Privacy and redaction

Turn on redaction to hide personal details and credentials in prompts and responses, and see what each device leaves out.

Prompts and responses can contain personal details or credentials. Tokenize gives you two layers of control: a dashboard setting that redacts sensitive information for your whole organization, and device settings that decide what each computer sends in the first place.

Who can do this: Admins.

Turn on redaction

  1. Go to Settings → Privacy.
  2. Turn on Hide personal and sensitive information. The switch shows On.
  3. Check the Preview. It shows example sessions with redaction on or off, for example an API key replaced with <API_KEY> and a phone number replaced with <PHONE_NUMBER>.
  4. Click Confirm privacy settings.

The setting is off until an admin turns it on. You may also see it as a step when you first set up your workspace.

What redaction does

When redaction is on, Tokenize replaces personal details and credentials in new prompts and responses before they appear in the dashboard. Each value is replaced with a label for its type, such as <PHONE_NUMBER> or <API_KEY>. Redaction covers common credentials and most kinds of personal information. Email addresses and place names are not redacted.

Keep these points in mind:

  • It applies to new data only. Prompts and responses already in Tokenize do not change when you turn it on or off.
  • Some records may be left out. If Tokenize cannot safely remove sensitive information from a record, it leaves that record out of the dashboard rather than show it unredacted.
  • It can reduce the quality of insights. When hidden details provide useful context, session titles, summaries, and suggestions built from redacted text can be less specific.
  • It covers what the dashboard shows. Redaction doesn't change what devices send. To limit that, see What devices leave out below. For how Tokenize stores and protects data, see the Data Processing Addendum and Privacy Policy. To have your data removed, see Delete your data.

Cost, token, and usage numbers are not affected.

What devices leave out

The Tokenize desktop app limits what leaves each computer, whether or not redaction is on:

  • MCP server settings. When the app reports which MCP servers are installed, it sends environment variable and header names only, never their values. It sends the number of command arguments, not the arguments, and only the scheme and host of server URLs.
  • AI tool sign-in credentials. The app uses Claude Code's sign-in to fetch your Claude Code cloud sessions from Anthropic. It does not save that credential with the data it sends.
  • Cursor lifecycle events. The events Tokenize records from Cursor's hooks never include prompt or response text, attachments, or workspace paths.

To stop a device from sending prompt text at all, turn off prompt text in its managed preferences. See What data Tokenize collects.

Troubleshooting

  • "Your role does not include privacy management." Ask an admin to change this setting.
  • "Privacy controls are not available from the current API version yet." Try again later, or contact your Tokenize account team.