Privacy & Trust

Prefex runs entirely on your machine. Your prompts go directly from Prefex to the upstream API (Anthropic or OpenAI), nobody else sees them.

What Prefex logs

Every request writes one row to a local SQLite database at ~/.prefex/data/prefex.db. The row contains:

FieldLoggedExample
TimestampYes2026-03-27T14:23:01Z
ChannelYesclaude_code
ModeYeslive
Model usedYesclaude-haiku-4-5-20251001
Input tokensYes1024
Output tokensYes312
Cost (USD)Yes0.0003
Router decisionYesweak
Cache hitYestrue
Latency (ms)Yes72
Prompt textOpt-inOff by default. Stored locally if store_system_prompt_text: true.
Response textNever-
System prompt textOpt-inOff by default. Local only, for cache analysis.
API keysNever-

Your prompts never leave your machine

Prompts, responses and tool output go only to the LLM provider you configure. The SQLite database is local. The dashboard reads from that database.

What Prefex sends us

Nothing is sent automatically. An anonymous daily usage report is opt-in, off by default. Prefex is built by a very small team, and one summary per day is how we know whether it works outside our own machines. It is counts and percentages only:

FieldExample
version, os, archv1.14.0, darwin, arm64
tokens_processed, turns, sessions, active_hours150700000, 290, 29, 0.8
avg_context_tokens, peak_context_tokens519000, 860000
tokens_cached, cache_hit_pct150600000, 91.7
tokens_compacted, tokens_compacted_distinct3600000, 128000
compaction_coverage_pct27.9
provider_mix, tier_mix, channel_mix{"Anthropic": 100.0}, {"opus": 79.0}
layers_on["router", "cache", "compression"]

Never sent: prompts, completions or tool output; file paths, project or repository names; model names (only the tier, since a name can encode a private deployment); API keys, session, device or account identifiers; dollar figures. There is no identifier, so two reports from the same machine cannot be linked. Our collector stores only fields on a fixed allowlist and discards anything else. prefex install shows this disclosure and, in a terminal, asks [y/N], defaulting to No. Without a terminal (curl | bash, autostart, CI) it stays off. A re-run or upgrade keeps your earlier choice.

Turn it on or off at any time. We do not nag.

prefex install --usage-reporting      # opt in at install
prefex install --no-usage-reporting   # stay off, no prompt
prefex toggle usage-reporting on|off  # any time afterwards
PREFEX_USAGE_REPORTING=1 curl -fsSL https://promptforce.ai/install.sh | bash   # opt in via the script
# or: dashboard, Settings · Privacy, Anonymous Usage Reporting

Other outbound requests

Install ping (opt-in). Only when you set PREFEX_USAGE_REPORTING=1: when install.sh or install.ps1 finishes, it sends one request to promptforce.ai/api/ping with the version, OS, architecture, and whether it was an install or an upgrade. Nothing else, once per install or upgrade. Without that variable no ping is sent; PREFEX_NO_PING=1 or DO_NOT_TRACK=1 suppresses it even when the variable is set.

Update check. Once a day Prefex asks GitHub for the latest public release tag and compares it locally. The request carries nothing about your install. Turn it off with prefex toggle update-check off.

Opt-in only: prefex advisories (downloads a signed file, sends nothing), the marketplace catalog download (telemetry.enabled, off by default), leaderboard submission (aggregate numbers plus the username and email you enter, only when you click Submit), and endpoints you configure yourself, such as a policy gateway, hosted guardrails, or an OTLP collector.

The full legal text is in the Privacy Policy.

Verify with tcpdump

Run this while Prefex is active:

# Capture outbound HTTPS from this machine
sudo tcpdump -i any -n "dst port 443" 2>/dev/null

# Expect your LLM provider (e.g. api.anthropic.com), plus once a day GitHub's
# release API unless you turned it off, the licence check (promptforce.ai, on start
# and daily), and the usage report only if you opted in.

Binary verification

Prefex is a single ~20MB standalone binary with zero external dependencies.

# Check the binary
ls -lh $(which prefex)
# Output: ~20MB binary

License

Prefex is free until it saves you $500 beyond native prompt caching. No credit card. The licence key is verified offline on your machine. So that a reinstall doesn't reset the meter, prefex sends a small licence check to promptforce.ai on start and once a day: a salted hash of the machine id, the binary version, the key id ("free" for the built-in key) and three numbers (value added on this machine, value added under the key, and when it ran out). No prompt, path, email or IP is stored, and if the check can't be reached prefex keeps running on its local meter. Nothing else is sent.

What you get

Prefex ships as a pre-compiled Go binary. The proxy is proprietary. The embedded rules-based router runs entirely in-process, no external ML services needed.

Questions

Open an issue or discussion at github.com/PromptForcePrime/prefex for anything privacy, data, or security related.