Feature explainer · April 2026
Privacy filter
Remove personal info from your screen data before it reaches any AI model — inside an enclave you can verify didn't store, log, or leak anything.
What it does
When the Privacy toggle in chat is on (the shield icon next to the send button), Screenpipe filters text pulled from OCR, audio transcripts, accessibility text, and memory notes before sending it to the AI you are chatting with.
The filter replaces personal info with placeholders:
Before: "email louis.beaumont@gmail.com about the Stripe invoice for 555-1234" After: "email [EMAIL] about the Stripe invoice for [PHONE]"
Currently detected:
[PERSON]— names[EMAIL]— email addresses[PHONE]— phone numbers[ADDRESS]— physical addresses[ACCOUNT]— account numbers, SSNs, card numbers[URL]— URLs that look personal[DATE]— dates that look personal[SECRET]— API keys, tokens
Why it's different from a regex
Many PII scrubbers use pattern matching. They look for text such as @ + domain and replace it. This can miss names without context, addresses without zip codes, or account numbers in an unexpected format.
Our filter uses a 1.5B-parameter token-classification model (openai/privacy-filter) fine-tuned specifically to find private info in free text. It reads the whole sentence and decides, token by token, what is and isn't personal.
The confidential part
We run this filter in a confidential-compute enclave hosted by Tinfoil. A confidential enclave is a virtual machine whose memory is encrypted by the CPU (AMD SEV-SNP / Intel TDX) — even the cloud provider running the hardware can't read what's inside.
The practical guarantees:
- Attested code. The enclave publishes a signed measurement of the exact container image it's running. Anyone can fetch the measurement and check it against the open-source code. If the measurement doesn't match, the enclave is compromised and your client will refuse to talk to it.
- No disk. The enclave has no persistent storage. Data written during a request does not survive the request.
- No logs. The server code doesn't log request bodies. Anyone can audit it.
- Encrypted transport. HTTPS from your machine to the enclave. Tinfoil's load balancer terminates TLS inside the attested boundary, so the decrypted text only exists in enclave memory.
What Screenpipe sees
Your local screenpipe-server calls the enclave directly. Text leaves your device, is redacted inside the enclave, and returns with personal information replaced. Screenpipe's own cloud is outside this path and cannot see the raw text.
The enclave caches recent redactions by content hash (SHA-256) for 1 hour so repeated screen content (the same email thread, the same IDE file) doesn't re-pay the round trip. Nothing else persists.
Where it's applied
- Chat: toggle the shield icon above the send button. The app adds
filter_pii=1to every search the AI performs on your screen data. - Scheduled tasks: set
privacy_filter: truein a scheduled task's front-matter to have every search the agent runs pre-redacted. - Direct API: append
?filter_pii=1to any/searchrequest against your local screenpipe-server.
Limits
- Latency. Adds ~1–2 seconds per search. We cache aggressively so repeated data is nearly free, but the first hit on new text pays a round-trip.
- Model imperfection. The model scores above 99% on common categories in our tests, but it can miss sensitive information. Combine it with the ignored-windows filter and exclude password managers from recording.
- Not raw frames. Screenshots are binary images; the filter works on the text already extracted from them. If raw-image upload is ever added, that's a separate feature with its own consent.
- Business tier. The toggle is available to Business subscribers to cover compute costs. Other users see the shield icon with an upgrade link.
Open source
All of this is auditable:
- Filter service + Dockerfile + Tinfoil deploy config: https://github.com/screenpipe/privacy-filter
- Client-side integration in Screenpipe: crates/screenpipe-engine/src/privacy_filter.rs
- Tinfoil's attestation SDK for verifying the running enclave: docs.tinfoil.sh
Questions or suggestions? support@screenpi.pe.