Notes on offline privacy
Why we build the way we do, what the research actually says, and how we measure ourselves, plainly.
The 18 HIPAA Identifiers and Safe Harbor
Safe Harbor is a list of eighteen things to remove, and three of them are partial rather than deletions: dates keep the year, ages over 89 collapse into one bucket, and the three-digit postal prefix survives only where the area is large enough. Here is the full list, the other route, and an honest account of which identifiers Omit finds.
Read the postEarlier posts
- 31 Aug 202610 min read
What Is PII? Definition, Examples, PII vs PHI
PII means information that identifies a person, but four different laws draw that line in four different places, and the same email address can be in scope under one and arguable under another. Here is each definition, what counts as an example of each, and where PII ends and PHI begins.
- 29 Aug 20268 min read
How to Unredact a PDF, and How to Prevent It
Most recovered redactions come back the same trivial way, because a black rectangle is a drawing and the text is still underneath it. Here is why it happens, how to tell which kind you are holding, and what actually removes a value.
- 26 Aug 20266 min read
What Does Redacted Mean?
Redacted means information was deliberately removed from a document before it was released, usually shown as a black bar. Here is where the word comes from, why documents get redacted, how it differs from censorship, and whether the hidden text can be recovered.
- 24 Aug 20265 min read
Is ChatGPT Confidential?
It depends which ChatGPT, and the honest answer for every tier is the same: confidentiality there is a contractual promise, not an architectural guarantee. A 2025 court order proved the difference in the most concrete way available.
- 23 Aug 20266 min read
Redaction vs Anonymization vs Pseudonymization
Four words that get used interchangeably and mean four different things, with four different legal consequences. Here is what each one actually does to your data, which regulation defines it, and which one your tool is really performing.
- 23 Aug 20266 min read
How to Redact a Word Document
Highlighting text in black is not redaction, and neither is deleting it with track changes on. Omit removes the value from the file itself, across headers, footers, comments, footnotes, tracked deletions and document properties, entirely offline.
- 23 Aug 20266 min read
How to Redact a Court Filing Under Rule 5.2
Federal Rule 5.2 names four categories of personal identifier and tells you exactly how much of each may remain. Only one of the four is plain deletion, which is why blacking everything out is not compliance. Here is the rule, the four treatments, and where filings actually fail.
- 23 Aug 20266 min read
ABA Opinion 512 and the Law Firm AI Policy
Formal Opinion 512 does not ban generative AI for lawyers. It requires informed consent before client information goes into a self-learning tool, which turns a firm AI policy into a question about what leaves the machine. Here is what the opinion asks and how a policy answers it.
- 17 Aug 20263 min read
How to Redact PII From CSV, Excel, and JSON
Omit redacts PII inside structured data files, not just documents: CSV and Excel rewrite the cell, JSON rewrites the value in place, and in every case the file's shape survives. Here is exactly what changes and what does not, format by format.
- 17 Aug 20262 min read
How to Redact PII From Images
Omit redacts PII inside PNG, JPEG, TIFF and BMP files the same way it redacts documents: OCR reads the text, the same detector finds the PII, and the matching regions get blacked out in the image itself, entirely on your machine.
- 17 Aug 20262 min read
How to Permanently Redact a PDF
Most PDF redaction draws a black rectangle over text that is still sitting underneath it, recoverable with a copy-paste. Omit removes the text itself, checks the result before writing the file, and runs entirely offline, no Adobe required.
- 14 Aug 20265 min read
What languages Omit actually works in
Three different answers, because the interface, the name detection and the ID detection each cover a different set. Five interface languages, seven detection languages, and structured detectors that work in any language at all.
- 14 Aug 20265 min read
Omit vs Google Cloud DLP: The Accuracy Tier
Google Cloud DLP scored on ordinary prose, not just structured identifiers. Our combined tiers now beat or match it on 12 of 14 comparable entity types, and the full entity-by-entity data is linked below.
- 13 Aug 20264 min read
Omit vs Google Cloud DLP: The Fast Tier
Google Cloud DLP recognises 213 kinds of sensitive text. Our free-with-every-install Fast tier recognises 191 of them on your own machine, with nothing uploaded, and matches or beats Google on every comparable type. Here is the measurement, including where we are weaker.
- 6 Aug 20267 min read
Omit Redact beta: what actually shipped
Release notes for the Omit Redact 1.0.0 beta, including the two installers and their real measured sizes, what the 15 day trial covers, and the plain fact that the build is not code signed yet.
- 30 Jul 20268 min read
Why we built Protect
The leak happens at the paste, which is the last moment the data is still yours. Four documented incidents show what happens after that moment, and why we made the clipboard guard free for everyone.
- 23 Jul 20266 min read
Why we built Omit
Before Omit we worked on Telos, an app people fill with the most private things about themselves. Making it useful meant sending some of that to a language model, and nothing would strip the personal details out first without uploading them somewhere. So we built that step.
New posts, no noise
One email when we publish something worth your time. No newsletter, no tracking.