Can ChatGPT or Copilot anonymize a document for you?
An assistant can swap names for placeholders, but only after reading the raw file. See what it misses, where your document goes, and a safer order.
Yes, an assistant can rewrite a text and swap names for placeholders, but only after you give it the document unmasked. That disclosure is the very thing you wanted to avoid. And it returns new text, not a safe copy of your file, so mask first on your own device.
What goes wrong when you ask an assistant to anonymize?
Three things go wrong, and the first one happens before any anonymizing starts.

- The disclosure comes first. The assistant reads every name, number and address in clear before it hides any of them.
- The output is a rewrite. In a plain chat, the assistant writes new text. It does not paint masks on your pages. A stamp, a signature or a photo in a scan is not covered by a rewrite.
- Misses are invisible. If the assistant skips one name, nothing flags it. You can only find it by reading every line against the original.
Take a reference letter for Jane Example, a nurse at Oak Street Clinic. The assistant swaps her name and bank account number but leaves “the only night nurse at Oak Street Clinic”. That phrase still points to her, and only a careful reader will spot it.
Authorities warn about the output too. In May 2024, the ChatGPT taskforce of the EDPB, the board of the EU data protection authorities, published preliminary views. It wrote that the training approach may produce biased or made up outputs, and that users are likely to take them as accurate. Germany's federal cybersecurity agency, the BSI, says generative models offer no guarantees about the quality of their outputs.
Where does your document go when you use an assistant?
It depends on the tool and the plan. The table uses the vendors' own pages and EU regulators, as of October 2026 unless dated otherwise. These terms change, so check your plan before you upload anything.
| Route | Training on your content | What else to know |
|---|---|---|
| ChatGPT, personal account | OpenAI's Help Center says it may train on your content, after steps to reduce personal information. To opt out, turn off “Improve the model for everyone” in Settings, Data controls. | In May 2024, the EDPB noted that OpenAI counts file uploads as content. |
| ChatGPT Business, Enterprise, Edu and OpenAI API | Not used to train by default, says OpenAI. API customers can opt in to sharing. | API: abuse-monitoring logs are kept up to 30 days by default, and uploaded files stay until you delete them. |
| Microsoft Copilot Chat, work or school account | Not used to train the underlying models, says Microsoft. | Prompts and responses are logged in your organisation's Exchange (Microsoft's mail service), and uploaded files sit in OneDrive for Business. Admins can search them and set how long they are kept. |
| Microsoft Copilot, personal Microsoft account | Updated app and web (from 18 August 2026): prompts, responses and file contents are not used to train underlying models, says Microsoft. | Older app: Microsoft says it trains on signed-in users' conversations and uploaded files unless they opt out. It says it removes identifying details first. History is kept 18 months by default, and some chats get human review with no opt-out. |
| Model on your own computer | Nothing goes to a vendor if it runs only on your machine. | The CNIL says an on-site deployment stops the provider from reusing data. You still run and secure it. |
Copilot Chat can also send short web queries to Bing. Microsoft says they are a few words long and may include terms from an uploaded file, but not the whole file. Bing follows other data rules: Microsoft says it acts there as an independent controller, meaning it alone decides how to use that data.
When is it acceptable to use an assistant on a document?
Three cases can justify it. Each one depends on facts only your organisation knows, so ask your data protection officer, your IT team or a lawyer. Outside the EU, the rule may differ.
- A business plan with a contract that excludes training. Article 28 of the GDPR (EU) requires a written contract, or another legal act, when a vendor processes personal data on your behalf. That contract must say the vendor acts only on your documented instructions. Microsoft says its Copilot offers for organisations fall under its Data Protection Addendum, with Microsoft as processor.
- A company policy that allows this kind of document. The CNIL recommends internal policies or charters that clearly set allowed and forbidden uses. The BSI says employers should tell staff which AI tools they may use and what they may enter.
- A document with no personal or confidential data. The CNIL says never to share confidential information, such as personal data, with a consumer service.
In what order should you use an assistant on a sensitive document?
- Work on a copy. Keep the original.
- Mask the copy on your own device, with a tool that does not upload the file.
- Check the masked copy against the original, page by page. Look for clues such as job titles, places and rare events, because they can still point to someone.
- Only then ask the assistant for help, on the masked copy.
- Read its answer with a critical eye, and compare any rewrite with the original.
ONYRI Sanitize is one way to do step two. It masks a PDF, Word (.docx) file or scan in your browser, without uploading the file. In Token mode (Pro plan), each value becomes a label such as [NAME1], and within a document the same text always gets the same label, so an assistant can follow who did what. A name written two ways gets two labels. The export is flattened into page images, so the assistant reads it as images. Nothing restores the original values: keep your original.
Ask the assistant to find, not to fix. A prompt like this keeps you in control:
Here is a masked document. List any remaining details that could point to a real person, such as job titles, places, dates or rare events. Quote each detail and say where it is. Do not rewrite or correct anything.
Then check its list yourself. If it finds nothing, that does not prove that nothing is left. Before you trust any masking method, test it on invented documents with a written answer key. Our guide on testing a redaction tool explains how.
Frequently asked questions
Is it safe if I switch off training in ChatGPT?
Not by itself. Switching off training changes what the vendor does with your chats. It does not change the fact that the assistant read your unmasked document, or that your employer may forbid it. As the table shows, vendors may still log or store chats.
Does a business plan solve the problem?
It solves part of it. A contract can exclude training and say who may see the data. It does not fix the rewrite or the misses, so you still compare the result with the original.
Is a model that runs on my own computer a safe way to anonymize?
It avoids sending the file to a vendor, and the CNIL finds on-site systems generally more secure for personal data. But the output still needs a line-by-line check, because the BSI says models offer no guarantees about the quality of their outputs.
Can an assistant help once the document is masked?
Yes, with limits. Ask it to list remaining clues, then decide yourself. A masked copy can still point to a person through context, so your company policy still applies.
How can I check that an assistant missed nothing?
You cannot, from its answer alone. Build a short test file with invented people and a written list of every item to hide. Then count what stayed visible. Never test with real files.
Sources & references
- Report of the work undertaken by the ChatGPT Taskforce, 23 May 2024 (points 12, 21, 30 and 31)European Data Protection Board (EDPB)
- CNIL's Q&A on the Use of Generative AI Systems, 18 July 2024CNIL
- Generative AI Models: Opportunities and Risks for Industry and Authorities, version 2.0, 17 January 2025Bundesamt für Sicherheit in der Informationstechnik (BSI)
- Article 28 GDPR: ProcessorIntersoft Consulting (gdpr-info.eu)
- How your data is used to improve model performanceOpenAI Help Center
- Data controls in the OpenAI platformOpenAI
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot ChatMicrosoft Learn
- Microsoft Copilot Chat privacy and protectionsMicrosoft Learn
- Data, privacy, and security for Microsoft CopilotMicrosoft Learn
- Microsoft Copilot for individuals: your activity history (web and updated app, from 18 August 2026)Microsoft Support
- Privacy FAQ for Microsoft Copilot (personal accounts, app before 18 August 2026)Microsoft Support