Home / DGAI Help / Privacy & AI / How Your Privacy Works

How Your Privacy Works

DGAI's whole design goal is simple: let a powerful cloud AI reason about your family DNA data without ever seeing who anyone is. Here's exactly how it does that — and how you can verify it yourself.

1. Everything is tokenized before it's sent

Before any data leaves your computer, every identifying thing is replaced with a stable token:

TokenStands for
[P1]A profile / test kit you manage
[M1234]A DNA match (a tester)
[A5678]A tree ancestor
[G12]A group / family cluster
[S7]A surname
[L34]A place

Tokens are consistent: the same surname is always [S7], the same match is always [M1234] — across the whole conversation and across sessions. That's what lets the AI still reason about family-line clustering and recurring locations; it just can't see the real value.

2. The mapping stays on your machine

The token↔real-name mapping lives in a small sidecar database on your computer, never inside your GDAT database and never sent anywhere:

  • macOS: ~/Library/Application Support/DGAI/maps/
  • Windows: %LOCALAPPDATA%\DGAI\maps\

3. Answers are translated back locally

When the AI replies (in tokens), DGAI swaps the tokens back to real names on your screen. Restored names are highlighted, and hovering a reply shows a “Restored locally:” list of each [TOKEN] → name — so you can always see precisely what was, and wasn't, sent.

4. Names you type are scrubbed too

If you type “Mary Jones”, DGAI recognizes her and substitutes her token before sending, showing “sent as: ‘Mary Jones’ → [M1234]”. It matches known full names and surnames while avoiding common words, so ordinary questions still read naturally.

5. Some fields never leave the process at all

Highly identifying fields aren't tokenized — they're simply never read into anything the AI could see: contact names, emails and phone numbers, vendor match keys, profile/tree URLs, PersonGuids, and WikiTree / FamilySearch ids.

6. Free text is withheld by default

Free-text fields — research notes, event summaries, MRCA notes — can contain names no tokenizer can catch, so they are withheld from cloud AI unless you explicitly opt in (a checkbox in Settings). When withheld, the AI just sees [withheld: free-text excluded by privacy settings].

7. An outbound guard is the backstop

As a final safety net, DGAI keeps a dictionary of every distinctive identity value in your database and scans every outgoing request. If even one real value slips through, the request is blocked outright — you'll see “Blocked outbound request: the payload contains a value from the local identity dictionary… Nothing was sent.” There is deliberately no “send anyway” for cloud AI.

Read-only, always. DGAI opens your GDAT database in read-only mode, so it can never modify your data no matter what you (or the AI) ask.

The two opt-ins

Everything above is on by default. Only two settings loosen it, and both are off unless you choose them:

  • Send research notes / free text to cloud AI — lets your notes flow (still with tokenized names where detectable). Off by default.
  • Real names (localhost AI only) — skips tokenization entirely, allowed only for a local AI on your own machine. DGAI refuses it for any non-local endpoint, so nothing leaves your computer either way. See Choosing an AI Backend.

DGAI is a DNAGedcom tool. © DNAGedcom LLC 2020–2026. DGAI is provided as is with no guarantee given as to its performance.

All Applications · DNAGedcom User Group · Email Support