Imagine you're on a video call and sharing your screen. You've got a sticky note with a database password visible in the corner, your Slack DMs open in a tab, and a terminal showing environment variables with API keys. The AI assistant watching your screen to 'help' you just ingested all of it. PerceptFence is a content-layer bouncer — it sits between the raw screen capture and the AI model, scanning every frame for secrets and PII before the model ever sees them. The mechanism is closer to a mail room that opens every envelope and redacts classified paragraphs before forwarding than to a filter on the model's output side. The committed claim: PerceptFence provides a documented mediation architecture that neutralises 91.8% of OCR-surviving secrets and PII in synthetic developer-support screens, versus 58.1% for Microsoft Presidio and 17.9% for gitleaks, while retaining 76.3% of task-relevant tokens. The authors are unusually disciplined about what they are NOT claiming — no live deployment, no formal privacy guarantees, no novel redaction primitives, no general model robustness. This is an architecture paper with a deterministic evaluation scaffold, not a product announcement. The evaluation design is the most interesting part. They built 480 synthetic developer-support screens rendered in Chrome, degraded them to simulate real capture conditions, then read them with OCR — replicating the actual pipeline a deployed assistant would use. Rules were frozen before testing, and three screen types were held out entirely to test generalisation. The held-out types hit 97.4% neutralisation, which is a strong signal that the rules generalise rather than overfit. A separately implemented 'exposure oracle' scored 9,600 adversarial strings, providing an independent check. On the baseline comparison: PerceptFence dominates on digit-PII payloads (0.828 vs 0.183 for Presidio across the 5 shared seeds), but Presidio actually leads outside that family (0.238 vs 0.154). The authors report this honestly and flag the overall 0.398 vs 0.260 comparison as 'only indicative.' This kind of candour is rare and should be rewarded. The comparison tells you PerceptFence is specialised — it excels at structured secrets (API keys, passwords, credit card numbers) but does not outperform general-purpose NER on free-text PII like names and addresses. The architecture sits in the rule-based content filtering family, not the ML-based PII detection family. This is a deliberate choice: deterministic rules are auditable, have predictable failure modes, and don't require training data with privacy-sensitive content. The tradeoff is that they can't adapt to novel PII patterns without manual rule updates. The 76.3% task-token retention on held-out screens means roughly one in four useful tokens gets caught in the crossfire — a non-trivial cost that would matter in production. The biggest gap is the absence of live deployment testing. The entire evaluation runs on synthetic fixtures, and the paper explicitly omits live capture, category inference, authenticated re-consent, cross-session state, and an external model adapter. These are exactly the components where real-world systems fail. The synthetic-to-real gap for screen capture is substantial — real screens have overlapping windows, dynamic content, non-standard fonts, and adversarial users who don't arrange their secrets neatly. The authors know this and say it plainly, which is the right move for a v0.4.0 release. The contribution is genuine but bounded: a well-documented architecture pattern and evaluation methodology for a problem that barely has either. As screen-share AI assistants proliferate (Copilot, Gemini, Claude desktop), the need for a mediation layer between capture and model is real and growing. PerceptFence doesn't solve this problem, but it gives the field a testable scaffold and an honest baseline to beat.