De-identification
A client's name never reaches the internet.
Marling removes the details that identify a client before a request reaches ChatGPT, Claude or Gemini, and puts them back in the answer. Your team writes normally. The model never learns who.
What happens to a message.
-
You write it as you would anyway
“Draft a letter for Matthew Sorensen, DOB 04/17/1986, confirming the new arrangement.”
-
The device finds the identifiers
Names, dates of birth, phone numbers, addresses, record and matter numbers. This runs on the device, before anything is sent.
-
Placeholders go out, not the real values
The model works on “Draft a letter for <FULL_NAME>, DOB <DOB> …”. The substance of the request stays intact, so the answer is still useful.
-
The answer comes back complete
The device swaps the real values back in. You see a finished letter with the right name on it.
What leaves, what stays.
| Item | Where it goes |
|---|---|
| Names, dates of birth, contact details, record and matter numbers | Stays on the device |
| The substance of a request | Leaves, identifiers removed |
| A passage from one of your documents used in an answer | Leaves, identifiers removed |
| Your documents themselves, your saved chats, your search index | Stays on the device |
| Dictation audio | Never leaves, never stored |
If masking can’t run, nothing sends
If the step that hides identifiers is unavailable, the message is refused rather than sent as it is. No partial protection.
You decide what counts as sensitive
Paste two of your own record or matter numbers and Marling learns the pattern. Mark your practice’s own name as fine to show. Every change is previewed and checked before it takes effect, so an exception can’t expose a client.
Questions careful people ask.
So the model still sees my client’s situation?
Yes. It sees “client is behind on payments and asking for a plan”, not whose payments. That is what makes the answer useful and the exposure small.
Does the AI learn from our conversations?
No. Marling uses the providers’ commercial services, which don’t use your requests to train their models, and identifying details are removed before anything is sent.
Is this enough for regulated work?
It is built so identifiers stay on the device and refuses to send if masking isn’t running. No product can be “certified” compliant; going live with real client information also means the right agreements are in place, and we walk through that with you.