MaskSheet / Guide and security · 日本語

Mask Excel and CSV data
before sharing it with AI.

You may want AI to analyze revenue or visit frequency without seeing names and phone numbers. MaskSheet creates a separate spreadsheet with selected values replaced, while keeping useful numbers and table structure.

No AI analysis. No data sent to AI.
MaskSheet uses rules based on column names and text patterns. Files and pasted answers are processed in your browser. Every feature is free, with no account required.

Prepare a copy in three steps

  1. Open an Excel or CSV file. Headers after titles or blank rows are estimated automatically. Correct the reading position in the review screen if needed. CSV encoding is normally detected automatically.
  2. Review the recommended result. The masked table appears immediately. Change only the columns you need. Check column names and retained values too.
  3. Save a new file. Excel includes all processed sheets; CSV includes the selected sheet. Your original file is unchanged.
Fictional input Output
Name: Alex Morgan PERSON_001
Phone: +1 (202) 555-0142 Blank
Email: alex@example.com EMAIL_001
Revenue: 86,000 Number retained

Try the free masking tool

Company names and internal confidential data

Company, Employer and Vendor headers, and values with forms such as LLC, Ltd. and Japanese corporate designators, are detected as organization candidates. Project name, Salary and Diagnosis headers are treated as sensitive candidates. Ordinary revenue and count columns remain available for analysis unless you choose otherwise.

Add internal abbreviations, project names or codes under custom terms in the review screen: up to 100 terms, one per line. Case-insensitive, width-normalized substring matching checks all data cells and headers in all sheets. Matching cells are replaced in full, even in Keep columns. Matching headers become Column_1, etc. Deleted cells stay blank. Terms are not automatically saved.

This cannot determine every company’s confidentiality rules or infer all trade secrets from context. Review retained data and use column controls for other confidential information.

How detection works

The first 30 rows are checked for headers, including up to three header rows. Uncertain layouts are flagged, and a no-header option preserves all data rows. Name shapes and a small set of Japanese surname hints flag additional candidates for review. Uncommon names may be missed and product names may be flagged. Evidence and matching counts are shown by column. Unmerge cells in the data area before importing.

The app checks column names and every non-empty data cell. Headers such as Name, Phone, Email, Customer ID, Date of birth and Notes are recognized, along with Japanese equivalents. Regular expressions identify email-like text, selected phone formats, selected API-key formats and Japanese addresses containing a prefecture.

Card-number candidates must have 13–19 digits and pass a Luhn check. Twelve-digit numbers are treated as Japanese My Number candidates, without official verification or a My Number check-digit test. Order numbers and other ordinary data may be flagged incorrectly.

Secret, card-number and twelve-digit-number candidates take priority; next come header rules, then other value patterns. Phone, card-number and My Number candidate columns are blanked. Other detected columns are replaced by tokens. Columns without candidates are kept.

What “processed locally” means

There is no file upload, autosave, analytics, advertising or external AI API. Vercel serves the page, program and fonts, and may process access information such as your IP address when serving the site. Opening a contact or sharing link connects to the destination website.

Once the page and fonts finish loading, processing works without a network connection. To check, open Network in your browser's developer tools, clear the log after loading, then try the sample, export and restoration. These operations produce no HTTP requests from the app.

MaskSheet has not undergone an independent security audit or certification. It cannot guarantee protection against malware, browser extensions, screen viewing or compromise of the hosting service or dependencies. Use a trusted device and browser.

Restore original values in an AI answer

The example above omits output IDs. Actual tokens use PERSON_outputID_001 and can be replaced with their original values using the mapping. Exactly matching strings of the same kind receive the same token across sheets. Different people with the same name are not distinguished: use customer IDs for person-level analysis.

To restore answers later, save the encrypted mapping from the export screen. Each save creates a new random 128-bit output ID in the tokens and encrypted mapping. The AI file and mapping filenames include that ID. Save the matching mapping before exporting again. Tokens belonging to a different output are left unchanged and flagged. Legacy mappings cannot verify the output and require explicit confirmation. Encryption uses AES-256-GCM and PBKDF2-SHA256 with 600,000 iterations, plus a fresh random salt and IV for each save. Use a long, unique password of at least 12 characters and store it separately. Never send the mapping to AI. Forgotten passwords cannot be recovered.

Limits to know before you use it

CSV encoding

A BOM identifies UTF-8 or UTF-16. Without a BOM, the app tries strict UTF-8, then Shift_JIS if decoding fails. This is an estimate, not a guarantee. If text looks garbled, choose an encoding under “Fix garbled CSV text” and reopen the file. Windows-1252 is available for older Western European files. Exports always use UTF-8 with a BOM.