Keep your data where it belongs.
Do you have to hand over your data to use AI?
With discode, they stay with you, on your device. Your anonymization assistant detects sensitive data right where you are and suggests replacements. You decide before your question ever leaves your device.
You type a question, and your words land on a server in San Francisco. Or in Beijing. Your blood count. Your colleague's mobile number. Your contract partner's IBAN. You don't even notice. It hits your own data as much as other people's: a doctor types up a case, a lawyer a brief — and names, diagnoses and case numbers end up on someone else's servers. Whoever wants to prevent that redacts by hand today — and still misses something.
Your own data, your own call — whether you take the risk is up to you. But the moment other people’s data enters the picture — company data, or data belonging to your colleagues, employees, clients, or friends — you carry a responsibility that goes beyond yourself.
Those who want to prevent this redact by hand. But you redact a PDF, miss a single spot, and that’s exactly the one that ends up in the answer. One moment of inattention, and the detail that should never have left is out there.
Two layers, one decision per data point
Your anonymization assistant checks every request twice, right on your device: Layer 1 detects 16 data types via fixed patterns — email, phone, IBAN, credit card and more. Layer 2, HEIMDALL, is a small AI model in your browser that recognises names, companies and places — without anything leaving your device for it. Before sending, the PII review shows you every find: yellow gets anonymized (default), grey stays in plain text. Anonymized means replaced with plausible look-alikes — not a blacked-out bar but realistic placeholders, so the answer stays coherent in context. You decide, per data point.
More details
Local AI detection: two layers, one decision per data point. Your anonymization assistant checks every request twice, right on your device, without uploading anything. Layer 1 detects 16 data types via fixed patterns: email, phone, IBAN, credit card and more. Layer 2, HEIMDALL, is a small AI model in your browser that finds names, companies and places. Both work locally; nothing leaves your device. Before sending, the PII review shows you all findings: yellow means the assistant suggests anonymizing (default), grey stays in plain text. You decide, per data point. And “anonymized” doesn’t mean redacted: every finding is replaced with a realistic look-alike, a plausible placeholder, so the answer remains coherent and quality doesn’t suffer.
Vault & Fail-Closed
The model only sees placeholders — you see real data. The mapping lives solely in the request's memory: no log, no cache, no database. After the answer it's discarded. And if anonymization fails? Then nothing is sent. No half measures.
More details
Fail-closed: on a pipeline error the system aborts with an error (503) instead of silently forwarding unanonymized.
Learns as it goes —
and stays with you.
If the assistant misses something and you anonymize it yourself, it remembers that — on this exact device. What it learns stays with you, nowhere else. Switch devices and it starts fresh — not an oversight but the consequence of “your data stays on your device”.
Chinese providers? You decide.
Some of the best models come from Chinese providers — and some data should never end up there. One toggle: “Include Chinese Providers”. Off means off — no model hosted exclusively in China, no matter how well it scores. Off by default; you enable it only when you want to.
Our commitments
No training on your data: Most API tiers don't use your content for training anyway — and because sensitive data is replaced before sending, it never reaches a model that could learn from it. Full control: Your data is viewable and deletable at any time — no forms, no waiting, no justification needed.
The most important limit first: the assistant detects sensitive data and suggests anonymization. The final check before sending stays with you. Unusual formats aren’t always detected automatically. If you mark them yourself, the assistant learns (on-device). Indirect identifiability — where a combination of harmless details reveals someone — isn’t detected. On uploads, local anonymization checks the text, not image content. And whether an answer itself generates new personal data — we don’t check that. A lot of fine print, yes — but we’d rather be honest than promise perfect security that doesn’t exist.
Two more things that follow directly from “local”: if you ask a question on your phone and open the answer on your computer, you’ll see placeholders instead of your real data — because the originals were never on our servers and can’t travel to a second device. Best to finish a request on the device where you started it.

Sven Heimdall
Sven Heimdall is discode’s data bouncer. He stands at the door of your device, spots sensitive data before it leaves, and only lets through what you wave past. Strict at the door, relaxed in tone.
