Redact client data before you use a generative AI tool
The confidentiality duty in Model Rule 1.6 covers all information relating to the representation, whatever its source — not just privileged material. That is a wider net than most redaction tools assume, and it is why this preset leans towards over-detection: names, companies, addresses, matter and case references, financial identifiers and dates of birth.
Scrubbing is not a substitute for the analysis your jurisdiction requires. It is the practical step that makes the analysis survivable: a prompt containing [NAME_1] and [COMPANY_2] is a different risk proposition from one containing your client.
Your text
Safe to paste
Preset: names, companies, matter and account references, addresses, financial identifiers.
Mapping — 0 values (only visible in this tab)
| Placeholder | Real value | Uses |
|---|
Check a few rows before you paste — this is the fastest way to spot a detector that grabbed the wrong thing. Nothing here is stored or sent anywhere.
What to look for — 30 detectors, custom terms, exceptions
People & organisations
Government & health IDs
Financial
Technical & secrets
Location
Step 3 — paste the AI’s answer here to put the real values back
The model replies using the placeholders. Paste its answer below and every
[NAME_1] becomes the real name again — using the mapping held in this tab, which
is the only copy that exists.
How it works
- Open this page — the detectors are already set for “For lawyers”.
- Paste your text, or drop a .txt, .md, .csv, .json or .log file onto the panel.
- Check the highlights: every match is coloured by type, and one click keeps a type as-is.
- Copy the safe version and paste it into the AI tool of your choice.
- Paste the model’s reply back into step 3 to restore the real values.
What ABA Formal Opinion 512 asks of you
The ABA’s first ethics opinion on generative AI, Formal Opinion 512 (29 July 2024), sets out the obligations that apply when a lawyer uses these tools: competence, confidentiality, communication with the client, supervision, and reasonable fees. On confidentiality it is specific — before inputting information relating to the representation into a self-learning tool, a lawyer must obtain the client’s informed consent, and boilerplate in an engagement letter is not informed consent. The lawyer is also expected to understand how the tool uses data, which means reading the terms rather than assuming.
Removing client-identifying details before the prompt changes the question you are answering. Research on an abstracted fact pattern is a different act from disclosing information relating to a representation, and it is the route most firms end up taking for public tools.
Redaction is not the whole of the duty
A fact pattern can identify a client without a single name in it. A matter with an unusual procedural history, a widely reported transaction, or a party described by its market position may be recognisable to anyone who follows that sector — including a model that has read the same news coverage. The scrub is the floor, not the ceiling.
Two other duties survive the scrub entirely: verification and candour. Opinion 512 is direct that outputs must be checked, and courts have sanctioned lawyers for citations that did not exist. A scrubbed prompt does not make an unverified citation safe to file.
Tips
- Put the matter name, codename and any distinctive deal term in custom terms — those are usually more identifying than the party names.
- Keep the key file out of the client folder unless your retention policy says otherwise; it is the document that reverses the redaction.
- Check your state bar’s guidance as well as ABA 512 — several have issued their own opinions with stricter consent expectations.
Detectors are pattern-based and imperfect: read the highlighted output before you paste it anywhere, and confirm your own confidentiality obligations against the current rules for your profession, employer or jurisdiction. Compiled 2026-07-29.
Frequently asked questions
Does scrubbing remove the need for client consent?
Not automatically. Opinion 512 ties consent to inputting information relating to the representation into a self-learning tool. Whether an abstracted, de-identified fact pattern still counts is a judgement call — one that depends on how recognisable the facts are and on the tool’s terms. Document the reasoning rather than assuming either answer.
Is a chatbot conversation discoverable?
Treat it as potentially retained and potentially producible. In the New York Times litigation, OpenAI was ordered to preserve consumer output logs including deleted chats; that specific obligation ended on 26 September 2025, but logs preserved under it still exist. Assume durability, not deletion.
Is this tool covered by any privilege?
No third party is involved at all, which is the point: the text never leaves your device, so there is no disclosure to a vendor to analyse. That is an architectural fact you can verify with your browser’s network tab, not a promise in a policy.