Waqi Demo

Ask a normal question.
Leak nothing.

Nobody types card numbers at an AI — the leak happens when the AI pulls the answer from your tools, because that data arrives full of customer details. Pick a question and watch Waqi strip them out mid-flight, while you still get the answer.

Ask your AI:
How much did we make this week?

1 · What Stripe sends back

This week's payments: £950.00 Tue Visa 4242 4242 4242 4242 jane.okafor@acmeltd.co.uk £420.00 Tue Visa 4000 0566 5566 5556 dan.hurst@brightpath.io £1,262.00 Wed MC 5555 5555 5555 4444 s.malik@falconinteriors.ae · +971 50 123 4567 £2,200.00 Fri Amex 3782 822463 10005 procurement@nordicsupply.se Total: £4,832.00 across 23 charges (19 smaller charges not shown)

The highlighted parts are what would reach the AI company without Waqi.

2 · What the AI actually sees

This week's payments: £950.00 Tue Visa [CARD:aa46] [EMAIL:0537] £420.00 Tue Visa [CARD:cdcb] [EMAIL:f4b1] £1,262.00 Wed MC [CARD:f654] [EMAIL:c063] · [PHONE:1d1d] £2,200.00 Fri Amex [CARD:26e8] [EMAIL:81bf] Total: £4,832.00 across 23 charges (19 smaller charges not shown)

Waqi swaps each detail for a coded placeholder before it leaves.

3 · The answer you still getYou made £4,832 this week across 23 charges — your biggest was £950 on Tuesday, and four payments over £400 made up most of it.
Cards: 4 kept from the AIEmails: 4 kept from the AIPhones: 1 kept from the AI

Same answer your team needs — the personal details never left. The placeholders are stable, so the AI can still tell “the same customer failed three times” without ever knowing who they are. And this page runs Waqi's detection in your browser — nothing here is sent anywhere.

Check an email before you paste it into an AI

The other way data leaks: someone copies a real email or document into ChatGPT to “summarise this” or “draft a reply”. Paste that kind of thing on the left — the right shows the version Waqi would let through.

What you were about to paste

The safe version

The safe version appears here.

Not ready to buy today? Take the Pilot Pack.

The 14-day pilot checklist, the DPA, and the security model — everything you need to evaluate Waqi properly or make the case to your team.

Why this matters

Sending customer data to an AI is a disclosure you're accountable for

Under UK and EU GDPR, personal data that reaches a third-party AI provider is processing you are responsible for — whether it went there by policy or by paste. The UAE's PDPL and Cybercrime Law carry their own duties around disclosing personal and financial data. What that exposure looks like in practice:

Fines that scale with you

The most serious UK GDPR breaches can be fined up to £17.5M or 4% of worldwide annual turnover, whichever is higher (€20M / 4% under EU GDPR). For a small business the headline number matters less than the fact that the regulator sets it — not you.

The 72-hour clock

A notifiable personal-data breach must be reported to the regulator within 72 hours of you becoming aware of it. If you can't say what left the building, you can't write that report — and "we don't know what the AI saw" is not an answer an investigator accepts.

The part no insurer covers

Enforcement action is public. Customers forgive outages; they rarely forgive finding out their card details or health notes sat in a third party's AI logs. The trust you lose costs more than any fine.

To be precise about what Waqi does and doesn't do: it is a control, not a compliance certificate. It minimises the personal data your AI provider ever receives (the identifiers it detects never leave), gives every listed free-text field a one-click hard wall, and writes a per-call audit log — the evidence trail that lets you answer "what exactly did the model see?" with a record instead of a guess. Your policies, contracts, and processes remain yours to get right — Waqi makes the data-minimisation part real. Read our DPA.

In production

The real thing does more than this page

The hosted proxy runs these same rules on every tool response, plus field-aware detection (name and card-reference fields), one-click hiding of whole free-text fields, per-member links, and a per-call audit log of who asked for what and what was stripped.