{"id":51629972,"url":"https://github.com/adityaarsharma/shush","last_synced_at":"2026-07-13T06:30:28.517Z","repository":{"id":370421584,"uuid":"1294700531","full_name":"adityaarsharma/shush","owner":"adityaarsharma","description":"Remove PII \u0026 secrets from any file before you paste it into ChatGPT or Claude — a 100% local PII redaction CLI. No network, no AI. 89 detectors across 20+ countries.","archived":false,"fork":false,"pushed_at":"2026-07-09T07:01:18.000Z","size":23,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-09T08:11:14.466Z","etag":null,"topics":["ai-safety","anonymization","chatgpt","cli","command-line","data-anonymization","data-privacy","dlp","gdpr","gdpr-compliance","hipaa","llm","openai","pii","privacy","python","redaction","secret-scanning","secrets","security"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/adityaarsharma.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-09T06:09:27.000Z","updated_at":"2026-07-09T07:01:09.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/adityaarsharma/shush","commit_stats":null,"previous_names":["adityaarsharma/shush"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/adityaarsharma/shush","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/adityaarsharma%2Fshush","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/adityaarsharma%2Fshush/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/adityaarsharma%2Fshush/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/adityaarsharma%2Fshush/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/adityaarsharma","download_url":"https://codeload.github.com/adityaarsharma/shush/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/adityaarsharma%2Fshush/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35413537,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-13T02:00:06.543Z","response_time":119,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ai-safety","anonymization","chatgpt","cli","command-line","data-anonymization","data-privacy","dlp","gdpr","gdpr-compliance","hipaa","llm","openai","pii","privacy","python","redaction","secret-scanning","secrets","security"],"created_at":"2026-07-13T06:30:22.860Z","updated_at":"2026-07-13T06:30:28.502Z","avatar_url":"https://github.com/adityaarsharma.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003e🤫 Shush\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\u003cb\u003eHush your files before you hand them to an AI.\u003c/b\u003e\u003cbr\u003e\nStrip PII \u0026amp; secrets from any file before you paste it into ChatGPT, Claude, Gemini, or Copilot.\u003cbr\u003e\n100% local · no network · no AI · no signup.\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://github.com/adityaarsharma/shush/actions/workflows/ci.yml/badge.svg\" alt=\"tests\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/license-MIT-green\" alt=\"MIT License\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/python-3.8+-blue\" alt=\"Python 3.8+\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/dependencies-0_core-brightgreen\" alt=\"Zero core dependencies\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/detectors-89-orange\" alt=\"89 detectors\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/network-none-red\" alt=\"No network\"\u003e\n\u003c/p\u003e\n\n---\n\n\u003e **You wouldn't commit your `.env` to GitHub. Stop pasting it into ChatGPT.**\n\nA free command-line tool that strips personal data, passwords, and API keys out of your files before you share them with an LLM. Point it at a file, folder, or zip — get a clean copy back. Nothing ever leaves your machine.\n\nShush is a **terminal command** (not a chatbot, not a website). You run it on your own computer — Mac Terminal, Windows PowerShell, or Linux shell. It reads a file, a folder, or a zip, replaces every sensitive value with a safe placeholder like `[EMAIL]`, `[IP]`, `[API_KEY]`, `[NATIONAL_ID]`, and writes a clean copy you can safely paste into **ChatGPT, Claude, Gemini, Copilot, DeepSeek, or a local Llama model.** Nothing ever leaves your machine.\n\n**Keywords:** PII redaction · data anonymization · remove sensitive data before AI · sanitize logs for ChatGPT · strip API keys · GDPR · India DPDP · LGPD · CCPA · PDPA · POPIA · PIPL · HIPAA · secret scanner · CLI · offline · privacy.\n\n---\n\n## Why you need this (the real, everyday problem)\n\nEvery day, developers and support teams paste real data into AI tools to *\"summarize this\"* or *\"help me fix this\"* — and hand a third-party company their customers' private data without realizing it.\n\nHere's what people actually dump into ChatGPT, and what leaks each time:\n\n| What people paste into AI | What secretly leaks | Shush replaces it with |\n|---|---|---|\n| **A support ticket** (\"customer can't log in…\") | customer name, email, phone, order/account ID, sometimes their password | `[NAME] [EMAIL] [PHONE] [USER_ID] [PASSWORD]` |\n| **A server / error log** | IP addresses, file paths, hostnames, session tokens | `[IPV4] [FILE_PATH] [DOMAIN] [JWT]` |\n| **A database dump / CSV export** | thousands of emails, phones, national IDs, card numbers | `[EMAIL] [PHONE] [NATIONAL_ID] [CREDIT_CARD]` |\n| **A `.env` or config file** | DB passwords, AWS/Stripe/OpenAI keys, connection strings | `[PASSWORD] [AWS_KEY] [DB_URL] [OPENAI_KEY]` |\n| **A stack trace / bug report** | internal URLs, auth headers, user records | `[URL] [GENERIC_KEY] [EMAIL]` |\n| **A spreadsheet of customers / leads** | names, emails, phones, addresses, tax IDs | `[NAME] [EMAIL] [PHONE] [STREET_ADDR] [TAX_ID]` |\n| **A copied email thread** | sender/recipient identities, signatures, phone numbers | `[NAME] [EMAIL] [PHONE]` |\n\nUnder data-protection laws almost everywhere — the EU's **GDPR**, India's **DPDP Act**, Brazil's **LGPD**, California's **CCPA/CPRA**, and a dozen more (full list below) — sending that data to a third party can be a reportable breach. Most people doing it have no idea. The usual \"fix\" is a policy nobody reads, or an enterprise DLP suite that costs five figures. Shush is the one-command version you can run yourself, offline, and actually read in five minutes.\n\n---\n\n## What it removes — 89 detectors across 20+ countries\n\nModelled on the taxonomies used by Microsoft Presidio, AWS Comprehend, Google Cloud DLP, and HIPAA's 18 identifiers — then deliberately extended so it works for people everywhere, not only in the countries those tools were built around. National IDs are listed **A–Z by country**; no jurisdiction gets special billing.\n\n| Category | Examples caught |\n|---|---|\n| **Contact / personal** | emails, intl phone numbers, names (salutations \u0026 `From:/Name:` labels), dates of birth, age, usernames/logins, street addresses, ZIP/postal codes |\n| **Network / infra** | IPv4, IPv6, MAC addresses, URLs, domains, file paths (`/home/…`, `C:\\Users\\…`), GPS coordinates |\n| **Credentials** | passwords, API keys, bearer/OAuth tokens, JWTs, SSH \u0026 PGP private keys, `.env` secrets, DB connection strings |\n| **Cloud keys** | AWS, GCP, GitHub, Slack, Stripe, OpenAI, Twilio, SendGrid, Google OAuth |\n| **Financial** | credit cards, CVV, PIN, IBAN, SWIFT/BIC, bank account \u0026 routing numbers, BTC \u0026 ETH addresses |\n| **National IDs (A–Z)** | 🇦🇺 Australia (TFN, ABN) · 🇧🇩 Bangladesh (NID) · 🇧🇷 Brazil (CPF, CNPJ) · 🇨🇦 Canada (SIN) · 🇨🇳 China (resident ID) · 🇫🇷 France (INSEE/NIR) · 🇮🇳 India (Aadhaar, PAN, + 4 more) · 🇮🇩 Indonesia (NIK/KTP) · 🇮🇹 Italy (Codice Fiscale) · 🇯🇵 Japan (My Number) · 🇲🇽 Mexico (CURP, RFC) · 🇳🇬 Nigeria (NIN, BVN) · 🇵🇰 Pakistan (CNIC) · 🇸🇬 Singapore (NRIC) · 🇿🇦 South Africa (ID) · 🇰🇷 South Korea (RRN) · 🇪🇸 Spain (NIF/DNI) · 🇹🇷 Türkiye (TC Kimlik) · 🇦🇪 UAE (Emirates ID) · 🇬🇧 UK (NHS, National Insurance) · 🇺🇸 USA (SSN, ITIN) · + generic passport / driver's licence / tax ID |\n| **Health** | Medicare number, medical record number (MRN), patient ID |\n| **Vehicle / device** | VIN, licence plates, IMEI |\n| **Identifiers** | UUIDs, user/customer IDs, long numeric IDs |\n\nBias is **fail-closed**: when a value is ambiguous, it redacts. Over-redaction is safe; a leak is not.\n\nDon't see your country's ID? [Open an issue or PR](https://github.com/adityaarsharma/shush/issues) — adding one is a single line + a test. The goal is genuinely global coverage.\n\n---\n\n## Legal \u0026 compliance\n\nNearly every country now has a data-protection law that makes you responsible for personal data you hold — and pasting it into a third-party AI service is a *disclosure* to that service. Shush is a practical **technical safeguard** (\"data minimisation\" / \"pseudonymisation\") that helps you avoid that disclosure in the first place. Laws it's relevant to, A–Z by region:\n\n| Region | Law | Shush helps you with |\n|---|---|---|\n| 🇦🇺 Australia | Privacy Act 1988 / Australian Privacy Principles | not disclosing personal information to an overseas processor |\n| 🇧🇷 Brazil | **LGPD** (Lei Geral de Proteção de Dados) | minimising personal data before third-party processing |\n| 🇨🇦 Canada | **PIPEDA** | limiting collection/disclosure to third parties |\n| 🇨🇳 China | **PIPL** (Personal Information Protection Law) | avoiding cross-border transfer of personal information |\n| 🇪🇺 EU / 🇬🇧 UK | **GDPR** / UK GDPR | data minimisation (Art. 5), pseudonymisation (Art. 32) |\n| 🇮🇳 India | **DPDP Act 2023** | limiting processing of personal data by a Data Fiduciary |\n| 🇯🇵 Japan | **APPI** | restricting third-party provision of personal data |\n| 🇰🇷 South Korea | **PIPA** | limiting provision of personal information to third parties |\n| 🇳🇬 Nigeria | **NDPA 2023** | lawful, minimised processing of personal data |\n| 🇸🇬 Singapore | **PDPA** | limiting disclosure and cross-border transfer |\n| 🇿🇦 South Africa | **POPIA** | minimality + limiting further processing |\n| 🇦🇪 UAE | **PDPL** | controlling cross-border personal-data transfers |\n| 🇺🇸 USA | **CCPA/CPRA** (California), **HIPAA** (health), **GLBA** (financial) | not sharing personal/health/financial data with a third party |\n\n\u003e **Not legal advice, and not a compliance certification.** Shush is an engineering control that *reduces* risk by keeping sensitive data on your machine. It does not make you compliant on its own, and — because free-form data is messy — it cannot guarantee 100% capture. For regulated data (health, financial, children's, biometric, or any large-scale personal data), have your privacy/DPO/compliance owner review your process, and always spot-check Shush's output before sharing. Use of this tool is at your own risk, under the [MIT license](LICENSE) (provided \"as is\", no warranty).\n\n---\n\n## How to run it in your terminal (step by step)\n\nShush runs in a **terminal / command line**. You don't install an app or sign into anything. If you've never used a terminal, follow your OS below exactly.\n\n### Step 0 — Check you have Python (once)\n\nShush needs Python 3.8 or newer (Macs and most Linux already have it).\n\n```bash\npython3 --version\n```\n\nIf that prints something like `Python 3.11.x`, you're ready. If it says \"command not found\", install Python from [python.org/downloads](https://www.python.org/downloads/) (on Windows, tick **\"Add Python to PATH\"** during install).\n\n### 🍎 macOS — Terminal or iTerm\n\n1. Open **Terminal** (press `Cmd + Space`, type \"Terminal\", hit Enter). iTerm works identically.\n2. Get Shush and go into its folder:\n   ```bash\n   git clone https://github.com/adityaarsharma/shush.git\n   cd shush\n   ```\n   (No git? Download the ZIP from GitHub, unzip it, then in Terminal type `cd ` and drag the unzipped folder onto the window.)\n3. Run it on your file:\n   ```bash\n   python3 shush.py ~/Downloads/support-ticket.docx\n   ```\n   You'll get `support-ticket.scrubbed.txt` right next to it — that's the safe copy.\n\n### 🪟 Windows — PowerShell or Command Prompt\n\n1. Open **PowerShell** (Start menu → type \"PowerShell\" → Enter).\n2. Get Shush:\n   ```powershell\n   git clone https://github.com/adityaarsharma/shush.git\n   cd shush\n   ```\n3. Run it (on Windows the command is usually `python`, not `python3`):\n   ```powershell\n   python shush.py C:\\Users\\You\\Downloads\\export.csv\n   ```\n\n### 🐧 Linux — any shell\n\n```bash\ngit clone https://github.com/adityaarsharma/shush.git \u0026\u0026 cd shush\npython3 shush.py /path/to/logs.txt\n```\n\n### The four ways to use it\n\n```bash\npython3 shush.py ticket.docx                 # one file  -\u003e ticket.scrubbed.txt\npython3 shush.py ./exports  ./clean          # a whole folder (recurses) -\u003e ./clean\npython3 shush.py company-dump.zip  clean     # a zip      -\u003e clean.zip\npython3 shush.py data.csv --report           # DRY RUN: just show what it WOULD remove, write nothing\n```\n\nThen open the `.scrubbed` copy, **spot-check it**, and paste *that* into ChatGPT / Claude / any LLM. Done.\n\n\u003e 💡 **Tip:** run `--report` first on a sensitive file to see the counts of what it found before you trust the output.\n\n---\n\n## Supported file types\n\nWorks out of the box with **no extra install** (Python standard library only):\n\n`.txt .md .log .csv .tsv .json .yaml .yml .html .xml .ini .conf .env .sql` and common source files, plus **`.docx`** (Word).\n\nAdd PDF and Excel with one command:\n\n```bash\npip install pypdf openpyxl     # enables .pdf and .xlsx\n```\n\nZip in → zip out. Folders recurse. Unreadable files are **skipped, never emitted raw** (fail-closed).\n\n---\n\n## What a run looks like\n\nInput (`ticket.txt`):\n```\nFrom: Sarah Johnson \u003csarah.j@acmecorp.com\u003e\nCustomer ID: 88452019\nServer 10.0.0.42 at /home/deploy/app is down.\nDB: postgres://admin:s3cr3tpass@db.internal:5432/prod\nCard 4111 1111 1111 1111.  CVV: 123\nPassword: hunter2secret\n```\n\nCommand:\n```bash\npython3 shush.py ticket.txt --report\n```\n\nOutput (`ticket.scrubbed.txt`):\n```\nFrom: [NAME] \u003c[EMAIL]\u003e\n[USER_ID]\nServer [IPV4] at [FILE_PATH] is down.\nDB: [DB_URL]\nCard [CARD_SPACED].  [CVV]\n[PASSWORD]\n```\n\nThe sentence still makes sense to the AI — *\"a server is down, a card payment failed\"* — but every identity is gone. It also writes a `_shush_report.json` listing exactly what was removed.\n\n---\n\n## How it works (and why it's safe)\n\n1. **Extract** the plain text from each file (Word/PDF/Excel formatting is discarded).\n2. **Redact** every match, swapping it for a **sentinel** so a later pattern can never re-match an already-inserted placeholder.\n3. **Restore** sentinels to readable `[LABEL]` placeholders.\n4. **Write** the clean copy + a JSON report of what was removed.\n\nBecause it's plain regex running locally, **your data never touches a network or an AI model.** No API key, no telemetry, no cloud. Air-gap your laptop and it still works. You can read the entire tool in a few minutes — no black box.\n\n---\n\n## Honest limitations (read this — it's why you can trust it)\n\n- **Regex, not magic.** It catches *structured* PII reliably (emails, IPs, keys, cards, national IDs). Free-form names buried in prose are the one thing regex can't guarantee — it catches names in salutations and `From:/Name:` labels, and you should **spot-check** the output before sharing anything sensitive.\n- **Not legal advice.** This is an engineering tool that dramatically reduces risk. For regulated data (health, financial, children's, biometric, or any personal data under GDPR / DPDP / LGPD / CCPA / and the rest), have your privacy/compliance owner review before sharing externally.\n- Tools that claim to catch *everything* are the ones nobody who's been burned will trust. Shush tells you exactly what it did.\n\n---\n\n## FAQ\n\n### How do I remove personal data before pasting into ChatGPT?\nRun Shush on the file first: `python3 shush.py yourfile.txt`. It writes a `.scrubbed.txt` copy with every email, phone, ID, key, and card replaced by a placeholder. Paste *that* into ChatGPT instead of the original.\n\n### Is it safe to paste support tickets or logs into ChatGPT / Claude?\nNot as-is — tickets and logs almost always contain customer emails, IPs, and sometimes passwords or keys, and pasting them sends that data to a third party. Scrub them first so only the redacted version leaves your machine.\n\n### Does Shush send my data anywhere?\nNo. It's plain regex running locally — no network calls, no API key, no telemetry, no cloud. Turn off your Wi-Fi and it still works.\n\n### How is this different from an enterprise DLP tool?\nDLP suites cost five figures, need a security team, and run as a black box you rent. Shush is a single ~600-line Python file you can read in five minutes, own, and extend — free, MIT-licensed.\n\n### Does it work with local LLMs like Llama or Ollama?\nYes. Shush doesn't care which model you use — it cleans the file *before* it reaches any AI, ChatGPT / Claude / Gemini / Copilot / a local model alike.\n\n### Which countries' IDs does it detect?\n20+ so far — see the [detector table](#what-it-removes--89-detectors-across-20-countries) above. Missing yours? It's a one-line PR.\n\n---\n\n## Development \u0026 tests\n\nThere's a full stdlib test suite (no pytest needed) — because for a redaction tool, a regression *is* a leak. Every test asserts both that the secret is gone **and** that it got the right label.\n\n```bash\npython3 -m unittest discover -s tests -v     # 38 tests, runs in \u003c1s\n```\n\nCI runs the suite + a live CLI smoke test on Python 3.8–3.12 on every push and PR.\n\n## Contribute a pattern (especially your country's IDs)\n\nFound a PII type it misses — a national ID, a bank format, a vendor key? Add one line to `PATTERNS` in `shush.py`, add a test case in `tests/test_shush.py`, and open a PR. Coverage for more countries is explicitly welcome — the goal is a redaction tool that works for the whole world, wherever you and your users happen to be.\n\n---\n\n## License\n\nMIT — see [LICENSE](LICENSE). Use it, fork it, ship it inside your company. If it stops one data leak, it did its job.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fadityaarsharma%2Fshush","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fadityaarsharma%2Fshush","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fadityaarsharma%2Fshush/lists"}