What Rule 1.6 actually requires

Rule 1.6(c) obligates attorneys to make "reasonable efforts to prevent the inadvertent or unauthorized disclosure of information relating to the representation of a client." Submitting a prompt that contains a client's name, case number, or any identifying detail to ChatGPT sends that data to OpenAI's servers. That transfer is the disclosure the rule addresses.

"Reasonable efforts" does not require a perfect solution — it requires a deliberate safeguard commensurate with the sensitivity of the information. Bar disciplinary bodies assess whether the attorney took a step appropriate to the known data practices of the tool and the nature of the client information involved.

The problem with manual redaction

Most attorneys who are careful about this try to remove sensitive details by hand before pasting into ChatGPT. In practice, that approach fails: it is time-consuming, applied inconsistently under deadline pressure, and one missed identifier away from a disclosure.

It also misses non-obvious identifiers — a combination of city and injury type in a malpractice matter, a financial figure distinctive enough to identify the deal, a case number that looks like a date — that an attorney scanning quickly will overlook. Manual redaction is effort-dependent in a way that on-device automation is not.

The on-device safeguard approach

Naosuu intercepts every ChatGPT prompt before it leaves the browser. It detects client names, case numbers, SSNs, dates, addresses, and financial figures using a combination of regex patterns and a local NER model — and replaces each with a placeholder like [PERSON_1] or [CASE_NO_1].

ChatGPT responds to the anonymized version. Naosuu restores the real values in the response before the attorney reads it. Nothing identifying ever reaches OpenAI's servers. The workflow is identical to using ChatGPT normally — the protection is invisible.

Frequently asked questions

Does OpenAI store ChatGPT conversations?
Yes, by default. OpenAI logs conversations and may use them to improve its models. Opting out in settings reduces training use but does not eliminate server-side processing of the prompt. That transit is the exposure Naosuu eliminates.
Can a firm ban ChatGPT to avoid the issue entirely?
They can, but the ban is routinely ignored. Attorneys use personal devices and personal accounts. A technical safeguard that works wherever the attorney works is more effective than a policy that assumes compliance.
Does this apply to Claude and Gemini as well?
Yes. The same Rule 1.6 analysis applies to any commercial AI service that receives a prompt — including Claude (claude.ai) and Google Gemini. Naosuu protects all three platforms automatically with the same on-device redaction workflow.

Automatic redaction for every prompt

Naosuu intercepts ChatGPT, Claude, and Gemini prompts on your device, strips identifying client data, and restores it in the response. 30-day free trial, no credit card required.

Start free trial