In development A privacy demonstrator by Amazed Labs

AI gets what it needs. Nothing more.

LimitID is a local macOS console that keeps your sensitive values on your Mac while you draft with AI.

It detects sensitive values as you write, replaces them with reversible aliases, shows you exactly what would leave the machine, and restores your real values into the answer locally. The AI endpoint you configure only ever sees cloaked text.

LimitID is an experimental demonstrator in active development. It is not a public download today and it is not a compliance tool.


How it works

Local transform, cloaked outbound, local restoration

Three steps, in the order the product performs them. The real values you type and the map back to them never leave your Mac.

1

Local

Everything you type — and the map from each alias back to its real value — stays on your Mac, in memory only. Nothing sensitive is written to disk or logs.

2

Cloaked outbound

When you send, only the cloaked text — typed aliases in place of sensitive values — can leave the Mac. You review exactly what would be sent, first.

3

Local restoration

The reply comes back with aliases, and LimitID restores your real values on this Mac. A reply that forges or drops an alias is withheld, fail-closed.

On your Mac (never sent)

Draft a letter for Jane Roe, SSN 123-45-6789, at 250 Market St.

Cloaked text (all that can leave)

Draft a letter for ⟦WC:NAME:0001⟧, SSN ⟦WC:SSN:0002⟧, at ⟦WC:ADDR:0006⟧.

The aliases are reversible: the alias → value map is held in memory on your Mac so the answer can be restored locally. That same reversibility means this is not de-identification — real values are recoverable, on your Mac, by design. (⟦WC:…⟧ is the product's stable internal alias format.)


What stays local

The boundary is visible, and it is narrow

LimitID treats the AI endpoint as untrusted. Only cloaked text crosses the boundary; the values and their map stay behind it.

Stays on your Mac

  • The real sensitive values you typed.
  • The alias → value map used to restore the answer.
  • Your original draft, held in memory only — not written to disk or logs.
  • Any endpoint bearer token: kept in the macOS Keychain, sent only in the request's authorization header.

There is no LimitID backend, account, or billing system — no data is sent to us.

Can leave the Mac

  • Only the cloaked text — with aliases where sensitive values were.
  • Only after you review the exact outbound at the send step.
  • Only to an OpenAI-compatible endpoint you configure and control (a local model, or an https endpoint you run or trust).

By default LimitID runs a fully offline demo — no network at all. Sending anywhere is opt-in and off until you configure it.


The demonstrator

Real screens from the macOS build

These are captures of the in-development app running its offline demo with synthetic sample data — not mockups.

LimitID review screen: category chips for SSN, Email, Phone, Date, Street address, Account and Person name, above a monospaced outbound preview where each sensitive value has been replaced by a bracketed alias token, with a Send Cloaked button.
Review before sending. Category counts and the exact cloaked outbound — the only text that can leave — with a best-effort person-name notice.
LimitID conversation screen showing a user prompt and the AI reply with the real names, SSN, email, phone, date and account values restored locally on the Mac.
Restored locally. The reply is shown with your real values substituted back in from the in-memory map on your Mac.
LimitID first-run explainer describing three steps: Local, Cloaked outbound, and Local restoration, plus notes that it runs a fully offline demo by default and operates no backend, account or billing system.
First-run explainer. The same three-step journey, stated plainly, with the offline-by-default and no-backend facts up front.
LimitID Provider Setup screen with an endpoint URL field, optional model id, and a bearer-token field labelled never shown once stored, with the note that the token lives only in the macOS Keychain.
Provider setup. Point LimitID at an endpoint you control. The token lives only in your Keychain; only cloaked text is sent.

Screens use synthetic sample values only. No real personal data appears in the product or on this site.


Honest limits

What LimitID is not

Restraint and honest limits are the point. LimitID reduces the surface area of one specific risk — pasting sensitive text into cloud AI — and nothing more.

Detection is pattern-based

It uses deterministic rules, not a learned model. It is not exhaustive and can miss values, especially adversarial or unusual ones.

Person-name detection is best-effort

Names and organizations are the hardest to catch and are treated as best-effort. The review step asks you to verify before sending.

Aliases are reversible

The alias → value map is kept so the answer can be restored. This is not de-identification, and it is not a promise that content cannot be traced back.

Not a compliance or certification tool

It holds no certification and makes no regulatory-readiness claims. It is not a substitute for professional legal, security, or privacy review.

Text only, honest posture

It reads text, not images, audio, or files, and cannot protect content from a compromised Mac. It does not promise that nothing leaks.

Experimental and in development

Behavior, coverage, and availability may change. There is no measured performance claim, no customer claim, and no production availability.


In development

Where the project is today

LimitID is an early macOS demonstrator built and verified on the developer's Mac. It is honest about its stage.

  • A working SwiftUI macOS console — a real engine, not a static mock.
  • Not currently offered as a public download.
  • Runs a fully offline demo by default; sending is opt-in.
  • No backend, account, sign-in, or billing system.
  • Developer ID signing and notarization are not yet in place.
  • No third-party certification and no compliance claims.

From the studio

Built by Amazed Labs

LimitID is a privacy project from Amazed Labs — a small studio making useful, honest, humane software. It shares the studio's posture: build with restraint, state the limits plainly, and ship only what is true.

  • Warm and useful
  • Restraint and honest limits
  • Privacy kept local by design

Learn about the studio and its other work at amazedlabs.org.


Get in touch

Questions about LimitID, or interested in following its development? Email is the only channel — there are no forms, sign-ups, or trackers here.

[email protected]