Practical guide · By Aurelio Avila · October 8, 2026
Before you paste: protecting client and project names in AI prompts
Generic detection is good at patterns. An email address, a card number or an API key has a shape that a scanner can recognize without knowing anything about you. A client's company name or your internal codename does not. It looks like any other word, which is exactly why it is the thing most likely to slip through.
Why names are the easy leak
Names arrive in prompts without anyone deciding to include them. They sit in email subject lines, file paths, ticket titles, meeting notes and staging URLs. Copy a thread to ask for a summary, and the client's name comes along in every quoted header.
On its own, a budget figure or a launch date is anonymous. Attached to a name, it becomes information about a specific company, and in most engagements that is precisely what the confidentiality clause covers. The detail is harmless; the connection is not.
A quick pre-paste routine
This takes less than a minute once it becomes a habit.
- Scan for proper nouns. Company names, product names, codenames and people. Read the prompt once looking only for capital letters.
- Swap, don't delete. Replace each name with a consistent placeholder ("Client A", "Project A", "the vendor"). Consistency matters: if the same company appears three times, use the same placeholder three times so the answer still makes sense.
- Check paths, URLs and filenames. A staging hostname or a folder called after the client gives the name away even when the body text is clean.
- Strip signatures and headers. Quoted email chains carry names, titles and phone numbers in every reply.
- Reread the answer before reusing it. The assistant will echo your placeholders. Swap the real names back in locally, not in the chat.
The same routine applies to everything else on our checklist of what not to paste into ChatGPT. Names are simply the item that needs your own knowledge, because no pattern can supply it.
How protected terms work in Redaxa
Redaxa's free checks cover personal data, credentials, financial information and secrets. Names of clients and projects are different: the tool cannot know your internal vocabulary unless you tell it. As the prompt privacy guide says, "do not assume generic detection knows your internal vocabulary."
That is what protected terms are for.
- Pro lets you add your own protected terms to flag client and project names. Enter the names once, and every check treats them like any other finding, with a safer version of the prompt ready to copy. Pro also includes local repository checks on Windows and redacted text reports. €79.90 a year (€6.66 a month, billed yearly).
- Business adds shared protected terms that apply to every member's checks, category policies (warn, redact or block sending in the extension), a metadata-only activity view with CSV export for admins, and 1–3 seats. €149.90 per user per year (€12.49 a month, billed yearly).
- Scripts and pipelines can pass custom terms to the Scan API; organization protected terms are always applied on top.
A 7-day trial is available for eligible new subscribers. A card is required, and you can cancel before the trial ends to avoid a charge. Full details are on the pricing page.
A few practical notes on building the list: add the forms you actually type, not just the legal name. If a client is known internally by an abbreviation or a codename, add that as its own term. Keep the list current when engagements start and end, and under Business, keep it shared so new team members inherit it on day one.
Where the check runs
Protected terms apply wherever you run Redaxa:
- The Chrome extension checks your message inside ChatGPT, Claude, Gemini, Copilot and Perplexity before it sends.
- The Windows app ships with signed auto-updates.
- The web check works from any browser.
Processing is server-side: the prompt text goes to Redaxa's backend for the scan over an encrypted connection, is not forwarded to a third-party AI service and is not stored. See the privacy policy for the full description.
FAQ
Do I need to add every client I have ever worked with?
Start with active engagements and anything under a confidentiality clause. Add past clients if their information still appears in the material you work with, and remove terms when they are no longer relevant.
Will a protected term catch abbreviations and nicknames?
Add each form you use as a separate term: the full name, the short form, the codename. That way the check matches what you actually type.
Can my team share one list?
Yes, with Business. Shared protected terms apply to every member's checks, and admins can set category policies for the whole workspace.
Can I try name protection for free?
Free checks cover personal data, credentials, financial information and secrets, and you can run up to 5 a day on the site with no account. Protected terms are part of Pro and Business, with a 7-day trial for eligible new subscribers.