Handiwork
  • Home
  • Tools
  • Guides
  • Categories
  • About
Browse Tools
Handiwork
  • Home
  • Tools
  • Guides
  • Categories
  • About
Browse Tools

Popular tools

  • GPA & CGPA Calculator
  • Bill Splitter
  • Age Calculator
  • QR Code Generator
  • Keyboard Tester
  • Passphrase Generator

Categories

  • Text
  • Image
  • Design & Color
  • PDF & Documents
  • Developer
  • Security
  • Calculators
  • Converters & Encoders
  • Productivity
  • Random & Decision

Resources

  • All Tools
  • Guides
  • Editorial Standards
  • Changelog
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
Browse all tools>
English

© 2026 Handiwork. Built and maintained by Handiwork.

All toolsAll security tools

Security tool

Paste & Clear PII Scrubber

Paste text to auto-redact emails, API keys, JWTs, webhooks, and other sensitive data.

Redaction rules— All types enabled+

All scrubbing runs in your browser. Automated redaction can miss context-specific data, so review the output before sharing it.

About the Handiwork Paste & Clear PII Scrubber

The Paste & Clear PII Scrubber finds and redacts sensitive information from any text you paste — emails, phone numbers, API keys, JWTs, webhook URLs, database connection strings, and more. Click Paste & scrub for a one-step workflow, or type directly and watch redaction happen automatically. Match counts show what was removed, presets let you focus on secrets or personal info, and everything runs locally in your browser so nothing is ever uploaded.

How to use the Handiwork Paste & Clear PII Scrubber

  1. Click Paste & scrub (or paste/type your text) — redaction runs automatically.
  2. Review the match counts and inspect the scrubbed output for anything the automated rules may have missed.
  3. Copy the redacted text. Adjust presets or rules if needed, then click Regenerate.

What is PII and why redact it?

PII (Personally Identifiable Information) and secrets include email addresses, phone numbers, Social Security numbers, credit cards, IP addresses, API keys, and access tokens. Accidentally sharing them in a screenshot, support ticket, log dump, or public repository can lead to spam, account takeover, or compliance violations — so removing them first is a simple but important safeguard.

What the scrubber detects

By default, all rule types are enabled: email addresses, phone numbers, SSNs, credit card numbers, IP and MAC addresses, API keys and bearer tokens, Slack and Discord webhook URLs, JWT tokens, passwords and secrets in config files (key=value), URLs and database connection strings with embedded credentials, and PEM private keys. Each category can be toggled individually under Redaction rules.

Presets for quick control

Use Everything to redact all supported types — the default for most sharing scenarios. Secrets only targets API keys, JWTs, config secrets, credential URLs, connection strings, and private keys while leaving personal identifiers like emails untouched. Personal info focuses on emails, phones, SSNs, credit cards, and IP/MAC addresses. Your rule choices are saved locally in your browser for next time.

Private by design

Because scrubbing happens entirely in your browser, the sensitive text you paste is never uploaded anywhere. That matters: a tool built to protect secrets should never transmit them. Only your redaction rule preferences are stored locally — not the text you scrub.

Assumptions and limitations

  • Pattern matching cannot understand every context or identifier format. It can miss sensitive data and can also redact harmless text that resembles a secret.
  • Names, street addresses, dates of birth, free-form medical details, and organization-specific identifiers are not detected generically.
  • Always inspect the complete output before sharing it. For regulated or high-impact data, follow your organization’s approved data-loss-prevention and review process.

Sources and standards

These authoritative references were used to verify the method and guidance on this page.

  • Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) — U.S. National Institute of Standards and Technology

Frequently asked questions

What kinds of data can it detect?

+

It detects email addresses, phone numbers, Social Security numbers, credit card numbers, IP and MAC addresses, API keys and bearer tokens, Slack and Discord webhook URLs, JWT tokens, passwords and secrets in config files, URLs and database connection strings with credentials, and PEM private keys. Match counts show how many of each type were redacted. Always review the output before sharing — no automated tool catches everything.

Does my pasted text get uploaded?

+

No. All detection and redaction runs locally in your browser, so nothing is sent to a server. Only your redaction rule preferences are saved in local storage for convenience.

Do I need to click a button to scrub?

+

Redaction runs automatically when you paste or type text. If you change presets or individual rules afterward, click Regenerate to update the output with your new settings.

What are the presets for?

+

Everything redacts all supported types. Secrets only targets keys, tokens, webhooks, config secrets, credential URLs, connection strings, and private keys. Personal info targets emails, phones, SSNs, credit cards, and IP/MAC addresses. You can also fine-tune individual rules in the Redaction rules panel.

Method and guidance reviewed July 12, 2026 by Handiwork.

How we review tools

Go deeper

Understand the method and trade-offs

Privacy & technology · 8 minHow browser-based tools handle your dataLocal processing can reduce exposure, but it is not a magic privacy guarantee. This guide separates tool input, site telemetry, browser storage, downloads, and network requests so you can make a practical risk decision.Read guideSecurity · 11 minPasswords, passphrases, and browser encryptionPassword tools solve different problems. This guide explains the difference between generation and estimation, why length and uniqueness matter, and why encryption is only as strong as its password and operating environment.Read guide

Related security tools

All security tools
  • Passphrase GeneratorGenerate strong, memorable passphrases from random words with live entropy.
  • Password Strength CheckerTest password strength with entropy, crack-time estimates, and improvement tips.
  • Text Encrypt & DecryptEncrypt and decrypt text with a password using AES-256, locally in your browser.
  • Password GeneratorCreate strong random passwords with presets, strength meter, and entropy readout.