RUNS IN YOUR BROWSER · ZERO SERVERS · OPEN SOURCE PLANNED

Paste freely.
Leak nothing.

Hushpaste strips API keys, customer data and other secrets from your prompt inside the browser, before it reaches any AI chat. When the answer comes back, your real values slide back in.

No spam, one email at launch. Or try the free tool now →

YOU PASTE
DB_HOST=10.24.3.17
STRIPE_KEY=sk-live-4f9a8c1d2e7b3a60
Refund for anna.keller@acme-bank.com
THE AI RECEIVES
DB_HOST=[IP_ADDRESS_1]
STRIPE_KEY=[API_KEY_1]
Refund for [EMAIL_1]
Built for the AI chats you already useChatGPTClaudeGeminiCopilot

Your team is already pasting this into AI.

LOGS AND STACK TRACES

Tokens, internal hostnames and user IDs ride along inside every error dump.

CUSTOMER EMAILS AND TICKETS

Names, phone numbers and IBANs get pasted into "just rewrite this politely".

CONFIGS AND CODE

One .env file or connection string, one paste, one incident report.

Banning AI doesn't work. Blind trust doesn't either. Mask first, then send.

FREE WEB TOOL · NOTHING IS UPLOADED

Mask it. Send it. Restore it.

Everything runs in this page. Paste your text, copy the masked version into any AI chat, then paste the answer back to swap the real values in again. The sample uses fake values only.

Always detected: API keys, AWS keys, GitHub tokens, bearer tokens, emails, IBANs, phone numbers, IP addresses.

1. Mask your text

MASKED · 0 items

2. Restore the AI's answer

Paste the reply you got back. Every placeholder from step 1 is swapped for the real value.

RESTORED · 0 values restored

Three steps, one click, no workflow change.

01

Paste or type as usual

Hushpaste watches the prompt box in your browser. Nothing to copy into another tool.

02

Sensitive values become placeholders

Keys, emails, IBANs, phones and names are swapped locally for tokens like [EMAIL_1].

03

The answer comes back whole

Placeholders in the reply are swapped back to your real values, in memory, in that tab only.

The browser extension that does this automatically is in development. The web tool above works today.

SECURITY MODEL

Nothing to steal, because nothing leaves.

  • Detection and replacement run in your browser. This page sends your text nowhere.
  • The placeholder map lives in the open tab and is gone when you close it.
  • No accounts, no cookies, no tracking of what you paste.
  • The detection core is planned to be open source so it can be audited.
1 · Your text, real values
↓ masked inside your browser
2 · Hushpaste, running locally
↓ placeholders only
3 · The AI chat
Hushpaste servers: not in the path

For people who can't afford one bad paste.

Developers and DevOpsLegalFinance and bankingCustomer supportHR and recruiting

FREE WITH SIGNUP

The AI Paste Safety Kit

Everything you need to stop leaks this week, before the extension ships.

  • Checklist: 20 types of data you should never paste into AI
  • Ready-to-import regex rules for secrets (.json)
  • One-page AI usage policy template for your team
Send me the kit

Simple pricing.

Planned early-access pricing, subject to change at launch.

FREE

$0

Web tool for occasional use

  • Paste-and-mask web tool
  • Built-in detection rules
  • AI Paste Safety Kit

PRO

$8 / month

For individuals who use AI daily

  • Browser extension, auto-mask on send
  • Restore real values in replies
  • Custom rules and allowlists

TEAM

$6 / user / month

For companies that want AI with guardrails

  • Everything in Pro
  • Shared policies and admin rules
  • Reports that never contain content

Questions, answered straight.

Can you see my data?

No. Detection and replacement run in your browser. There is no Hushpaste server in the data path, and the placeholder map is held in the open tab only.

Which sites will it support?

Launch targets are the major AI chats, including ChatGPT, Claude and Gemini. Waitlist members help decide what comes next.

How accurate is detection?

Values with a known format, such as keys, tokens, IBANs and emails, are caught by pattern matching. Names and organizations are not detected automatically yet, so add them in the "extra words" box and review the result before sending.

What if the AI rewrites a placeholder?

Restoration matches placeholders exactly. If a reply changes one, it stays as it is and is not guessed.

Is it open source?

The detection core is planned to be, so anyone can audit exactly what runs in your browser.

Get early access.

Join the waitlist and be first to get the browser extension and the free Safety Kit.