Feature explainer · April 2026

Privacy filter

Remove personal info from your screen data before it reaches any AI model — inside an enclave you can verify didn't store, log, or leak anything.

What it does

When the Privacy toggle in chat is on (the shield icon next to the send button), Screenpipe filters text pulled from OCR, audio transcripts, accessibility text, and memory notes before sending it to the AI you are chatting with.

The filter replaces personal info with placeholders:

Before:  "email louis.beaumont@gmail.com about the Stripe invoice for 555-1234"
After:   "email [EMAIL] about the Stripe invoice for [PHONE]"

Currently detected:

Why it's different from a regex

Many PII scrubbers use pattern matching. They look for text such as @ + domain and replace it. This can miss names without context, addresses without zip codes, or account numbers in an unexpected format.

Our filter uses a 1.5B-parameter token-classification model (openai/privacy-filter) fine-tuned specifically to find private info in free text. It reads the whole sentence and decides, token by token, what is and isn't personal.

The confidential part

We run this filter in a confidential-compute enclave hosted by Tinfoil. A confidential enclave is a virtual machine whose memory is encrypted by the CPU (AMD SEV-SNP / Intel TDX) — even the cloud provider running the hardware can't read what's inside.

The practical guarantees:

What Screenpipe sees

Your local screenpipe-server calls the enclave directly. Text leaves your device, is redacted inside the enclave, and returns with personal information replaced. Screenpipe's own cloud is outside this path and cannot see the raw text.

The enclave caches recent redactions by content hash (SHA-256) for 1 hour so repeated screen content (the same email thread, the same IDE file) doesn't re-pay the round trip. Nothing else persists.

Where it's applied

Limits

Open source

All of this is auditable:

Questions or suggestions? support@screenpi.pe.