Your file never
reaches a server.

Data Alias reads, scans, and rewrites your file inside the browser tab you already have open. Detection, pseudonymization, and export all run there, so its contents, its name, and its values are never transmitted to a server. You can confirm that yourself in about a minute.

Processing runs in your tab

Parsing, detection, and pseudonymization all run in JavaScript inside the browser tab you have open. The flow has no upload step.

The server has no endpoint for file data

There is nowhere to send a cell value, a column name, a filename, or an alias mapping — not to Data Alias, and not to a third-party CDN.

Nothing to train on

Data Alias never receives your file, so it cannot be used to train, fine-tune, or evaluate any model — ours or anyone else's.

Storage is local and opt-in

Files live in tab memory and are gone on refresh. Rule presets and the alias vault are written only when you ask for them, and only to this browser.

The vault is encrypted before it is stored

Your passphrase derives a key with PBKDF2, and the mappings are sealed with AES-GCM on your machine. The passphrase itself is never stored and never sent.

You approve every rule before export

Each detected column and the rule applied to it are shown before the safe copy is created. Nothing is transformed until you say so.

There is no
upload path

Data Alias has no server-side route that accepts a file. Reading, detection, transformation, and export all happen in the tab you have open, so there is no background sync to disable and no analytics on file content to opt out of.

Detection runs against local pattern rules and an optional on-device model. The optional vault is encrypted with a key derived on your machine. Every export passes through a review step, because no automated detector is complete — you make the final call on what leaves the tab.

Verify it yourself

Start with a file
you would not upload.

Protect a file