Privacy
mask2ai exists to keep personal data off the wire. It has no wire of its own.
What it reads
In Claude Code: the prompt you submit, the input and output of each tool call, and the text of each reply as it streams, all handed to it by Claude Code's hook system. In Chrome: the body of chat requests to claude.ai and chatgpt.com, and the text rendered on those pages. Nothing else.
What it stores
A map from placeholder to real value, so the values can be restored. In Claude Code it is a file under the plugin's data directory, one per session, mode 0600, deleted when the session ends. In Chrome it is in the tab's sessionStorage and is gone when the tab closes. There is no other state, no cache and no log.
What it sends
Nothing to mask2ai. There is no server, no account, no telemetry and no update check. The only traffic is the traffic you were already sending to Anthropic or OpenAI, with placeholders in place of the personal data that was recognised.
What still reaches the provider: placeholders, everything the patterns do not recognise, file paths, and your prompt once you resend it in masked form. Detection is pattern based; the docs list exactly what is and is not caught.
The code
About 300 lines of JavaScript with no dependency beyond Node.js, MIT licensed, at github.com/serkankorkut/mask2ai. The repository ships a proof that captures every byte Claude Code sends and a headless check of the extension on both sites.