The engine detects; you decide. The analysis panel is your review station: nothing leaves without your approval.

Reading the analysis panel

After Analyze, each detection shows up as a chip, and your text is highlighted:

  • Dotted underline: automatic detection by the local engine (“auto” badge).
  • Solid underline: dictionary entry or structured pattern (email, phone, amount). Deterministic.

The pseudonymized preview shows the exact text that would be submitted to the model, tokens included. That preview is what you approve.

Dismissing a detection

Every chip has an ×:

  • On an automatic detection, dismissal acts immediately: the analysis is redone and the term leaves the masking (it would go out in the clear, an assumed and logged choice).
  • On a dictionary entry or a structured pattern, an extra confirmation is required: removing a deterministic mask is a more consequential gesture.

In every case, the panel shows the result of a real, full re-analysis, never a local patch-up: what you see is always exactly what would be sent.

Catching a missed term

The engine is deliberately cautious on some types (places, notably), and an unusual name can slip past it. Catching it takes three seconds:

  1. Select the term in your text.
  2. Right-click, then choose its type (person, organization, place, project, and so on).
  3. The term enters the vault dictionary, re-analysis happens on its own, and the underline turns solid.

From then on, that term is masked for life in this vault: deterministic, never a probability again.

If you edit the text

The send button greys out and a banner asks you to re-analyze. The app compares the text down to its hash: the approved preview and the sent text cannot diverge, not even by one letter.

Every gesture leaves a trace

Analyses, dismissals and dictionary additions are logged in the vault’s audit log, with counts by type, never the values themselves.