ToolBoxOnline
Text Tools

Dummy Text That Leaks: Why Real Names in Placeholders Are a Privacy Disaster

A designer pastes real customer names into a mockup, the file ships to a vendor, and suddenly private data is public. Real placeholder text done right.

lorem ipsumplaceholder textprivacydata leakdesign workflow

Somewhere right now, a designer is building a mockup of a bank's new app and filling it with a real customer's real name, email, and balance. It looks great in the screenshot, and then that screenshot goes to the client, the vendor, the intern, and the training set of an AI tool. This is how "placeholder text" becomes a data breach — and it's shockingly common. The fix isn't to stop using dummy text; it's to use dummy text that's actually dummy. Here's the leak, and the workflow that closes it.

The Leak Is Real, and It's Boring

Nobody hacks a design file. Instead, a mockup with real names gets screen-shared in a meeting, uploaded to a collaboration tool that trains on your content, or handed to an outside agency under an NDA that doesn't cover customer data. Even a "test account" is dangerous if the test account belongs to a real person in the database. The counter-intuitive part: the most realistic-looking placeholder — real names, real addresses, real balances — is the riskiest one, because it's the one nobody flags as sensitive. Security teams review production data; they don't review Figma files. The leak isn't exotic, which is exactly why it keeps happening.

Use Placeholder Text That Can't Leak

The solution is to make your dummy content impossible to confuse with reality. A lorem ipsum generator is the obvious start, but go further: generate obviously-fake names like "Avery H. Winslow" for user rows, "Test Bank, N.A." for institutions, and "available for demonstration" instead of real balances. The goal is dummy data that still exercises the layout — long names that wrap, long account numbers that overflow — without carrying any real identity. If your layout needs repeated strings of the same fake text, a text repeater builds the filler in one shot, and a password generator makes perfect fake credentials that no human could mistake for a real account.

When Real Data Is Actually Required

There's one honest exception: some testing needs real data — genuine text density, real user journeys, actual edge cases. In those cases the rule is isolation: use a clearly labeled synthetic dataset stored separately from production, never copy-paste from the live database, and scrub anything that looks like a real person before the file leaves your machine. We covered why placeholder text exists in our guide to where dummy copy comes from. The short version of the lesson: placeholder text is a tool for layout, not a license to copy real people into your screenshots. Keep the dummy data dummy, and the only thing that leaks from your mockups is good design.

Tools mentioned in this article

Share this tool