Prefex runs entirely on your machine. Your prompts go directly from Prefex to the upstream API (Anthropic or OpenAI), nobody else sees them.
Every request writes one row to a local SQLite database at
~/.prefex/data/prefex.db. The row contains:
| Field | Logged | Example |
|---|---|---|
| Timestamp | Yes | 2026-03-27T14:23:01Z |
| Channel | Yes | claude_code |
| Mode | Yes | live |
| Model used | Yes | claude-haiku-4-5-20251001 |
| Input tokens | Yes | 1024 |
| Output tokens | Yes | 312 |
| Cost (USD) | Yes | 0.0003 |
| Router decision | Yes | weak |
| Cache hit | Yes | true |
| Latency (ms) | Yes | 72 |
| Prompt text | Opt-in | Off by default. Stored locally if store_system_prompt_text: true. |
| Response text | Never | - |
| System prompt text | Opt-in | Off by default. Local only, for cache analysis. |
| API keys | Never | - |
Prompts, responses and tool output go only to the LLM provider you configure. The SQLite database is local. The dashboard reads from that database.
Nothing is sent automatically. An anonymous daily usage report is opt-in, off by default. Prefex is built by a very small team, and one summary per day is how we know whether it works outside our own machines. It is counts and percentages only:
| Field | Example |
|---|---|
version, os, arch | v1.14.0, darwin, arm64 |
tokens_processed, turns, sessions, active_hours | 150700000, 290, 29, 0.8 |
avg_context_tokens, peak_context_tokens | 519000, 860000 |
tokens_cached, cache_hit_pct | 150600000, 91.7 |
tokens_compacted, tokens_compacted_distinct | 3600000, 128000 |
compaction_coverage_pct | 27.9 |
provider_mix, tier_mix, channel_mix | {"Anthropic": 100.0}, {"opus": 79.0} |
layers_on | ["router", "cache", "compression"] |
Never sent: prompts, completions or tool output; file paths, project or
repository names; model names (only the tier, since a name can encode a
private deployment); API keys, session, device or account identifiers;
dollar figures. There is no identifier, so two reports from the same machine
cannot be linked. Our collector stores only fields on a fixed allowlist and
discards anything else. prefex install shows this disclosure and, in a
terminal, asks [y/N], defaulting to No. Without a terminal (curl | bash, autostart,
CI) it stays off. A re-run or upgrade keeps your earlier choice.
Turn it on or off at any time. We do not nag.
prefex install --usage-reporting # opt in at install prefex install --no-usage-reporting # stay off, no prompt prefex toggle usage-reporting on|off # any time afterwards PREFEX_USAGE_REPORTING=1 curl -fsSL https://promptforce.ai/install.sh | bash # opt in via the script # or: dashboard, Settings · Privacy, Anonymous Usage Reporting
Install ping (opt-in). Only when you set PREFEX_USAGE_REPORTING=1: when install.sh or install.ps1 finishes, it sends one
request to promptforce.ai/api/ping with the version, OS, architecture, and
whether it was an install or an upgrade. Nothing else, once per install or
upgrade. Without that variable no ping is sent; PREFEX_NO_PING=1 or
DO_NOT_TRACK=1 suppresses it even when the variable is set.
Update check. Once a day Prefex asks GitHub for the latest public release
tag and compares it locally. The request carries nothing about your install.
Turn it off with prefex toggle update-check off.
Opt-in only: prefex advisories (downloads a signed file, sends nothing),
the marketplace catalog download (telemetry.enabled, off by default),
leaderboard submission (aggregate numbers plus the username and email you
enter, only when you click Submit), and endpoints you configure yourself, such
as a policy gateway, hosted guardrails, or an OTLP collector.
The full legal text is in the Privacy Policy.
Run this while Prefex is active:
# Capture outbound HTTPS from this machine sudo tcpdump -i any -n "dst port 443" 2>/dev/null # Expect your LLM provider (e.g. api.anthropic.com), plus once a day GitHub's # release API unless you turned it off, the licence check (promptforce.ai, on start # and daily), and the usage report only if you opted in.
Prefex is a single ~20MB standalone binary with zero external dependencies.
# Check the binary ls -lh $(which prefex) # Output: ~20MB binary
Prefex is free until it saves you $500 beyond native prompt caching. No credit card. The licence key is verified offline on your machine. So that a reinstall doesn't reset the meter, prefex sends a small licence check to promptforce.ai on start and once a day: a salted hash of the machine id, the binary version, the key id ("free" for the built-in key) and three numbers (value added on this machine, value added under the key, and when it ran out). No prompt, path, email or IP is stored, and if the check can't be reached prefex keeps running on its local meter. Nothing else is sent.
Prefex ships as a pre-compiled Go binary. The proxy is proprietary. The embedded rules-based router runs entirely in-process, no external ML services needed.
Open an issue or discussion at github.com/PromptForcePrime/prefex for anything privacy, data, or security related.