AI UX PlaygroundNewsletterJoin 2K+ AI designers and PMs on Substack. New teardowns, patterns, and prompts as they drop.

Trust

Privacy Filters

Detect and mask personally identifiable or sensitive data in prompts, retrieved context, or outputs. Show that protection ran, not only a silent redact.

Interactive demo

User Input
My email is alex@test.com
Sent to LLM
My email is REDACTED

Overview

How might we design privacy filters so people can trust and act on AI output?

When to use

  • Essential for enterprise applications, healthcare systems, and platforms handling sensitive data where automatic PII detection and masking protects user privacy.

When to skip

  • Creative tools where users intentionally paste private drafts and need full fidelity.
  • Admin audit views that are already access-controlled and must show raw values.
  • Offline local models with no outbound risk and no compliance requirement to mask.

Rules

  • Silent dropping of PII with no indication anything was removed.

  • Masking that breaks copy/paste for roles that are allowed to see the value.

  • False confidence: labeling content safe when detection coverage is partial.

  • Blurring screenshots in marketing while leaving the same PII in exportable text.

Evidence

ProductImplementation
GleanEnterprise search controls that respect ACL and sensitive fields.
Healthcare AI toolsPHI masking in transcripts and generated notes.
Financial platformsAccount and card redaction in AI summaries and support views.
Enterprise chatbotsPrompt and response filters for emails, phones, and IDs.

FAQ

What are privacy filters in AI UX?

Privacy filters detect sensitive data (names, emails, IDs, secrets) and mask or redact it in the UI, often with a control for privileged users to reveal values.

Should masking happen on input, output, or both?

Both when risk is high. Mask before retrieval or logging on the way in, and again on generated text on the way out.

How do users know filtering ran?

Show a clear redacted chip or placeholder, plus a short note like “2 fields hidden.” Invisible filtering erodes trust when something looks missing.

How does this relate to data ownership?

Data ownership covers retention and deletion rights. Privacy filters are the real-time display and processing control for sensitive fields.