Gemini CLI

Gemini CLI history: answering an audit or security questionnaire

A customer asks how AI-generated code is reviewed and retained. What do we show them?

Why this is hard

The question has stopped being hypothetical: customer security questionnaires now ask about prompt logging and retention directly. The answer has to be a system rather than a description of good intentions, and it has to cover a period that already happened.

What Gemini CLI specifically does to you here

Retention defaults to 30 days with cleanup enabled, and the sessions live in a directory named tmp. Both facts are relevant to an auditor asking what your retention policy is, because the honest answer is that you inherited one.

See it on your own machine
cat ~/.gemini/settings.json 2>/dev/null | head

Where Gemini CLI keeps this in the first place: ~/.gemini/tmp/<project_hash>/chats/. general.sessionRetention deletes sessions after 30 days, and cleanup is enabled by default.

What a working answer looks like

A working answer means a retained, timestamped record you can point at — with a retention policy you chose rather than inherited from a tool's default.

Start by measuring what you have. npx promptwake doctor reports what every AI tool on the machine is holding and how much of it sits inside a deletion window — no account, writes nothing, sends nothing anywhere. If the conclusion is that the record should not depend on one laptop, that is what PromptWake captures: prompt, response and the resulting diff, local by default and synced into a shared timeline on the paid tiers.