Blog · Productivity & AI · · 1 min read

Anonymize an email before pasting it into ChatGPT

Twelve replies, stacked on top of each other. All you want is for ChatGPT to summarize the thread and suggest an answer. Select all, paste, send. Except that, without noticing, you just handed a third-party server your client's name, their email address, the signature with their cell number, and even the attachments quoted at the very bottom of the message. The real question is not whether the AI will summarize it well. It is what leaves with the text.

Raw emailat risk
From : Jean Dupont <j.dupont@client.fr>
To : Marie Leroy
Subject : Devis dossier 2026-0457
Hi Marie, can you approve the quote for file 2026-0457 for SARL Martin? Thanks.
Ready for AIsafe
From : [PERSONNE_1] <[EMAIL_1]>
To : [PERSONNE_2]
Subject : Devis dossier [REFERENCE_1]
Hi [PERSONNE_2], can you approve the quote for file [REFERENCE_1] for [ORGANISATION_1]? Thanks.

It is already in the header and the signature

An email gives you away. Before the first word of the body, even. The header lines up the names and addresses of the sender and every recipient, and an address like j.dupont@client.fr already names the company without anyone having to look. The carbon copy drags in people who never asked to be there. And the signature? Right at the bottom, it spells out job title, direct line, cell number, sometimes the firm's postal address. It is the densest patch of personal data on the page, and by far the one people forget the most.

The reply chain that keeps growing

A summary? You almost never paste a single message: you paste the whole thread. And because each reply re-quotes the one before it, a twelve-message exchange carries twelve headers, twelve dates and every single contact who ever touched it. Client references repeat. So do file and quote numbers, at every level. As for the attachments quoted at the bottom ("Attached: contract_SARL_Martin.pdf"), they sometimes name the client in the filename alone.

Clean the thread before pasting it

The move comes in three beats. You pseudonymize the whole email, header, signature and reply chain included, work with the AI on the masked version (rewrite, summary, draft reply), then re-identify the result locally just before you send it. The AI never sees a real contact. And you get the real one back at the end.

Safe-Doc handles it. It masks the email and its attachments before the AI, keeps the layout intact and processes everything in the European Union before purging. See the ChatGPT and GDPR at work guide.

Paste a real email thread. See, in black and white, what would leave before the AI. Reversible pseudonymization.

Part of the guide : Use cases ↗