People & brands
Creators, managers, brand contacts. The same person keeps the same label across every file in the batch, so threads still make sense.
Aarav Mehta → [PERSON_03]
Sensitive data removal · redactor.cohostly.cloud
Chat exports, screenshots, emails and spreadsheets go in. The same files come back with every name, phone number and amount replaced, and the conversation still readable.
09:12 Priya Nair: My order 4471 never arrived. 09:13 Agent: Which number is on the account? 09:14 Priya Nair: +91 98765 43210. I paid ₹2,499.
09:12 [PERSON_01]: My order [NUMBER_01] never arrived. 09:13 Agent: Which number is on the account? 09:14 [PERSON_01]: [PHONE_01]. I paid [AMOUNT_01].
Same person, same label, every file in the batch.
Drag them here, or paste a screenshot with ⌘V. Nothing is uploaded until you press Redact.
ready
The key is derived in your browser and never stored. Your redacted ZIP is encrypted while it waits on the server, so nobody with access to that machine can open it. Lose the passphrase and the file cannot be recovered.
Uploaded over this connection, redacted, then deleted from the server.
download expires in minutes
no matching files
counts only. The values themselves are never shown or stored
nothing detected
job failed
Coverage
Google Cloud DLP handles the standard identifiers. Built-in rules on top of it catch the things a generic detector misses: deal terms, handles, campaign IDs, and loose numbers.
Creators, managers, brand contacts. The same person keeps the same label across every file in the batch, so threads still make sense.
Aarav Mehta → [PERSON_03]
Indian and international formats, including numbers sitting inside a screenshot.
+91 98765 43210 → [PHONE_01]
Amounts, percentages, payment schedules, credit periods and contract values.
50% upfront → [PAYMENT_PERCENTAGE]
Timestamps, dates, follower counts, IDs. If it reads as a number, it goes.
22:47 → [NUMBER]:[NUMBER]
Email addresses, URLs, IP addresses, @handles and campaign IDs.
@aaravbuilds → [HANDLE_01]
Text inside images is read with OCR and covered with a black box. Only the matches, not the whole bubble.
chat screenshot → black bars
| Chats | .txt · .json · .csv · .md |
|---|---|
| .eml, including attachments | |
| Images | .png · .jpg · .jpeg · .webp |
| Documents | .pdf (text and scanned) · .docx · .xlsx |
| Anything else | copied to _unprocessed/ untouched and listed in the report |
How it works
A ZIP, a handful of files, or an entire folder with its subfolders. Preview anything before it leaves your machine. The batch limit is MB.
Each file is scanned, matches are replaced with labels, and your folder layout is kept exactly as it was. Anything unsupported is set aside rather than dropped.
Open the redacted files in the browser, look at the per-type counts, and download one ZIP. Everything is erased from the server after minutes.
exports/ support-chat.txt invoice-april.pdf screenshot-01.png contacts.csv
Redact
exports/ support-chat.txt 12 replaced invoice-april.pdf 7 replaced screenshot-01.png 5 boxed out contacts.csv 96 replaced
Data handling
Plainly, with no marketing around it.
No generative AI is involved at any step. No LLM, no chatbot, no model that could memorise your text or repeat it to someone else. Detection is regular expressions and word lists from this application's config, plus Google Cloud DLP, a deterministic classifier that returns the position of things it recognises. Nothing you upload is used as training data. The same input always produces the same output.
| Item | Where it lives | How long |
|---|---|---|
| Uploaded file | Temp directory on this server | Deleted the moment the job ends |
| Extracted originals | Temp directory on this server | Deleted the moment the job ends |
| Name → label mapping | Server memory only, never disk | Cleared when the job ends |
| Redacted ZIP | Temp directory, AES-256 encrypted when you set a passphrase | minutes, then deleted automatically |
| Processing report | Inside your ZIP | Yours. Counts per type, never values |
| Accounts | None | n/a |
| Product analytics | Page views and feature usage (PostHog) | Never includes file names or file content |
| Your passphrase | Never sent. The key derived from it lives in server memory for the length of one request | Discarded when the request ends |
| Training data, model fine-tuning | None. No generative model is involved at any step | n/a |
One honest caveat. Detection is automated and not perfect. A nickname in a screenshot header, an unusual spelling, or heavily mixed-language text can slip through, and ordinary words occasionally get masked by mistake. Read the output before you pass it on.
Hosting
| This site | Operated by Cohostly at . |
|---|---|
| File processing | Runs on Cohostly's own servers. Files are never handed to a storage bucket, queue or CDN. |
| Detection engine | |
| What leaves the server | |
| Front-end assets | Fonts and UI components load from Google Fonts and jsDelivr. They see your browser's request for those files; they never see your data. |
FAQ
[PERSON_01] stay consistent inside a single job so conversations remain coherent, but the table linking them to real values is destroyed when the job ends and is never included in the download. Two separate jobs will not agree on numbering.
redactor.cohostly.cloud is served over HTTPS, so your upload and the redacted ZIP you download are encrypted in transit. The text sent to Google Cloud DLP for detection travels over HTTPS as well.
_unprocessed/ folder inside your download and listed by name and reason in the report, so you can deal with them by hand.
_unprocessed/ folder added at the top level.
preview truncated