---
title: "Masking personal data"
description: "Hide card, IBAN, ID and passport numbers before a conversation is saved, and what the AI sees."
source: https://hiy.ai/docs/masking
---

# Masking personal data

Masking hides certain numbers in a conversation **before it is saved**. Your Inbox, Activity, exports, summary emails, handover alerts, webhooks and Zapier all read the saved conversation, so they hold the masked text and never the number. It is **off for everyone** until a workspace owner turns it on, in **Workspace → Data & privacy → Personal data masking** (new app).

## What is masked

Only the kinds you tick, and only when they match. A number is masked when its check digits add up or a nearby word confirms it; a lookalike such as an order number or a date is left alone. No AI decides this.

| Kind | Ticked at first | Looks like when masked |
| --- | --- | --- |
| Card numbers | Yes | `•••• 4242` (the last four stay) |
| IBANs | Yes | `GB•• •••• 5678` |
| National ID numbers (US Social Security, UK National Insurance, Spanish DNI and NIE, Italian codice fiscale, French NIR, Dutch BSN) | Yes | `[ID number]` |
| Passport numbers | Yes | `[passport number]` |
| Phone numbers | No | `•••• 89` |
| Email addresses | No | `•••@acme.com` |

A bare nine-digit ID needs a word like "SSN" beside it, and a passport number needs "passport" (or the same word in Spanish, French, German, Italian or Dutch) within 30 characters. **Your own patterns** add up to 10 of your own, such as an order number, written as a regular expression. A pattern that could hang the matcher, uses a backreference or lookbehind, or matches nothing in particular is refused when you save. **Try it** shows the result on a sample, in your browser, before anything is saved.

## The limits

- **Forward only.** Turning masking on changes messages saved from then on. Conversations already saved stay as they are, and turning it off restores nothing.
- **It can't be undone.** The number is replaced before it is stored, so hiy no longer has it and nothing can unmask it.
- **A wrong guess loses the text.** That is why masking waits for a check digit or a context word.
- **Only these kinds.** A name, an address or a number in a shape we don't check is not masked.
- **Slack keeps its own copy.** A message sent from Slack is saved in hiy masked, but Slack still holds the original in your Slack workspace.
- **It does not narrow who can read.** A colleague you invite still reads every saved conversation, masked or not.

## What the AI sees

Earlier turns reach the AI from the saved conversation, so with masking on they are always masked. The message being answered reaches the AI as typed, and the safety check always reads the visitor's own words. **Also hide from the AI** (off by default) masks the current message too. It never applies to emails or phone numbers, because the agent needs them to save a visitor's contact. The agent's reply is masked before it is saved, since it can repeat a number back.

The visitor's own screen is never changed or blocked. After a reload they see the saved, masked conversation.

## Contact details a visitor chooses to give

An email, phone or name submitted through your lead or handover form, or one the agent saves from the conversation, is stored as given: the visitor chose to give it, and your follow-ups, replies and webhooks need a working address. What the visitor wrote around it, the lead's question and the values the agent collected, are masked. If the agent tries to save a contact that was already masked, it asks the visitor again.

A handover's webhook and Zapier payload carry the lead's contact as given, and a transcript excerpt and summary written from the masked text.

## Per agent

Each agent follows the workspace setting unless you give it **its own**, which can be stricter or looser. Only the workspace owner changes any of it; members see it read-only.
