A recorder is only acceptable if it is not also a new exposure.

PromptWake reads the transcripts your tools already write and stores them on your own machine. It does not sit between you and your model, it does not need an API key, and it does not upload anything unless you switch sync on deliberately.

Where your data actually lives

On Free, nowhere but your disk. On paid plans, cloud sync is opt-in per project and encrypted in transit. Enterprise can self-host the whole system so nothing leaves your infrastructure at all.
Book a demo

Local storage by default

Capture writes to SQLite under your home directory. You can open the file, back it up or delete it without asking anyone.

  • No account needed for local capture
  • Sync is off until enabled
  • Per-project sync control

Secrets are dropped before writing

API keys, tokens and credentials are detected and removed before anything reaches disk. They are not redacted afterwards, which means the stored history cannot leak what it never contained.

Nothing in the request path

There is no proxy, no gateway and no interception. Your prompts go straight to your model, and the recorder reads what the tool writes afterwards.

Roles, including read-only

On shared plans, an auditor role can read the record without the ability to change it, and administrative actions are themselves logged.

What we do not claim

We will not put a certification badge on a website to win a procurement question. The formal position — roles, sub-processors, security measures, breach notification and audit rights — is set out in the Data Processing Addendum, and security documentation is shared under NDA. If your process requires a specific attestation, ask us directly and we will tell you where we actually are rather than what sounds reassuring.

The documents

Data Processing Addendum — roles, sub-processors, transfers, deletion.
Privacy Policy — what is collected and what never is.
Terms of Service and Refund & Cancellation Policy.

Security questions

Do you train on our prompts?

No. There is no model in the product. PromptWake records what your tools produce; it does not send it anywhere to be learned from.

Can we self-host?

Yes, on Enterprise. The daemon is already local; self-hosting covers the shared workspace, sync and reporting layers too.

How do we delete a record?

Locally, delete the database. Under a retention policy, records are archived rather than deleted, because a record that can be removed on request is weak evidence.

Who can see a shared workspace?

Only the people you invite, under the role you give them. Role changes and access are recorded in the audit log.

Send us your security questionnaire.

We would rather answer it plainly than have you infer the answers from a trust badge.