SHARE THE DATA.
NOT THE PERSON.
Scan for personal data, secrets and combinations that could identify someone before a spreadsheet leaves your hands. Choose where the copy is going, preview every change, then export a safer version — without uploading the raw rows.
MAKE A SAFE COPY.
KEEP THE ORIGINAL.
Tell the tool where the copy is going. A public sample needs a stricter check than an internal QA file. Detection, transformation and preview all stay in your browser.
Drop in CSV or Excel
CSV, XLSX, XLS or ODS. The accepted worksheet is scanned locally across all non-empty cells. Up to 100,000 rows, 250 fields and 5 million cells; larger sheets are rejected rather than sampled or truncated. No raw rows are uploaded and no AI model receives the data.
READY FOR SELECTED USE
No blocking identifiers remain.
Transformation record
SEE EVERY CHANGE
BEFORE YOU EXPORT.
The useful part is not merely replacing email addresses. It is understanding what still makes a person identifiable after the obvious fields are gone.
Scan the evidence
Column names and value patterns across the accepted worksheet identify likely direct identifiers, system IDs, sensitive attributes, quasi-identifiers, payment details and credential-like secrets.
Choose the privacy boundary
Mask, drop, generalise, synthesise or use stable pseudonyms where joins need to survive. The recommended default changes with the destination.
Run the share check
Before export, the tool checks what remains — including risky combinations of quasi-identifiers that can still single somebody out.
BEFORE YOU SHARE.
A masked spreadsheet is not automatically anonymous. These are the boundaries the tool keeps explicit.
Does my file leave the browser?
No. File parsing, detection, transformation, hashing, preview and export all happen locally in the browser. This tool intentionally does not send the rows to Luna or another AI model.
Does a stable hash make personal data anonymous?
Not necessarily. A stable hash or token preserves linkability and can remain personal data or pseudonymous data depending on the context. The tool labels those actions as pseudonymisation and applies a stricter rule for public sharing.
Can the scanner find every kind of PII?
No. It detects common identifiers from column names and recognisable value patterns, but free-text context, unusual identifiers and combinations of innocuous-looking fields can still carry privacy risk. Always review the output before disclosure.
Why does public sample mode block more fields?
Public disclosure has a different risk profile from controlled internal use. Public mode therefore rejects retained direct identifiers, secrets and stable pseudonyms, and is stricter about combinations of quasi-identifiers.