A tax file is someone's entire financial life with their name on every page. You shouldn't have to strip out names and tax IDs by hand before pasting a return into ChatGPT or Claude — and then put them all back afterwards. Our on-device detector makes a best-effort pass before supported content is sent. It can miss identifying details, so review content before sending. See Terms of Service §7b, Known limitations.
No card required. You land straight in a simple chat — drop a file and ask.
Three steps. No setup, no training, nothing to install. If you can attach a file to an email, you can use this.
Drag in the return, computation, capital-gains schedule or tax-authority letter you're working on. On supported client paths, the client makes a best-effort pass for identifying details before sending. Coverage varies by content and format, and detection can miss. Review the content your client shows; see Terms of Service §7b, Known limitations.
On supported paths, the client attempts to replace personal data it detects with placeholders. Detection may miss details, so unmatched content may reach your selected AI provider. Review the content your client shows before sending; see Terms of Service §7b, Known limitations.
A client may use its local mapping to restore values it detected in a response. Detection and restoration can be incomplete, so review the result before relying on it.
Detection is best-effort on supported client paths. It can miss identifying details or formats; unmatched content may be sent to your selected AI provider. Review the content your client shows before sending; see Terms of Service §7b, Known limitations. File and image handling varies by client and type; not every client shows prepared content before sending. Read the data map for service data handling.
Name and identifier coverage varies by client and content type. Detection may miss details, and file handling can differ by format. Review the content your client shows before sending. If your client offers a “send unchanged” option and you select it, the original file bytes go to your selected provider. See Terms of Service §7b, Known limitations and available client options.
Tax advisers carry a professional duty of confidentiality over some of the most sensitive data there is — income, assets, family arrangements. Here is what the architecture actually does, so you and your own advisers can evaluate AI use against that duty — this is not legal advice.
The workarounds people use today are slow — and fragile.
The manual rename. "Taxpayer A", "Company X", find-and-replace before pasting — then reversing it all in the answer, hoping you didn't miss one instance on page 14.
The retyped summary. Typing an anonymised version of the document by hand because uploading the real one feels wrong. Half an hour gone before the AI has even started.
The quiet rule-break. Pasting the real thing and hoping it's fine. It's the fastest option — and the one that can cost you a client, or a licence.
The blanket ban. The firm forbids AI entirely, and the productivity gain everyone else is getting goes to your competitors instead.
The duty of confidentiality isn't unique to tax. If your clients trust you with their private affairs, this is built for you too.
Plain answers, no fine print surprises.
On supported client paths, the client attempts to replace personal data it detects before sending. Detection is best-effort and can miss content, so unmatched details may reach the AI provider you selected. Review what your client shows before sending; see Terms of Service §7b.
A client may use a local mapping for values it detected to try to restore stand-ins in a response. Detection and restoration may be incomplete, so review the result before relying on it.
When issued, a receipt records the claims in its envelope and can be independently verified. It does not prove that every personal-data value was found or that every request produced a receipt.
File handling varies by client and type, and not every client shows prepared file content before sending. Detection may miss personal data. Review what your client displays; see Terms of Service §7b. If your client offers a “send unchanged” option and you select it, the original file bytes go to your chosen provider.
The on-device detector checks names and supported formats for identification numbers, including national insurance numbers, TINs, account numbers and company registrations. Detection is best-effort and may miss format variations; review content before sending. See Terms of Service §7b, Known limitations. When CloakAPI issues a receipt, its signed envelope records the claims it contains. It does not establish that every Gateway interaction produced one.
Create an account to use the browser chat. Before sending, review the content your client displays; detection is best-effort and may miss details. File handling varies by client and type. If a client offers “send unchanged” and you select it, the original bytes go to your chosen provider. See Terms of Service §7b. The browser add-on is available from your account page; an IT team can handle setup for internal systems if needed.
Free to start, no card required. Drop a document, ask your question, and see the answer come back with the names where they belong.
Questions first? Write to hello@cloakapi.io — a human answers.