Skip to main content
Personal data protection replaces card numbers, email addresses, and other personal data before Tars stores what end users send. You choose which kinds of data to detect and how to replace them. Protection is off until an Admin turns it on, and it applies to one organization at a time.

Where the settings live

Open Settings and select Privacy under the Workspace heading. Only members with the Manage organization permission see this page, which means Admins. See Roles and permissions. The page has three parts: the Enable protection switch, the Protected data rules, and the Protection method. Changes take effect when you select Save changes. The save is written to the audit log as an organization settings change.

What Tars checks

With protection on, Tars checks these values before it stores them:
  • Messages that end users send in a conversation.
  • Answers that end users give to questions in a flow.
  • Answers that end users submit in a form that the agent shows in the conversation.
  • The name, email address, and phone number that a conversation captures for an end user profile.
  • CSAT feedback text.
Protection does not scan everything. Replies from the agent and from human agents are not checked, and neither are attachments, tool payloads, or knowledge base documents. Values already stored when you turn protection on stay as they are, because the policy applies only to new data.

Protected data

Built-in rules detect common kinds of personal data. Each rule has its own switch. Custom rules detect data that is specific to your organization, such as an internal account number. Select Add custom rules, then enter a Rule name and a Regular expression. An organization can have up to 25 custom rules. Type sample text in Test value to check a rule before you save it. The dialog lists the matches and shows a Redacted preview. A pattern that is unsafe, invalid, or able to match empty text is rejected with an error under the field.

Form answers

The agent can show a form in the conversation. Tars checks each answer in the form against the rules, the same as a message. The agent can also mark a form field as protected when the complete answer is personal data. For a protected field, Tars protects the full answer, including a checkbox answer, and not only the text that matches a rule. In Redact mode, Tars stores a protected answer as asterisks. In Mask mode, Tars stores a placeholder made from the field label in capitals, such as [DATE_OF_BIRTH]. If a protected answer contains a card number or a Social Security Number, Tars redacts the full answer. The submitted form in the widget shows the protected value, not the original.

Protected answers in tools

In Mask mode, the agent does not see the original of a protected answer. It gets a reference that it can send to a tool, such as a toolkit action. Tars puts the original in the tool call only when the call runs. In the tool result, Tars replaces the original with the reference again before the agent reads it. The same replacement applies to values that a tool gambit in Workflow Mode maps to variables. The execution log for an action that receives an original stores its input and output as redacted. If the original has expired, the tool call fails. In Redact mode, Tars does not keep the original, so no tool can receive it.

Protection method

The method decides what replaces a detected value. Card numbers and Social Security Numbers are always redacted when their rules are on, even in Mask mode. Tars does not keep those originals.

Original value retention

In Mask mode, the Original value retention section sets how long Tars keeps the encrypted originals. Choose Keep indefinitely, or choose Delete after and enter a number of days from 1 to 365. The new window applies only to values protected after you save. When the window ends, Tars deletes the original and the placeholder stays in the conversation. A legal hold on the organization pauses this deletion. See Erasure and legal holds.

Who sees the original

In live chat, a masked value in an end user message, a profile field, or CSAT feedback can be selected. A member who can open the conversation in live chat selects the placeholder to show the original for 60 seconds. Each reveal writes an audit event with the description viewed personal data for an end user, in the Data access category. Some files that leave the dashboard carry the original of a masked value that has not expired:
  • Conversation exports and Activity data view exports.
  • Transcripts that a member downloads or sends from the Conversations page.
The transcript that an end user downloads from the widget keeps the placeholders. Redacted values never come back, in any file. See Export conversations and Search and export the audit log.