Brooke Wright
Brooke Wright · @wright_mode
FREE KIT

Get the redaction kit

A free open-source app that strips the names and numbers out of client work before it goes near AI, then puts them back after. Plus the by-hand method if you want to start smaller. Yours to keep and change.

Free & open sourceRuns on your computerYours to customiseBuilt by Brooke
Something went wrong. Please try again.

No spam. Unsubscribe anytime.

Wright Mode — Free Kit

Never paste a client's real data into AI again

A free open-source app that hides names, tax file numbers and bank details before anything goes near ChatGPT or Claude — then puts them back in the draft that comes out. Clone it, rebrand it, teach it your industry’s paperwork. Or do it by hand with the method below.

🧰 Free & open source 💻 Runs on your computer 🔧 Yours to customise 🇦🇺 Built in Australia 🖥️ Cowork or Code

What's inside

Everything below this section teaches you to do the hiding by hand, or with a script you build yourself. That still works. But I have also built the whole thing as a small app you can run on your own computer — and the code is public, free and yours to change.

It is called Between Notes. You paste in your material (or import a PDF or a scanned page), it finds the identifying details, swaps each one for a placeholder, and hands you a prompt that is safe to paste into ChatGPT or Claude. When the draft comes back, you paste it in and the app puts every real detail back exactly as it was.

The repository

https://github.com/BrookeW1988/between-notes

Open the repository →  ·  Read CUSTOMISE.md →

Free, MIT licensed, no account, no API key, no monthly anything. It runs on your machine and never sends your material anywhere. I built it for an allied health practice, which is why the wording talks about clients and session notes — the CUSTOMISE.md file in the repo walks you through changing it for whatever you actually do.

1

Get it onto your computer

Open the link above and either clone it, or hit the green Code button and download the ZIP. You need Python 3.12 and about ten minutes.

2

Run the setup once

Follow the Quick start in the README. It installs what it needs and downloads a small English language model. Nothing is charged and nothing phones home.

3

Test it with made-up data

There are two fictional PDFs in the repo to try. Do not skip this. You are checking what it misses before you trust it with anything real.

4

Make it yours

Open CUSTOMISE.md. Two files control everything that matters: the document formats it writes, and what counts as an identifying detail in your industry.

If the terminal is not your happy place, do not do any of that by hand. Open the folder in Claude Code or Cowork and paste this instead:

Copy-paste this to install it

I have downloaded a local app from https://github.com/BrookeW1988/between-notes. Read the README, then walk me through setting it up on this computer one step at a time. I am not a developer, so tell me what to type and what I should see after each step, and stop and check with me before moving on. If something fails, explain what went wrong in plain English before you try to fix it.

And this one to turn it into a tool for your industry, not mine. Change the bits in square brackets:

Copy-paste this to customise it

Read README.md and CUSTOMISE.md in this folder. I want to adapt this app for [my bookkeeping practice]. 1. In static/core.js, replace the note templates with the documents I actually produce: [list them]. Rewrite makePrompt for my work but keep the four rules CUSTOMISE.md says to keep. 2. In privacy.py, add detection patterns for the identifiers in my work: [e.g. ABN, BSB and account numbers, my invoice prefix]. Change the labelled-field word lists to my labels: [e.g. client, supplier, account holder]. Add my industry's noise words to the safe-word sets: [e.g. Xero, MYOB, my business name]. 3. Rebrand it as [my business name] in templates/index.html and static/style.css. 4. Do not change app.py, documents.py or the restore logic. Then write me five fictional [expense query emails] with realistic identifying details, run each through the app, and tell me which details it missed and which harmless words it hid by mistake.

Why the second half of that prompt matters

Detection is never right the first time. You are looking for two kinds of mistake: things it missed, which is the dangerous one, and things it hid that it shouldn't have, which is the annoying one. The annoying one matters more than people think — if every second word is a placeholder, you stop reading the prompt properly, and that is exactly when the dangerous one slips past.

Read this before you use it on anything real

This is a working prototype, not a compliance product, and I am not going to pretend otherwise. It swaps details for placeholders that can be swapped back — that is not the same as making text anonymous. Context like a rare condition, a small town, a date or an unusual job can still identify someone even with every name removed. It can miss identifiers it has never seen. Test it properly on invented data, check what your own industry requires of you, and keep reviewing the full prompt before you send it. The repository says all of this in more detail and I have deliberately left it there.


A bookkeeper in my community told me she deletes every client's name and number by hand before she uses AI. Every single time. It takes ages. And here's the scary bit — one busy day, she'll miss one. That one slip is a client's private info, gone to a computer she doesn't control.

There's a better way. You get the computer to do the hiding for you — the same way, every time. You set it up once. Then it never gets tired, never gets bored, and never forgets.

😮‍💨 Doing it by hand

  • Slow — you redo it every time
  • Boring, so you start rushing
  • Easy to miss one name or number
  • One miss = real data leaked

✨ A little helper does it

  • Done in a few seconds
  • Exactly the same every time
  • Never gets tired or distracted
  • You literally can't forget

This is the most important page in the whole kit. Read it twice. It's also the answer to "can I just do this in Cowork?" — yes, as long as you follow this rule.

The rule

Do NOT paste your client's real info into the chat and ask AI to hide it. The second you hit enter, the AI has already seen it. Too late.

Instead: get AI to build you a little helper (a tiny script). The helper lives on your computer. The helper hides the private stuff. Only the safe, hidden version ever goes to AI.

1

Build the helper once

AI writes the little script for you. The script is just instructions — it has none of your client data inside it. Totally safe to make.

2

Run the helper on your file

This happens on your computer. The helper reads the file and hides the private bits. Your real data never goes anywhere.

3

Now use AI

You only ever hand AI the safe, hidden version. It can help you all day and never see a real name.

The mistake to avoid

Never paste a real client file into the chat and type "redact this". The AI sees it the moment you send it. Always: build the helper, then run the helper.


Before you hide things, you need to know what to hide. In Australia, these are the bits that matter most. Your helper should look for all of them.

🧑

Names

People and business names. Swap each for CLIENT_1, CLIENT_2, and so on.

🆔

Tax File Number

The TFN — 9 digits. Becomes TFN_1. This one's serious; never let it slip.

🏢

ABN

Australian Business Number — 11 digits. Becomes ABN_1.

🏦

BSB & account number

Bank details. Becomes BSB_1 and ACCOUNT_1.

📧

Emails & phones

Email addresses and phone numbers. Become EMAIL_1 and PHONE_1.

🏠

Addresses & DOB

Home or postal addresses and dates of birth. Become ADDRESS_1 and DOB_1.

A simple way to think about it

If a stranger could use it to find, contact, or pretend to be your client — hide it. When in doubt, hide it.


This is the easy way. Nothing scary, no black screen with code on it. You use Claude Cowork — the desktop app. If you've never touched the terminal, start here.

1

Make a folder

On your computer, make a folder called something like "Client work — safe". Pop the file you want to use (your spreadsheet, say) inside it.

2

Open Cowork and connect the folder

Open the Claude desktop app, go to Cowork, and connect that folder so Claude can see it.

3

Ask it to build the helper

Copy the prompt below and send it. Notice — you're asking it to build the tool, not to read your data.

4

Run the helper

Say: "now run it on my-file.csv". It makes a safe copy with all the private bits hidden.

5

Work on the safe copy

Now do your real job — "find the mistakes in this", "summarise this", whatever you need. AI only ever sees the safe version.

Copy-paste this into Cowork

Build me a small redaction script I can run on the files in this folder. It should find names, Tax File Numbers, ABNs, BSBs, bank account numbers, emails, phone numbers and addresses, and swap each one for a placeholder like CLIENT_1, ACCOUNT_1, TFN_1. Save a redacted copy AND a separate mapping file. Don't show me the real values — just build the tool.

That's it. It builds your helper. From now on you just say "redact this file" and it does the hiding for you.

Why this is safe

The helper does the hiding on your own computer. You only ever ask Cowork to work on the safe copy. Extra careful? Run the helper yourself and only ever open the safe copy with AI.


Prefer Claude Code (the terminal one)? Same idea, here's the short version. If that last sentence meant nothing to you — skip this and use Cowork above. Both end up in the same place.

1

Open Claude Code in your folder

Point it at the folder with your file in it.

2

Ask it to build the script

Paste the prompt below. It writes a little file called redact.py.

3

Run it

Say "run redact.py on clients.csv". The script does the hiding right there on your machine.

4

Use AI on the safe file

It hands you a clean, hidden copy. Use that for everything else.

Copy-paste this into Claude Code

Build a redaction script called redact.py. It takes a CSV, swaps names, Tax File Numbers, ABNs, BSBs, bank account numbers, emails, phone numbers and addresses for placeholders like CLIENT_1 and ACCOUNT_1, and writes both a redacted copy and a mapping file. Don't print the real values.

Same safety, same rule

The script runs on your computer. Your real data never goes to the cloud. AI only ever reads the safe copy it made.


Here's the whole thing in plain words, with a real example. Three little steps.

What's actually happening

1
Hide. The helper swaps the private bits. "Sarah Chen" becomes CLIENT_1. Her TFN becomes TFN_1. Her account number becomes ACCOUNT_1. It also writes a little mapping file that remembers which is which.
2
Use AI. Ask your question about the safe version. AI sees CLIENT_1 — not Sarah. It still does the maths, finds the errors, writes the summary. It just doesn't know who anyone really is.
3
Swap back. When AI hands you the answer, the mapping file puts the real names back in — on your computer. Now it's useful to you, and only you ever saw the real details.

The payoff

Same insights. Same time saved. But none of your client's private stuff ever left your computer. That's the whole game.


Don't just trust it — check it. This takes 30 seconds and you should do it every time until you're sure your helper is solid.

The 30-second leak check

Open the safe copy. Press Ctrl+F (or Cmd+F on a Mac) and search for one real client name, then one real number. If it finds nothing — you're good. If it finds something, tell AI "you missed this one, add it to the helper" and run it again.

Make it a one-click thing

Once it works, say: "save this as a skill called redact". Next time you just say "redact this file" and it's done. You can also point it at a whole folder and have it clean every file at once.

You just removed the scariest part of using AI for client work

No more hand-deleting. No more "what if I missed one". A two-minute setup, and you can finally use AI on real work without the worry. That's a proper unlock.


Ready to go deeper?

Take your skills to the next level with these resources.