Where the settings live
Open Settings and select Privacy under the Workspace heading. Only members with the Manage organization permission see this page, which means Admins. See Roles and permissions. Use Enable protection, Protected data, Protection method, and Protected value format to configure protection. Changes take effect when you select Save changes. The save is written to the audit log as an organization settings change.What Tars checks
With protection on, Tars checks these values before it stores them:- Messages that end users send in a conversation.
- Answers that end users give to questions in a flow.
- Answers that end users submit in a form that the agent shows in the conversation.
- The name, email address, and phone number that a conversation captures for an end user profile.
- CSAT feedback text.
Protected data
Built-in rules detect common kinds of personal data. Each rule has its own switch.
Custom rules detect data that is specific to your organization, such as an internal account number. Select Add custom rules, then enter a Rule name and a Regular expression. An organization can have up to 25 custom rules.
Type sample text in Test value to check a rule before you save it. The dialog lists the matches and shows a Redacted preview. A pattern that is unsafe, invalid, or able to match empty text is rejected with an error under the field.
Form answers
The agent can show a form in the conversation. Tars checks each answer in the form against the rules, the same as a message. The agent can also mark a form field as protected when the complete answer is personal data. For a protected field, Tars protects the full answer, including a checkbox answer, and not only the text that matches a rule. Protected answers use the Protected value format selected in Privacy settings: mask characters, the rule or field name in brackets, or custom replacement text. With character masking, Keep first and Keep last control which characters remain visible. If those counts would leave fewer than half the characters hidden, Tars masks the whole value instead. If an enabled card or Social Security Number rule matches, Tars redacts the full protected answer and ignores visible counts. Immediately after submission, the end user’s form and message can show the locally formatted answer using the configured visible counts. The widget does not run the backend’s card/SSN detection, so it can briefly show, for example, the last four card digits. When the backend’s saved answer arrives, that display is replaced with the fully masked value. The backend applies forced redaction before storage, so the partially masked local representation is not saved.Protected gambit responses
Input gambits have a Protect Response switch in the gambit editor. Turn it on when the complete response to that gambit is personal data, such as a date of birth. Tars then protects the full response with your protection method, and not only the text that matches a rule. With Use rule name selected, the placeholder is made from the gambit label, the same as for a form field. The switch is on the Text, Button, Card, Star Rating, Geo Location, Date & Time, Media Upload, Auto Suggestion, and Language gambits. A predefined option that the end user selects, such as a button, stays as it is. The flow still validates and branches on the real response. Tars protects the response before it stores the message and the response variable. The switch has no effect while Enable protection is off.Protected answers in tools
In Mask mode, the agent does not see the original of a protected answer. It gets a reference that it can send to a tool, such as a toolkit action. Tars puts the original in the tool call only when the call runs. In the tool result, Tars replaces the original with the reference again before the agent reads it. The same replacement applies to values that a tool gambit in Workflow Mode maps to variables. The execution log for an action that receives an original stores its input and output as redacted. If the original has expired, the tool call fails. In Redact mode, Tars does not keep the original, so no tool can receive it.Protection method
The method decides whether Tars retains the original. Protected value format independently decides how the replacement looks.
Before you choose a format explicitly, Redact defaults to mask characters and Mask defaults to the rule name, such as [EMAIL]. Changing the protection method preserves an explicitly chosen or saved format. Later format changes do not rewrite existing protected values.
Card numbers and Social Security Numbers are always redacted when their rules are on, even in Mask mode. Tars does not keep those originals.
Original value retention
In Mask mode, the Original value retention section sets how long Tars keeps the encrypted originals. Choose Keep indefinitely, or choose Delete after. Then enter a whole number and select minutes, hours, or days. The period must be at least 5 minutes and at most 365 days. An error under the field states the limit that a value breaks. The new window applies only to values protected after you save. When the window ends, Tars deletes the original and the placeholder stays in the conversation. A legal hold on the organization pauses this deletion. See Erasure and legal holds.Who sees the original
In live chat, a masked value in an end user message, a profile field, or CSAT feedback can be selected. A member who can open the conversation in live chat selects the placeholder to show the original for 60 seconds. Each reveal writes an audit event with the description viewed personal data for an end user, in the Data access category. Some files that leave the dashboard carry the original of a masked value that has not expired:- Conversation exports and Activity data view exports.
- Transcripts that a member downloads or sends from the Conversations page.
