Anonymize a table: a number or GUID instead of the value
You have to hand an export to a contractor, an analyst or a test environment, and personal data must stay behind. Deleting the ID column loses the main thing: which rows belong to the same person. It is better to replace the ID with an identifier that is the same everywhere that ID appears.
Free to use. Column menu → “Anonymize…”, or “Transform” → “Anonymize columns…”. Windows version — 4.6 MB, no installation: details. Pro — $29 once: price.
What you get
Every distinct value gets its own replacement, and one value gets the same replacement everywhere:
| Before | After |
|---|---|
| AB-0012345 | 1 |
| AB-0098765 | 2 |
| AB-0012345 | 1 |
All of one person’s visits are still linked and you can see how many there are, but the ID itself has left the file.
What to replace it with
- A sequence number — 1, 2, 3 in order of first appearance, optionally with a prefix and zeros:
P-00001. Works for numeric columns too. - A GUID — 36 random characters: it gives no hint of the row order in the original file.
- A random code of a given length — shorter than a GUID and fits a narrow DBF field; uniqueness is checked.
Three conditions without which anonymizing leaks
The whole file, not the screen
Rows hidden by a filter and records flagged as deleted are replaced too: in a DBF a deleted record physically stays in the file with its ID, and any other program can see it.
One dictionary across several columns
A patient’s ID and a guardian’s ID are one space of values. Tick both columns at once, and the same person gets the same number in both.
One dictionary across several files
Customers in one file, orders in another. Anonymize the first, then in the second choose “continue the dictionary”: the same IDs get the same numbers, new ones get the next. The link between the files survives.
Checks before writing
- “Preview” shows how many distinct values there are and some “before → after” examples without changing anything.
- Field length. A GUID in a DBF field
C(16)would be cut off and different IDs would collide. Such a replacement is rejected before writing, with a suggestion to take a shorter number or code. - Spaces and letter case are not distinguished by default: “1234 5678” and “12345678” are one ID.
The result is unsaved edits: you see what was replaced, you can undo it all, and the file on disk changes only on Save.
The mapping table
The “original value → replacement” table is the key that reverses the anonymization. It is saved nowhere by itself: you can export it to CSV with an explicit click — and store it apart from the anonymized file — or “Forget dictionary”, and the mapping disappears from the tab’s memory. If you do nothing, the dictionary lives until the tab is closed.
A saved table can be loaded back with the “Load…” button next to the dictionary choice. The kind of replacement is restored by itself: numbers continue from the maximum with the same prefix and zeros, GUIDs stay GUIDs. A table with contradictions — one ID with two replacements or one replacement for two IDs — is refused.
FAQ
Which formats does it work in?
Wherever the edit can be saved: DBF, Excel .xlsx, ODS, CSV, JSON, XML, SQLite. Export an old .xls to one of those first.
Can I continue the numbering next month, in a new session?
Yes. Save the mapping table after the first export and load it in the anonymize dialog a month later: the same IDs get the same numbers, new ones the next in order.
Does the data go to a server?
No. The replacement runs in your browser, and the page technically cannot send the file’s contents to any other address.
Free to use. Your file is not uploaded to a server. Windows version — 4.6 MB, no installation: details. Pro — $29 once: price.