Gemini CLI history: answering an audit or security questionnaire
A customer asks how AI-generated code is reviewed and retained. What do we show them?
Why this is hard
The question has stopped being hypothetical: customer security questionnaires now ask about prompt logging and retention directly. The answer has to be a system rather than a description of good intentions, and it has to cover a period that already happened.
What Gemini CLI specifically does to you here
Retention defaults to 30 days with cleanup enabled, and the sessions live in a directory named tmp. Both facts are relevant to an auditor asking what your retention policy is, because the honest answer is that you inherited one.
cat ~/.gemini/settings.json 2>/dev/null | head
Where Gemini CLI keeps this in the first place: ~/.gemini/tmp/<project_hash>/chats/. general.sessionRetention deletes sessions after 30 days, and cleanup is enabled by default.
What a working answer looks like
A working answer means a retained, timestamped record you can point at — with a retention policy you chose rather than inherited from a tool's default.
Start by measuring what you have. npx promptwake doctor reports what every AI tool on the machine is holding and how much of it sits inside a deletion window — no account, writes nothing, sends nothing anywhere. If the conclusion is that the record should not depend on one laptop, that is what PromptWake captures: prompt, response and the resulting diff, local by default and synced into a shared timeline on the paid tiers.
