Bypass AI Chatbot

Tired of the annoying AI chat bot? Send your message as a picture it cannot read — so a person has to.

100% private — runs entirely in your browser. Your data is processed on your device and never sent to the internet.

It becomes a picture the AI chat bot cannot read — but a human agent can.

The picture is drawn on your device and nothing is uploaded. The only thing that ever leaves is the image you send yourself. The machine test runs in your browser too — it downloads the recognition engine once, then reads the picture locally.

Tired of the annoying AI chat bot?

You have a real problem, and the annoying AI chat bot keeps answering with the same three menu options. You type "agent". It offers you the help centre. You type "human". It asks you to rephrase.

This tool turns what you want to say into a picture. A person reads it at a glance; the automated text-reading in the middle gets nothing and has to hand it on.

Type your message, copy the image, paste it into the chat or the email. Free, no account, and nothing is uploaded.

Why a picture gets further than text

Most first-line support is automated, and almost all of that automation works on text. It matches keywords, scores intent, picks a template and replies — often without a person seeing anything.

A picture breaks that chain in two different ways, and either one helps:

  • Many systems never read images at all. An attachment is exactly the thing a text-only bot cannot classify, so it gets handed to a person by default.
  • Systems that do read images use text-recognition software, and that software is far easier to defeat than a human eye.

That is the whole idea. You are not hiding anything — you are making your message inconvenient for the filter and perfectly normal for the agent.

Read this before you rely on it

This works against some systems and not others, and it is better to know which before you send something that matters.

It defeats ordinary text-recognition comfortably. Tesseract is the engine most cheap extraction pipelines use. Across six test messages on the recommended setting it recovered 6% of the words on average, and never a usable sentence. It fails unpredictably rather than cleanly, so the figure moves between messages — the worst single case was 18% — but it never gets near readable. You can check your own message with the *Test it against a machine* button on this page.

It will not defeat a modern AI that can see images. The large assistants read distorted text far better than Tesseract and keep improving. If a company has wired a vision model into its support inbox, treat this as no protection at all.

Some chats will not accept a picture. Email, ticket forms and most messaging apps do. A narrow web chat widget often does not — in that case, send it as an email attachment instead.

So: good for getting past keyword triage and text-only automation, which is what causes most bot loops. Not a security measure, and not a way to hide anything from a person.

How the picture is made

Your text is drawn completely normally — upright, crisp, undistorted. Nothing is bent or blurred. The interference goes *around* it: a scatter of letter-shaped debris in a different colour, behind the message, plus a fine spray of ink specks.

You separate the two instantly, because people group things by colour, size and alignment. A tidy row of dark letters sits in front of a mess of pale blue ones, and your eye never even has to try.

Recognition software has no such grouping. It converts the image to grey — losing the colour cue completely — then looks for ink of a plausible letter size and has to decide what is a character. The debris joins the queue of candidates, and the line it thinks it has found is nonsense.

Each line of the message is also stroked in the paper colour before it is filled, which clears a narrow margin around every letter. That is what lets the message lift cleanly off the clutter instead of tangling with it.

What testing changed

Almost everything here came from measuring against a real engine, and the first two designs were thrown away.

Distorting the text was the wrong idea. The first version bent the letters. Any bend strong enough to stop an engine also made the message tiring to read — which defeats the whole point of sending it to a person. Leaving the text alone and cluttering the page around it does the same job and stays easy on the eye.

The colour of the clutter matters more than the amount. Debris has to be a mid-tone colour, not a pale grey. Measured: debris at luminance 167 left 95% of the words readable to the engine, at 146 it left 20%, and at 110 it left 2%. Lighter clutter looks nicer and does nothing.

More clutter is not better — there is an optimum. This was the real surprise. Recovery is lowest at about one piece of debris per 420 square pixels, and rises in *both* directions: 6% at that density, but 24% when packed nearly twice as densely. Pile it on and the debris merges into a mass the engine simply writes off as background, leaving your message standing clean. That is why there is no "maximum" setting — it would be uglier and weaker at the same time.

A regular pattern is useless. Dense diagonal hatching left 91% of the words readable. These engines are built to filter out exactly that kind of repetition; only irregular, letter-like shapes confuse them.

One earlier idea was simply wrong. Text and background in different colours but identical brightness should, in theory, vanish when software converts the image to grey. It does not — the engine read it at 92%, exactly as well as black on white.

Writing a message that actually gets acted on

The picture gets you past the filter. What you write decides what happens next.

  • Ask for a human in the first line, plainly.
  • Include your order or account number — the agent cannot look anything up without it.
  • Keep it to a few sentences. Nobody enjoys reading a wall of waving text.
  • Say what outcome you want: a refund, a cancellation, a callback.
  • Stay polite. The person reading it is not the system that annoyed you.

What you can do with it

  • Get out of a chatbot loop that keeps offering the same menu
  • Send a complaint that will not be auto-sorted into a template reply
  • Put your order or account number where only a person will act on it
  • Attach it to a support email or a ticket form
  • Show someone how much of a support system is automated

Features

  • Checkable, not just claimed — test any image against a real recognition engine on this page
  • Two honest settings — the measured best, and a lighter one that says outright it protects less
  • Copy straight to the clipboard for pasting into a chat, or download a PNG
  • Draw it differently re-rolls the clutter without retyping
  • Text size, image width and paper colour all adjustable
  • Runs entirely in your browser — nothing is uploaded

Good to know

  • This is not security or encryption. Anyone who sees the picture can read it. It only resists automated reading.
  • A vision-capable AI can read it. Assume anything with a modern image model attached will get most of it.
  • Never put secrets in it. Passwords, card numbers and one-time codes do not belong in a support chat in any form.
  • Keep the plain text. If an agent asks you to re-send it as text, you will want it to hand.
  • A screen reader cannot read a picture. Do not use this with someone who relies on one.

Common questions

How do I get past an annoying AI chat bot?

The reliable routes are asking for an agent in plain words, saying "complaint" or "cancel", or using a channel the annoying AI chat bot does not handle — phone, email, or a social media account. This tool adds one more: send your message as a picture, which a text-only bot cannot classify and usually has to hand to a person.

Will this get me to a human every time?

No. It gets your message past automated text-reading, which is often what traps you in a bot loop. If the company runs a vision-capable AI on its inbox, or refuses attachments, it will not help. It improves the odds; it does not guarantee anything.

Can ChatGPT or a similar AI read the image?

Usually yes. Large models with image input read distorted text far better than traditional recognition software. This tool is aimed at ordinary text-extraction pipelines, and the page says so rather than pretending otherwise.

Is this allowed, or against the rules?

Sending a picture of your own message to a company's own support channel is an ordinary thing to do — people attach screenshots constantly. It gets around no security control and hides nothing about who you are. Check a service's terms if you are unsure, and never send anything you would not send as text.

Why can I read it when a machine cannot?

Because you separate layers and software does not. Your eye groups the dark, upright, evenly spaced letters into a line and pushes the pale blue clutter behind it without conscious effort. Recognition software converts everything to grey first, losing the colour cue, and then has to judge every blob of ink on its own. That difference is the entire mechanism.

Will my order number still be readable?

Yes. Your text is never distorted at all, so a reference number is exactly as sharp as it would be in any other image. Check the preview anyway, and press *Draw it differently* if a piece of clutter happens to sit awkwardly close to a digit.

Does anything I type get uploaded?

No. The picture is drawn in your browser and never sent anywhere. Even the machine test runs locally: it downloads the recognition engine once, then reads the picture on your device. The only thing that leaves is the image you choose to send.

Related tools

How to use it

  • Type or paste your message into the box
  • Leave the clutter on Recommended unless you need it easier to read
  • Read the preview yourself — if any word is a struggle, press *Draw it differently*
  • Copy the image and paste it into the chat, or download it and attach it to an email

We add new tools regularly — subscribe on YouTube to be notified when each one goes live.

More tools

View all

Recommended Apps

View all