How personal information is protected | Civio Civio Assist Knowledge Base     [Skip to content](#main)  [ ![Civio Civio Assist Knowledge Base](/civio-light.svg) ](https://nginx.deploy-lagoon-production.civio-assist-docs.dh1.amazee.io)  [Product documentation](/articles) [Release notes](/releases) [ Support portal ](https://nginx.deploy-lagoon-production.civio-assist-docs.dh1.amazee.io/portal/login)   Toggle navigation      

  [Product documentation](/articles) [Release notes](/releases) [Support portal](https://nginx.deploy-lagoon-production.civio-assist-docs.dh1.amazee.io/portal/login)  

  1. [Home](/) ›
2. [Product documentation](/articles) ›
3. [Privacy and safety](/articles?category=4) ›
4. How personal information is protected

 How personal information is protected
=====================================

Updated 3 weeks ago · 3 min read

 Search     Search  

Users often include personal details the chatbot never needs — a full name, an address, a customer number — just by asking their question naturally.

Personal details are detected and replaced with a placeholder *before* the message goes anywhere, so they are never sent to the AI model and never stored in the conversation transcript. This runs on every chatbot unless it has been switched off for yours.

It happens twice
----------------

The check runs in two places:

1. **In the chat window**, before the message leaves the user's browser.
2. **On our servers**, before the message reaches the AI model.

The two layers are independent and check for the same personal details. If a detail slips past one, the other still catches it.

What is detected
----------------

When any of these are found, the text is swapped for a placeholder:

Detail

Replaced with

Names

\[NAME\]

Email addresses

\[EMAIL\]

Phone numbers

\[PHONE\]

Street addresses and PO boxes

\[ADDRESS\]

Dates of birth

\[DOB\]

Passport numbers

\[PASSPORT\]

Driver's licence numbers

\[DL\]

Tax file numbers

\[TFN\]

Medicare numbers

\[MEDICARE\]

ABNs

\[ABN\]

Credit card numbers

\[CARD\]

![A conversation transcript in the dashboard where a user's name and email have been replaced with the NAME and EMAIL placeholders](https://assist.knowledge.civ.io/storage/5sTgeFOfzam7IaX1kMwailxPQTR3NNEblINkzDbL.png)

How it avoids false alarms
--------------------------

Blunt detection would ruin ordinary conversations, so a few refinements keep it accurate:

- **Numbers are validated.** Tax file, Medicare, ABN and credit card numbers are checked against the official rules that make those numbers valid. A random nine-digit number is left alone; a real tax file number is not.
- **Dates need context.** A date is only treated as a date of birth when nearby wording suggests it is one. "Is the pool open on 12/01/2026?" is untouched.
- **Places are told apart from people.** "I live in Sydney" keeps the place name, while "Hi, I'm Sydney" is treated as a person and replaced.

Turning it off, and making exceptions
-------------------------------------

Redaction is a setting on each chatbot, and it is switched on unless it is changed. It can be switched off for a chatbot whose users are already identified and where redaction serves no purpose, such as one sitting behind a staff login. With it off, whatever a user types is stored in the transcript and sent to the AI model as written.

A chatbot can also carry a list of words that are never treated as names, while every other detection continues as normal. This is what to ask for when a word your users type often is being replaced as though it were a person: a suburb, a park, a venue, or a service whose name reads like a first name.

Both are configured by the Civio team. Contact your Civio representative with the chatbot concerned and the words you want left as written.

What this does not cover
------------------------

No automatic detection is perfect. An unusual format or an unexpected way of writing something can slip through.

This protects free-text chat messages. It is not a substitute for a secure form. When you genuinely need to collect personal information, direct users to a proper form rather than letting them type it into the chat.

It is still worth telling users not to share sensitive details in chat. Your [AI disclaimer](/articles/ai-disclaimer) is a good place to say so.

Was this article helpful?
-------------------------

Your feedback helps us prioritise what to rewrite.

      Yes     No  

 [    Back to Privacy and safety ](/articles?category=4) 

 On this page 

### Still need help?

Raise a request in the support portal and track it to resolution.

 [ Submit a support request ](https://nginx.deploy-lagoon-production.civio-assist-docs.dh1.amazee.io/portal/login)

**Need additional help?** Contact our support team at [help@assist-support.civ.io](mailto:support@civ.io)

 © 2026 [Civio](https://civ.io)
