Protecting Privacy in Classifiers by Token Manipulation