The model does not need
your customer’s name

You upload a document and appto swaps the names, email addresses and national ID numbers inside it for placeholder tokens — before anything reaches the model. The case itself stays intact.

The model sees tokens.You see people.

The assistant works on tokens and appto puts the real values back in — before the answer reaches your screen. On your side nothing changes.

Complaints assistant

Customer: Anna Kowalska — I accepted the complaint, the goods arrived damaged, so a full refund is due. The reply is waiting for your “send”, address: a.kowalska@zenit.pl

The model worked on tokens
[PERSON_1]Anna Kowalska [EMAIL_1]a.kowalska@zenit.pl [PESEL_1]84061512345

Token–value pairs sit encrypted on appto’s side for 30 days and stay out of the model’s reach. The model provider never receives them — there is nothing on their end to reconstruct.

Either masked.Or stopped.

The gateway has no third option: a file either reaches the model with tokens instead of personal data, or it does not go out at all. There is no variant where something slips through unmasked because “it did not quite work”.

[PERSON_1][EMAIL_1][PERSON_2][EMAIL_2]
complaints-august.xlsx 42 detections · masked
[PERSON_1][PESEL_1][EMAIL_1]
zenit-contract-2026.pdf 9 detections · masked
[PERSON_1][PESEL_1][EMAIL_1]
damage-report.docx 6 detections · masked
customer-database.csv Stopped — did not clear the gateway

You see what the gateway foundThe number next to an attachment says how much personal data it recognized. Statistics count detections, not content — nobody has to read anyone’s conversations to learn where that data actually travels.

An edit never unmasksMasking runs again on every edit of the file, including writes made by an agent. A value that has been swapped once cannot be restored by accident.

Tokens hold across the conversationThe same file discussed across ten messages carries the same tokens everywhere. The model does not lose the thread, and you never get two names for one person.

Upload your first document

The gateway is an add-on.The rest is always on.

Masking is switched on by the organization and is off by default. Everything underneath it applies whether or not you turn it on — from the very first login.

Data masking

Personal data in uploaded files turns into tokens before anything reaches the model. The organization switches it on — it is off by default.

Permission boundaries

An agent reaches exactly as far as the person who asked it. It will not see a folder or a channel that they cannot open.

No training on your data

We call the models in the mode where providers do not use the data you send to train their models.

Encryption in transit and at rest

Traffic to appto runs over TLS/HTTPS only, and encryption at rest is handled by the platform layer. Internal access tokens are cryptographically signed.

A separate space for every company

Your data never surfaces in another organization’s view. Automated tests check this on every change to the system.

Servers in the EU (Ireland)

appto’s application data stays in the Union. Masking runs on EU infrastructure too — files do not leave it.

Try iton your own data.

You switch the gateway on yourself, in your organization’s settings. You send us nothing — you see for yourself what appto finds in your files and what leaves them for the model.

No card. Your account takes 30 seconds.

Before you switch the gateway on

The questions people ask about what happens to a file along the way. Need documentation for your IT team — subprocessors, a data processing agreement, material for a security questionnaire? Write to us and we will send the security pack.

Does the gateway also mask what we type into a conversation?

No. The gateway works on files — attachments in a conversation, files in Projects and the ones dropped into Slack. Text you type on the keyboard goes to the model exactly as you wrote it. We say that plainly, because files are where personal data travels in bulk: a single complaints spreadsheet can hold more of it than a month of conversations.

Is this data anonymization?

No, and we deliberately avoid that word. Anonymization is irreversible — after it nobody can tell who the content was about. Here the token–value pairs stay encrypted on our side so that appto can put the real data back into the answer you read. In GDPR language that is pseudonymization. We call it by its name, because the first serious audit would catch it anyway.

Does the gateway work straight away, on its own?

No. The organization switches it on, in advanced settings under the Privacy tab. If you do not turn it on, nothing about appto changes. It is a deliberate decision, not a setting that quietly arrives.

What exactly gets masked in a file?

The personal data covered by your organization’s policy — names, email addresses, national ID numbers. Business data stays: order number, product name, amount, description of the case. Without those the model would have nothing to work with, and keeping it working well is the whole point of this mechanism.

Will the answer be worse because of it?

The model receives the entire content of the document — who writes to whom, about what, at which stage and under which order number. A customer’s surname is rarely what decides the quality of a complaint response. Tokens are stable within a conversation, so the model knows that [PERSON_1] on page three is the same person as on page one.

Who can unmask the data?

Only appto, when it puts the values back into an answer. Token–value pairs sit encrypted in the Privacy Vault for 30 days and stay out of the model’s reach — the model provider never receives them, so there is nothing on their end to reconstruct.

What does it cost?

10 AI credits per page of a document, charged once, after successful processing. Reusing the same file costs nothing. A gateway that is switched off costs nothing.

What do we see in the statistics?

How much data the gateway recognized and of what type — statistics count detections, not content. That tells you where personal data actually travels in your company, without anyone having to look into someone’s conversations.