Skip to content
Free foreverBETA

The leak starts at copy and paste. Protect stops it there.

Protect takes personal data out of what you copy, on your own machine, before it can reach an AI tool or anywhere else. It never connects to the internet to do it, because it has nothing to send.

Protect is part of Omit Redact and it is free for everyone, permanently. No account, no key, no expiry.

What you copied

Summarize this: Robin Meier on 0176 4419 2288, invoice DE44 5001 0130 0000

What the chatbot receives

Summarize this: [PERSON] on [PHONE], invoice [IBAN]

Redacted 3 items of personal data from your clipboard.

Ctrl+Alt+V pastes the original

The paste path

Three stages between a copy and a leak. Protect stands in exactly one of them.

People move text into ChatGPT, Claude, Copilot and Gemini all day, because it is the fastest way to get the work done. The instant they paste, that text is on somebody else's machine, inside a system nobody at your end can audit or recall.

This is not a hypothetical failure mode

Four incidents, each reported by a named outlet, each linked below so you can check us rather than take our word. The count is not the point. What the four have in common is what matters.

1

Your clipboard

Protect stands here

Three moments, all of them on your machine.

  1. 01You copy something. Protect reads the clipboard locally and runs the same detection engine that Omit Redact uses on files. Nothing is uploaded, queued or logged to a server, because there is no server.
  2. 02Personal data comes out before you paste. Names, phone numbers, emails, account numbers and national IDs are replaced with labels. Then it tells you what it did, in a line at the edge of the screen, rather than changing your clipboard behind your back.
  3. 03The original is one keystroke away. When you genuinely need the raw value, Ctrl+Alt+V pastes it. That is a deliberate exception you make, not a default you have to remember to avoid.
2

The app you paste into

The browser is not a trustworthy place to put the guard

Both of these reached people through the same channel a browser-based guard would use. One of them sold itself as the guard.

Exhibit A

Shipped July 2025, disclosed December 2025

A VPN extension silently added AI chat interception

Koi Security found that Urban VPN Proxy version 5.5.0, shipped on 9 July 2025 as a silent auto update, began intercepting conversations with eight AI platforms: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok and Meta AI. It captured the prompts and the responses. Seven sibling extensions from the same publisher carried identical code, more than 8 million users between them, over 6 million on Chrome and 1.3 million on Edge. The data went to BiScience, a data broker.

"protect[s] people from entering personal information into AI chatbots"
What the Chrome Web Store listing claimed the product did

Exhibit B

Disclosed 6 January 2026

Two AI sidebar extensions exfiltrated chats

OX Security found two Chrome extensions harvesting ChatGPT and DeepSeek conversations plus every Chrome tab URL, transmitting to attacker servers every 30 minutes. "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" had 600,000 users and carried Google's "Featured" badge. "AI Sidebar with Deepseek, ChatGPT, Claude, and more" had 300,000. More than 900,000 users between them.

The Urban VPN one is the sharpest thing on this page. Software that advertised itself as protecting people from entering personal information into AI chatbots was, by silent auto update, collecting exactly that and sending it to a data broker. A guard that runs in the cloud, or inside the browser, asks you to trust a channel that has already failed this way, and to keep trusting it through every update you will not read. Protect runs on your own machine, ships no network code and transmits nothing. It has nothing to betray.

3

Everywhere after that

It happens where corporate tooling cannot reach. Pasting happens wherever the person is: a personal account, a personal login, a browser tab nobody administers. Enterprise data-loss tooling watches managed systems and sanctioned services, so a paste made outside them is one it can never see. A tool that runs on the desktop, offline, is the only thing that lives where the leak actually happens.

Shared conversations turned up in ordinary search results

Two vendors, a year apart. That makes it a pattern in how these products work, not one company's slip.

Exhibit C

July to August 2025

Google indexed shared ChatGPT conversations

Fast Company found roughly 4,500 shared ChatGPT conversations reachable through a Google site search. The exposed chats included people discussing addiction, physical abuse and suicidal ideation. The cause was an opt-in "Make this chat discoverable" checkbox in ChatGPT's share dialog. OpenAI's chief information security officer, Dane Stuckey, announced its removal on 1 August 2025, calling it a feature that "introduced too many opportunities for folks to accidentally share things they didn't intend to".

Exhibit D

July 2026

Google indexed shared Claude conversations and Artifacts

A Reddit user flagged on 26 July 2026, and 404 Media reported, that the query site:claude.ai/share surfaced shared conversations and Artifacts. Reported exposures included a detailed medical report on a real patient, clinical trial results containing patient names, documents listing names and phone numbers of primary school aged children, company documents marked internal use only, and employee reviews containing personal information about workers. Results stopped appearing by that Monday afternoon. Forbes reported a similar incident the previous year involving roughly 600 conversations.

"These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible."
Anthropic's response: the system worked as intended

Critics noted that Google Docs links do not become searchable. The difference is a search engine instruction Anthropic chose not to send.

Different companies, different years, the same shape. Text people had pasted into a chat travelled further than they expected, through a feature working the way it was built. Anthropic's answer is a reasonable one and the criticism of it is also reasonable, and neither changes the position you are left in. Once the paste has happened, where that text can go stops being your decision.

What this does not prove

That Protect catches everything. It does not. Protect reduces what leaves in a paste, and a paste is one route out of many: it does not see a file you upload, a screenshot you take, or a sentence you type by hand. Detection in free text is statistical and it can miss. What these four incidents argue for is narrower than a guarantee. They argue for putting the guard on the machine you control, rather than in a channel somebody else can change while you sleep.

Every claim above is stated the way its source states it. Where a company has given its side, that is quoted too.

What makes this one different

Offline clipboard tools exist. These are the things Protect has that a regex script or a browser extension does not.

  • Detection that holds up

    The same engine that redacts PDFs, spreadsheets and scanned images, with recognizer packs for every region Omit supports. Not a pattern list, and not a small model asked to guess.

  • It works past the browser

    An extension guards a tab. Protect sits at the Windows clipboard, so it also covers the ChatGPT and Claude desktop apps, Copilot inside Office, assistants in your IDE, and Slack.

  • Nothing to send anywhere

    No analytics endpoint, no crash reporting, no update check. The offline installer carries every model it needs, so a machine that has never been online runs it unchanged.

  • Reversible, if you want it

    Protect can store what it removed in Omit Redact's encrypted vault, so a redacted paste can be restored later through the panel that already exists. That part is a paid feature, and it is off unless you turn it on.

How you get it

There is no separate Protect download and nothing to buy. Three steps, and you never have to reach for a card.

  1. 01

    Light installer

    Install Omit Redact

    Protect arrives inside it. The light installer is the small one, 167 MB, and it is everything Protect needs.

  2. 02

    Free forever

    Turn Protect on

    It works immediately, free, permanently. No key, no account, no expiry, and nothing to activate. A fresh install ships switched off, so turning it on is your decision.

  3. 03

    Optional

    Start the trial only if you want the rest

    File redaction across PDF, CSV, Excel and images, the reversible vault, and the Accuracy detection tier run on a 15-day trial you start from inside the app. Protect keeps working either way.

Download Omit Redact

Free means free

Protect is the free part of Omit Redact and it stays free. There is no trial clock on it, no seat count, and nothing to activate.

Protect

Free

Free, permanently

The clipboard guard, for everyone.

  • Redacts personal data from anything you copy
  • Works in every application on the desktop
  • The same recognizer set as the paid product, on the Fast model tier
  • No account and no licence key

The rest of Omit Redact

15-day trial, then one key

Files, the vault, and the Accuracy model.

  • PDF, CSV, Excel, email, text and scanned images with OCR
  • The reversible vault, including for clipboard redactions
  • The Accuracy detection tier
  • A perpetual key, bought once, verified on-device
See pricing

What it does, and what it will not do

Protect asks for the three permissions that look worst on paper: it reads the clipboard, it can read text in other applications, and it starts with Windows. Here is exactly how that is handled.

What it does

  • A fresh install is inert

    Protect ships switched off. Until you turn it on there is no login task, no clipboard hook and no reading of other applications. Turning it on is the one deliberate act that arms all three, and turning it off releases them again.

  • It narrates every redaction

    Software that watches your clipboard and says nothing is indistinguishable from software that watches your clipboard and sends it somewhere. Every time Protect changes what you copied, it says so and tells you how to get the original back.

What it will not do

  • This build is not signed

    The beta carries no code-signing certificate, so Windows SmartScreen warns about it. We would rather say that on the page than let you find it in a dialog. A certificate is on the list for the stable release.

  • It is not enterprise DLP

    There is no central console, no fleet reporting and no discovery across your data stores. Protect covers the desktop it runs on. Teams that need organisation-wide monitoring run a DLP platform as well, not instead.

  • Detection is statistical, so it can miss

    No detector catches everything in free text. Protect fails closed where it can and shows you what it found, and it is a strong reduction in exposure rather than a guarantee of zero. Anyone who promises you the guarantee is selling something.

Questions about Protect

Is Protect really free, or free for now?

Free permanently. It is the free tier of Omit Redact rather than a promotion, and it needs no licence key at all. The paid part of the product is files, the vault and the Accuracy model, which is a different set of features from the clipboard guard.

Do I need to be online for it to work?

No, and it will not go online. The offline installer bundles every model Protect uses. There is no analytics endpoint, no update check and no activation call, so a machine with the cable pulled out behaves identically to one without.

Does it slow down ordinary copy and paste?

A copy is scanned locally before you paste it, which takes a moment on text and nothing you would notice on the sort of snippet people paste into a chatbot. Copies with no personal data in them are handed straight back untouched.

What if I need to paste the real value?

Press Ctrl+Alt+V. That pastes the original, deliberately, and Protect records that you did rather than quietly allowing it.

Which applications does it cover?

Any Windows application that takes a paste, because it works at the clipboard rather than through per-application integrations. That includes the desktop AI apps, Copilot in Office, IDE assistants and chat tools, not just a browser tab.

Does it start automatically?

Only if you enable Protect, and then yes, deliberately. Protection that does not survive a reboot is protection that has silently stopped, so the switch that turns Protect on is the same switch that asks Windows to start it. Turning Protect off gives the login task back.

Where does the original text go?

By default it is held as a single entry in memory and cleared by your next copy, so it never touches the disk. You can instead ask Protect to keep clipboard originals in the encrypted vault, which makes them restorable later. That mode is a paid feature and it is off until you choose it.

Is this the same detection Omit Redact uses on files?

Yes, the same engine and the same recognizer set. The one difference is the model tier: Protect runs Fast, and the heavier Accuracy tier comes with the paid product.

Stop the paste, not the work

Protect installs with Omit Redact and costs nothing. Turn it on when you are ready, and leave it off until then.