> ## Documentation Index
> Fetch the complete documentation index at: https://help.honestly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What is data masking and how do I turn it on?

> Data masking automatically removes personal data from open text responses before they are processed. Learn what it masks, that it cannot be undone, and what you need before switching it on.

Data masking detects personal data in open text responses and replaces it automatically before responses are translated, classified or exported. It is available as an add-on for your account and is set up once, for all surveys, by an admin.

### What data masking does

When it is switched on, every open text response that comes in is scanned for personal data. Anything it finds is replaced with a neutral placeholder — a name becomes a name token, an email becomes an email token — before the response is translated, classified or included in an export. Everyone sees the masked response, and only the masked version is translated, classified, exported and displayed. The original text is stored separately when masking runs and cannot be retrieved through the application — there is no function that shows an automatically masked response in clear text again.

### Which data is masked

You choose which categories are masked. At least one has to be selected:

* **First name, last name**
* **Email address**
* **Phone number**
* **Postal address**
* **Unique IDs / customer numbers**

The setting applies to your whole account, not to a single survey. Every survey in the account uses the same masking configuration.

### Where to find it

Go to your account settings and open the **Data masking** tab. Only admins can see and change it.

Switch on **Automatically mask personal data**, tick the categories you want, and click **Save changes**.

### Microsoft consent is required

To detect the personal data, the response text is sent to Microsoft (Azure OpenAI). For that reason you have to allow Microsoft as a sub-processor for your account first. Until that consent is given, the masking setting stays locked and cannot be switched on.

You grant it in the **Subprocessors** tab in your account settings.

### Masking cannot be undone and is not retroactive

<Warning>
  Automatic masking cannot be undone. Once a response has been masked automatically, there is no way back to the original text in the application.
</Warning>

Only responses that come in while masking is active are masked. Switching it on later does not change responses that were already collected — those keep their original text. For a survey's open responses to be masked, the setting has to be active before those responses are submitted.

### Data masking and anonymity are separate

The two controls do different things and work independently:

* The **anonymity threshold** decides whether a response is shown at all.
* **Data masking** removes personal details from inside a response that is shown.

A response can be visible because the anonymity threshold is met and still have its personal data masked. For how the anonymity thresholds work, see [Open-text anonymity](/help/dashboard/open-text-anonymity).
