts to replace some structured identifiers and names on-device. Detection can miss details or flag ordinary text; review the content it shows before sending. The extension holds a message while the on-device name model loads, and blocks it if the model fails to load, unless you choose to send with the layers that are ready.
The extension is built for Claude, ChatGPT, Gemini and Grok. File handling varies by site and file type; not every client shows prepared file content before sending. If your client offers a “send unchanged” option and you choose it, the original file goes to your selected provider. Check what the client shows before sending; see Terms of Service §7b, Known limitations.
For people who build. Add client-side detection, gateway routing and receipts when issued to your app using available integrations; detection is best-effort and coverage varies by client.
The API and the Platform use shared building blocks — SDK, drop-in proxy and REST — for different jobs. On supported client paths, on-device checks attempt to replace detected personal data before sending, but may miss details. Review what the client shows; see Terms of Service §7b, Known limitations.
We built cloakup — a private-AI chat for everyday people — on this Platform. Its browser checks attempt to replace detected details before routing the request; detection can miss content. Receipts may be issued on supported paths and describe claims in their envelope.
Fork the Apache-2.0-licensed starter-kit, call the REST API, add the MCP connector to your own AI app, or embed an SDK (Reading the release register…). REST + proxy work today; the SDKs and the MCP connector (packaged as @cloakapi/mcp-server) are downloadable now from app.cloakapi.io/downloads/sdks/ — CloakAPI does not host an MCP endpoint, so it runs on your own machine or your own infrastructure. The starter-kit is not published as a download yet.
For people with a task in front of them — writing, a CV, email, redaction, a spreadsheet, a translation, a scan, a document library, a file conversion, a meeting. Browser checks attempt to replace detected identifiers; coverage and file handling vary by app, and some details may be missed.
cloak-write — Draft, proofread, re-voice or condense text that names real people; detected identifiers are swapped for realistic surrogates on your device before the text is relayed.
cloak-cv — Get a CV reviewed, rewritten or tailored to a job ad while the name, address, phone and email it detects are replaced with stand-ins on your device.
cloak-convert — Convert PDF, Word, Markdown, HTML, CSV, JSON and Excel files in the tab; deterministic conversions run entirely on your device.
cloak-post — Draft, reply to and summarise email; detected names, addresses and account numbers are cloaked on your device first. It does not send the mail for you.
cloak-redact — Redact sensitive documents on your device: it proposes, you review and correct, and the result comes with a verifiable receipt.
cloak-sheets — Ask a sensitive spreadsheet questions in plain English; the AI writes the analysis code and it runs locally over your real cells.
cloak-translate — Translate documents and text; detected names, emails, IDs and addresses are replaced with surrogates on your device, then mapped back afterwards.
cloak-scan — OCR a photo, screenshot or scanned document on your own device, with the identifiers it detects cloaked before anything is offered to an AI.
cloak-docs — A document library that stays in your browser: ask questions, request a summary or a redline, with detected identifiers cloaked before the question is relayed.
cloak-meet — Record or upload a meeting, transcribe it on your device, and have the AI summarise the cloaked transcript rather than the raw one.
Detection is best-effort: formats can be missed and ordinary text can be flagged. Name coverage differs by app; in eight apps it uses an on-device model, while cloak-convert and cloak-sheets use a built-in list without model-backed name detection. Review the content your client shows before sending; not every client shows prepared file content. File and image handling varies; see Terms of Service §7b, Known limitations. Each app has its own plan; see your account.
In the apps that use the on-device name model, a message or document is held while it loads and blocked if it fails to load, unless you choose to send with the layers that are ready.
Why CloakAPI
Not a policy promise — properties of the architecture, hard to cheaply copy. Filter by theme; tap any card for the full story.
Clients attempt to replace detected personal data before sending; detection can miss details.
The gateway does not run server-side personal-data detection or tokenisation.
Some clients use a local mapping to restore detected stand-ins; availability varies.
When issued, receipts record their claims and can be checked against the public JWKS.
15% pooled · 5% BYOK · 5% local. No API subscriptions.
The privacy policy and data map describe service data and retention.
Pick a mode per API key. Switch any time. $10 minimum top-up · $2 trial credit after email verification.
Under the hood
Three steps on the standard client-side paths. The honest caveats live one tap away.
On supported client paths, on-device checks attempt to replace detected identifiers. Detection can miss details or flag ordinary text; review what your client shows before sending.
The gateway routes request content to the selected provider and does not run server-side personal-data detection or tokenisation. Values missed on-device may be relayed as received.
When issued, a receipt records claims in its signed envelope and can be independently verified. It does not show that every personal-data value was found or that every request produced a receipt.
Configurations, not certifications. Detector + routing + retention configurations that map to common frameworks — these are configurations you can activate, not certifications we hold.
EU: GDPR · NIS2 · DORA · Health: HIPAA · UK-NHS DSPT · Financial: PCI DSS 4.0 · FINRA 17a-4.
Provider footprint: Anthropic · OpenAI · Google Gemini · xAI Grok · DeepSeek · self-hosted local (Ollama / LocalAI). One API, all current models.
The data map describes service data and hosting details. See it for the current categories and retention information.
On supported client paths, on-device checks attempt to replace detected personal data, but can miss details or flag ordinary text. The gateway routes request content and does not perform server-side personal-data detection or tokenisation. File and image handling varies by client and type; not every client shows prepared content before sending. Check what your client shows before sending, and do not send a file you are not prepared to share with your selected provider. See Terms of Service §7b, Known limitations. The data map describes service records and retention details.
Start with $2 of trial credit after email verification. No subscription, no seats — just a small markup on the AI you already use.