Glossary
What is a re-identification key?
A re-identification key is the table, or secret, that maps each stand-in in a pseudonymized document back to the real value: [PERSON_001] to a client's name, [SIN_001] to their SIN. Whoever holds it can reverse the pseudonymization. NIST calls it a lookup table and says it "must be highly protected"; the EDPB says lookup tables are themselves personal data. Keep it away from the AI platform.
Last reviewed · 2 sources
What the standards say
NIST SP 800-188: "The mapping between the direct identifier and the pseudonym is performed using a lookup table or a repeatable transformation. In either case, the release of the lookup table or the information used for the repeatable transformation will result in compromised identities."
EDPB Guidelines 01/2025: "Lookup tables are personal data since they allow the identification of data subjects. Since they are parts of the pseudonymisation secrets, they need to be protected from unauthorised access and use."
Practical rules
- Store the key separately from the pseudonymized copy, and never paste it into the AI conversation
- Use stand-ins that carry no information about the values (numbered or random, never hashes of them), so the copy cannot be reversed without the key
- Keep the key as long as you need to restore the work, and delete it with the matter
- Remember that details you chose not to replace are not protected by the key at all
Where PiBye fits
How PiBye handles this
In PiBye the key never leaves your Mac. Stand-ins are numbered per matter rather than computed from the values, the map is stored locally, and the local connection to Claude Desktop or the ChatGPT desktop app exposes approved copies only, never the map.
1.0.1 · macOS 14.8.5 or later · Apple Silicon · 1.1 GB
Frequently asked questions
If someone gets the key, what do they learn?
Everything the stand-ins hide in documents they also have. That is why the key and the shared copy should never sit in the same place.
Does the AI provider receive the key?
It should not, and with PiBye it does not: the AI receives only the approved copy.
Sources
- NIST SP 800-188: De-Identifying Government Datasets, National Institute of Standards and Technology, September 2023. Checked 25 September 2026.
- Guidelines 01/2025 on Pseudonymisation (version for public consultation), European Data Protection Board, January 16, 2025. Checked 25 September 2026.