Everyone pastes screenshots, logs, PDFs and recordings into tickets, chats and AI assistants, and they leak secrets and personal data. cleanroom-ai is six free tools that clean those files first. The OCR, speech and PII models all run in your browser tab, so the file you are protecting never leaves your device.
🕶️ Screenshot Redactor API keys, passwords, emails, cards, names, faces & QR codes in screenshots |
🧽 Log Scrubber tokens, cookies & PII in logs, .env, JSON and HAR files, structure-aware
|
📄 PDF Redactor true redaction: flattens pages, then verifies no hidden text survives |
🔊 Audio Redactor bleeps names, phone & card numbers with Whisper running in the tab |
📷 Photo Share-Safe strips GPS & hidden EXIF, blurs faces and license plates |
🎬 Video Redactor tracks keys, names & faces through screen recordings, re-encodes WebM |
The live badge is a weekly GitHub Actions job that opens the published Hugging Face Space in a real browser, runs the example end to end, and fails if a single request leaves the page.
How do you know nothing is uploaded?
- Strict Content-Security-Policy. Each page may only connect to its own origin (plus Hugging Face's CDN for the Space's own model files), so the browser itself blocks any other destination.
- Everything is bundled. Models, WASM runtimes and libraries ship inside the Space: no third-party CDNs, fonts, analytics or accounts.
- CI that fails on any leak. A real-browser test records every network request and fails the build on any upload, any non-GET request or any third-party host, first against localhost and then against the live Space.
- Redaction is verified, not assumed. PDFs are flattened and then re-scanned to confirm no text remains, and videos are re-OCR'd after encoding to prove that none of the redacted items can still be read.
- Shared, tested engine. All six tools run on
@cleanroom-ai/core: checksum-validated secret and card rules, entropy checks, a PII NER model, PP-OCRv6 and YuNet faces.
Maintained by Parag Sawant · parags.dev





