Security: what stays on your device
Updated on 29 September 2026
In short
- Your documents are processed in your browser. They are never sent to a server, including for the AI features.
- Nothing leaves your device during processing. You can check this with your browser's Network panel or by going offline.
- The restore key is encrypted on your device and stays there.
- The tool assists you. Review is mandatory, and the result remains your responsibility.
How the tool works
When you open Localex, your browser downloads the page and its code from the site's own domain. From then on, everything happens on your device:
- reading the file and extracting the text;
- detecting the data to mask;
- replacing it with the strategies you chose;
- review, leak scan and export.
The heavy work (reading PDFs, detection, text recognition, AI) runs in Web Workers: separate threads inside your browser. They pass their results only to the page.
Your documents stay in the tab's memory. Closing the tab erases them. In case-file mode (an unlocked feature), files can be kept in the browser's storage (IndexedDB). They are deleted automatically after 24 hours, and you can delete them sooner.
The AI features also run on your device. The model files are downloaded once, from the site's own domain, then kept in the browser's cache. No online AI is called and no content is sent to any API.
The site's Content Security Policy only allows the page to connect to the site's own domain. No third-party script is loaded: no analytics, no advertising, no widgets. You can read the policy in the page's response headers: Network panel, first request, Content-Security-Policy header.
What leaves your device, and when
| When | What is sent | Recipient |
|---|---|---|
| Processing a document | Nothing | · |
| Opening a page | An ordinary request: IP address, browser, page requested | The site's host (Hostinger, servers in the EU) |
| When you leave the page | Usage counters: totals, for example "one document processed, PDF format", with no content and no identifier | Avlex's registry, through our server |
| Unlocking, at your request | Your e-mail address, the consents you tick, the optional fields you fill in, your phone number if you accept the call | Avlex's registry, through our server |
| Downloading an AI file | Your licence token, nothing else | Our server, which checks the licence with Avlex's registry |
| Preferences page | Your preference token and your choices | Avlex's registry, through our server |
Unlocking only happens if you ask for it. The confirmation e-mail is sent by Avlex. The data and retention periods are set out in the privacy notice.
Check it yourself
You do not have to take our word for it. Two tests are enough, with no special software.
With the browser's Network panel
- Open the tool on the home page.
- Open the developer tools:
F12orCtrl+Shift+I(Windows),Cmd+Option+I(Mac). Select the Network panel. - Tick Preserve log, then clear the list.
- Load a document, run the detection, review and export.
Look at the list:
- every request goes to the site's own domain;
- none contains your document, its text or the detected data;
- if a request to
/api/metricsappears, open it: its Payload contains counters only.
Offline test
- Open the tool while online. First process a test document of the same format: some parts of the code are only loaded on first use.
- Go offline: turn off Wi-Fi, unplug the cable or select Offline in the Network panel.
- Load your document, process it and export it.
Processing succeeds without a network, because it depends on no server. Only unlocking and the first download of the AI files need a connection.
What the "0 bytes sent" meter measures
The meter adds up what the page sends while a document is being processed. It stays at 0 because processing sends nothing. The page computes it itself: it is an indicator, not proof. The two tests above do not depend on us.
Leak scan and hidden data
Before every export, the tool re-reads the file it produced, not the preview on screen. It searches it for every original value and its variants:
- DOCX: every part of the file, including headers, footers, footnotes, comments, document properties (
docProps) and custom data (customXml); - PDF: all text and the metadata.
The result is "0 leaks", or a list of occurrences that blocks the export until they are fixed.
The scan looks for the values the tool knows: those it detected and those you added. It cannot find data that was never spotted. That is why review remains mandatory.
The tool also cleans hidden data:
- DOCX: comments, tracked changes (accepted or rejected, as you choose), author and company metadata, thumbnails;
- PDF: Info and XMP metadata, annotations, attachments, form fields;
- images: EXIF data.
Images embedded in a document are flagged. You can extract their text with OCR (an unlocked feature), remove them, or keep them with a warning. Text inside an image is only scanned if it was extracted with OCR.
True redaction of PDFs
Fake redaction draws a black box over the text. The text is still underneath: it can be selected, copied or searched.
Localex never does this. It offers two PDF exports:
- Text PDF: the document is rebuilt from the pseudonymised text. The text stays selectable; the original values are no longer in it.
- Redacted PDF, original layout: each page is turned into an image, the masked areas are blacked out in the image, and no text layer is kept. The text is therefore no longer selectable, and the file is larger.
In both cases, the leak scan runs before the export.
The restore key
In pseudonymisation mode, the tool replaces each item with a token, for example [PERSON_1]. The table linking tokens to original values forms the restore key.
- Encryption: AES-GCM, 256-bit, through the browser's WebCrypto API.
- Passphrase: the encryption key is derived from your passphrase with PBKDF2-SHA-256, using 600,000 iterations.
- Storage: you save the key file to your disk. You can also keep it in the browser for the session. It is never sent.
- Restoring: on the Restore page, paste the AI's answer, load the key and enter the passphrase. The original values are put back on your device. Tokens the AI altered, for example
[PERSON 1], are recognised and flagged.
If you lose the key or forget the passphrase, restoring is impossible. We have no copy and cannot rebuild it.
Keep the key separate from the pseudonymised text: that separation is what protects the people concerned.
Pseudonymisation or anonymisation
- Pseudonymisation: data is replaced with tokens, and a key lets you go back to the original. For you, as the holder of the key, the pseudonymised text remains personal data, and the GDPR still applies (GDPR, Article 4(5) and Recital 26; EDPB, Guidelines 01/2025 on Pseudonymisation, adopted on 16 January 2025 for public consultation).
- Anonymisation: no key is produced and the replacements are irreversible. Data is anonymous only if no one can reasonably identify the person any more, including by combining it with the context. A document can remain identifying without a single name: a rare profession, a small municipality, a well-known event.
The Court of Justice has clarified that identifiability is assessed according to the means reasonably available to each recipient (judgment of 4 September 2025, C-413/23 P). This changes nothing for you: you hold the key.
Limits
- No detection is exhaustive. Rules, lists and AI models can miss an item, or flag one wrongly.
- Human review is mandatory before any export. It cannot be switched off.
- The tool does not check the legal content of an AI answer.
- The security of your device, your browser and its extensions is outside the tool's reach. An extension can read the content of a page: use an up-to-date browser and keep extensions to a minimum.
- Processing is local, but the page and its code come from our server on every visit. The tests above let you check what they do.
The bars' AI guidelines
In January 2025, the Flemish Bar (Orde van Vlaamse Balies, OVB) and AVOCATS.BE (the French- and German-speaking bars, OBFG) published the same guidelines on lawyers' use of AI. In March 2026, the French-speaking Brussels Bar (OFABB) proposed a model AI charter for law firms.
These texts are addressed to you: you meet them, and the tool helps. The table shows, for each relevant requirement, what the tool does and what remains your responsibility. Localex is designed following these guidelines. Neither the OVB, AVOCATS.BE nor the OFABB has assessed or recommended the tool. The quotations below are our translations.
| What the texts ask | How the tool helps | What remains your responsibility |
|---|---|---|
| The lawyer pseudonymises personal data and does not enter personal data in prompts, inputs or documents submitted to AI tools (guidelines, point 1.2). | Detection of names, addresses, dates and Belgian identifiers validated by their check digits, among others. Every category is ticked by default. Consistent tokens, one-click copy for AI, then local restore. | Reviewing each document, adding what was missed, and submitting only the pseudonymised text to the AI. |
| Never enter documents or information covered by professional secrecy or a duty of confidentiality in an AI tool, unless working in a closed environment with adequate safeguards (point 1.2). No use of AI may reveal, even indirectly, information covered by professional secrecy (OFABB charter, point 2). | Processing happens on your device, AI features included: the document goes to no one. The re-identification risk analysis (an unlocked feature) flags what identifies indirectly: a rare profession, a small municipality, an exact amount. | Professional secrecy covers facts, not just names. Judging whether the pseudonymised text may be submitted to an external AI tool, and whether that tool offers the required safeguards. |
| Read the AI tool's terms of use carefully: training, transfer and storage, location of processing, open or closed system, liability, licences (point 1.1). Only use tools with sufficient safeguards (OFABB charter, point 3). | How Localex works is described on this page and can be checked: no document stored or sent, no training on your documents, processing in your browser. See also the terms of use. | Reviewing the terms of the external AI tool (ChatGPT, Copilot or another). Localex does not assess them. |
| Limit the data submitted to the AI tool or pseudonymise it; without adequate safeguards, refrain (OFABB charter, point 4). | Masking options per category; generalisation of dates, amounts and places; one preset for AI use and one for publication. | Choosing the level of masking suited to the case and to the AI tool used. |
| The lawyer checks the output, including the sources cited (point 1.1). Mandatory review, and no copy-and-paste without checking (OFABB charter, points 6 and 7). | Mandatory review before export, leak scan, flagging of altered tokens when restoring. | Checking the substance of the AI's answer: reasoning, legislation, legal writing and case law cited. |
| The lawyer always remains ultimately responsible for the output of the AI they use (point 1.3; OFABB charter, point 8). The use of AI must be explainable and traceable within the firm (OFABB charter, points 2 and 5). | The pseudonymisation certificate (an unlocked feature) records the processing without any personal data: categories, counts, strategies, SHA-256 hash of the file, date and tool version. | Standing behind the result and tracing the use of AI under your firm's rules. |
| Know the basics of AI and large language models (point 1.1). | The guides explain pseudonymisation, anonymisation and how to use the tool with AI. | Training, as part of your continuing professional development obligations. |
Sources:
- OVB, Richtlijnen voor advocaten voor het gebruik van Artificiële Intelligentie, 20 January 2025, Dutch and French text.
- AVOCATS.BE, Lignes directrices à l'intention des avocat(e)s sur l'utilisation de l'intelligence artificielle, published on 31 January 2025.
- OFABB, Charte d'utilisation responsable des outils d'intelligence artificielle, proposed model, March 2026.