PRIVACY

Remove UTM parameters and redact sensitive text before you send it

Paste as soon as the page opens. Clean Link strips UTM, gclid, fbclid, and other trackers and lists what was removed. Data Redaction masks phones, emails, national ID numbers, and keys. Source text stays in this tab and is never uploaded.

✓ Local parse ✓ Strip list ✓ Before / after ✓ No account
01

Paste a URL or text and see the cleaned result

Remove UTM parameters from a link, or redact PII in a message. Processing happens on this device. The right side shows a checkable strip list or a before-and-after mask.

Tool

This cleanup

Clean URLs and stripped parameters will appear here

02

UTM removal and PII redaction are separate jobs

Tracking parameters on a URL are not the same problem as phones and emails in a message. This page splits them. Neither leaves the browser.

Clean Link

After parsing the URL, it removes utm_*, click IDs such as gclid / fbclid / msclkid, common analytics tokens, and frequent commerce attribution (including spm and similar). The path and business parameters such as id / q stay. Each result lists the stripped parameter names.

Data Redaction

Rules detect phones (including E.164, NANP, and mainland China mobiles), national ID numbers, Luhn-checked bank cards, emails, common API keys / tokens, and IPv4 / IPv6. Smart masking is the default; you can switch to all asterisks.

How this splits from Burn-Link

Redaction handles PII scattered through a chat or ticket. A whole key, passphrase, or unpublished material should go through Burn-Link: ciphertext is stored briefly, the key stays in the # fragment, and it burns after reading.

03

What gets stripped, what stays, and what this cannot do

Privacy Cleaner only answers what you can remove before sending. Where it runs, what it strips, and the limits of rule-based cleanup are written below.

Where it runs

Parse, strip, and mask all run in this tab. Source text does not enter an HTTP request and is not written to analytics. After you close the page, this input does not remain on the server.

What gets stripped

Standard mode covers UTM, click IDs, analytics parameters, and common commerce attribution. Conservative mode touches only UTM and click IDs. The pathname and business query stay by default.

Masking

A few leading and trailing characters stay by default so you can check—for example the middle four digits of a phone, the local part of an email, or the last four of a card. You can switch to a full mask or turn off a rule.

What it cannot do

It cannot recognize every ID format, and it cannot prove the text meets a compliance rule. It does not claim GDPR or other certification. Recheck important outbound mail yourself.

FAQ

UTM remover and redaction FAQ

No. URL parsing, parameter stripping, and text masking all run in this tab. Source text is not sent in a request and is not written to analytics.

Standard mode removes utm_*, ad click IDs such as gclid and fbclid, common analytics parameters, and frequent commerce attribution. The path and business parameters such as id and q stay. Conservative mode removes only UTM and click IDs.

No. This page pattern-matches phones, national ID numbers, bank cards, emails, API keys, and IPs. It is an aid. Recheck important outbound mail yourself. MakePwd does not claim GDPR or other compliance certification.

Send a whole secret once with Burn-Link; the key stays in the URL # fragment. Encrypt a whole file in File Encryption Box on this device, then use a drive or email.