How to anonymise a document for ChatGPT (and keep it useful)

The short answer. Never upload a raw confidential document to ChatGPT. Replace the sensitive values first: names, companies, amounts, account numbers and addresses become consistent placeholders. You can do this manually, but it is slow and error-prone. With ShareSafe.ai you drop the file in the tool, review what was detected and download a safe version in under a minute. Choose pseudonymise if you want to translate the AI's answer back to the real names later. You hold the key for that.

Make your document safe now, no account needed

When is this risky?

ChatGPT is genuinely good at document work, which is exactly why real client material keeps ending up in it. Four situations that happen every day:

  1. An advisor uploads a client's annual figures for a summary. The client's name, revenue and margins are now outside his control.
  2. A recruiter pastes a CV to generate interview questions. Address, date of birth and ID-like numbers travel along.
  3. A consultant has a draft contract rewritten. Parties, amounts and penalty clauses sit in the prompt.
  4. An HR consultant summarises interview notes. Employee names and health details go with them.

The problem is not that OpenAI does something malicious. The problem is that you can no longer demonstrate what happens to that data, and you have to be able to explain it to your client. "No training on business data" is not the same as "nothing sensitive was sent".

What to shield

It varies per document type, but this is the core list:

CategoryExamples
Peoplenames, job titles in small teams, signatures
Organisationsclient names, suppliers, subsidiaries
Financialamounts, IBANs, VAT and registration numbers, rates
Contactaddresses, email addresses, phone numbers
Identifiersnational ID numbers, employee numbers, case numbers, licence plates
Contextdates and places that identify someone in combination

That last category is missed most often. "The CFO of a family business in a small Dutch town" is not a name, but it identifies a person.

Three steps

  1. Drop your file into ShareSafe.ai. PDF, Word, Excel or text, up to 25 MB. No account. Processing happens in the EU and your document is not kept after the run.
  2. Check the before and after view. You see exactly what was found: Jan de Vries becomes [NAME_01], Acme Corp becomes [ORG_01], €125,000 becomes [AMOUNT_01]. Missing something? Add it before you continue. That review is part of working safely, not a formality.
  3. Download the safe file and your Identity Key. The safe file goes to ChatGPT. When the answer comes back with placeholders, you translate them back to the real names with your Identity Key. You hold that key, we do not.

If you want no way back, choose anonymise instead of pseudonymise. Then there is no key and nobody can restore the link, including us.

FAQ

Is an anonymised document GDPR-proof?
Anonymisation and pseudonymisation reduce the risk sharply, but no automatic detection is infallible. That is why ShareSafe.ai shows what was found and you review before using the file. As long as a key exists, pseudonymised data legally remains personal data processing. You hold that key.
Why not just black bars in the PDF?
Black bars are often a layer on top of the text: the content is still underneath and can be copied out. ChatGPT also loses the document's coherence. Consistent placeholders ([NAME_01] stays [NAME_01] everywhere) keep the document usable for analysis.
Does ShareSafe.ai store my document?
No. Processing happens in memory, within the EU, and after the run we keep no copy of your document, your filename or your key. Every run comes with a processing receipt. See the [security page] for the exact route.
Does this work for Claude, Gemini or Copilot too?
Yes. The safe file is an ordinary file. Which AI you point at it is up to you.
What if I lose the Identity Key?
Then the placeholders in AI answers stay placeholders; nobody can translate them back, including us. Your original on your own machine is untouched.

ShareSafe.ai is part of VaultLM. Raw files stay in the EU. Minimal retention. You hold the key. Try it with your own document →