For macOS 14 and later

Nothing sensitive reaches ChatGPT, Claude, or Gemini.

PromptVeil sits between your keyboard and every AI chat on your Mac. It catches API keys, passwords, card numbers, and personal data the moment you press Return or paste, and swaps them for placeholders you can reverse later. Everything stays on your Mac.

No account. No cloud. One permission, explained up front.

Check my PAN CKGPS2845Z and tell me if the format is right
Sonnet 5 · Medium
PromptVeil caught 1 sensitive item
before your message reached Claude.
👤PAN (India) CKG••••5Z Allow
REDACTED VERSION
Check my PAN [PAN_1] and tell me if the format is right
Cancel Send anyway Redact & send
Works with ClaudeChatGPTGeminiPerplexityCopilotGrokDeepSeek in SafariChromeArcBraveFirefoxEdge and the desktop apps
How it works

It checks at the only moment that matters: right before send.

Copy-time scanners can't know where text is going. Browser extensions miss the desktop apps. PromptVeil watches the two keystrokes that actually move data into a chat.

1

Type or paste as usual

Use ChatGPT, Claude, Gemini, or any other AI chat exactly as you do today. PromptVeil is invisible until it has something to say.

2

Return and ⌘V are inspected

When you press Return or paste inside an AI chat, PromptVeil reads the text box and scans it on your Mac in a few milliseconds.

3

Redact, allow, or cancel

Sensitive values become placeholders like [EMAIL_1]. Send the redacted version with one click, whitelist a value forever, or stop the message.

you send: "reset the key sk-proj-a8f…"
model sees: "reset the key [API_KEY_1]"
you copy the answer: [API_KEY_1] becomes sk-proj-a8f… again
Examples

What a catch looks like, wherever you work.

Three real prompts, each stopped a keystroke before sending. Every value shown here is a documented test number, and every catch is exactly what the shipped rules produce.

United States · Customer support
Draft a polite reply to Jane Miller. Her SSN is 123-45-6789, her card 4111 1111 1111 1111 was charged twice, and she wants a callback on (415) 555-0134.
PromptVeil caught 3 sensitive items before your message reached ChatGPT.
  • 👤US Social Security number123••••89
  • 💳Credit card number411••••11
  • 👤Phone number(41••••34
Draft a polite reply to Jane Miller. Her SSN is [SSN_1], her card [CARD_1] was charged twice, and she wants a callback on [PHONE_1].
CancelSend anywayRedact & send
Developer · Config paste
Why does this deploy fail?
AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE
DATABASE_URL=postgres://admin:s3cret@db.acme.internal:5432/app
PromptVeil caught 2 sensitive items in what you are pasting into Claude.
  • 🔑AWS access keyAKI••••LE
  • 🔒Database connection stringpos••••pp
Why does this deploy fail?
AWS_ACCESS_KEY_ID=[AWS_KEY_1]
DATABASE_URL=[CONNECTION_STRING_1]
CancelPaste originalPaste redacted
Finance · Forwarded statement
Summarize this letter: Dear Investor, your account statement for folio no. 123456789/12 is attached. Contact us at care@fundhouse.com.
PromptVeil caught 3 sensitive items before your message reached Gemini.
  • 📄Looks like a personal financial document“Dear Investor”
  • 💳Account or folio number123••••12
  • 👤Email addresscar••••om
Summarize this letter: Dear Investor, your account statement for folio no. [ACCOUNT_NO_1] is attached. Contact us at [EMAIL_1].
CancelSend anywayRedact & send

Document markers such as “Dear Investor” are warn-only: they hold the send so you can think twice, but nothing in the sentence is rewritten. US identifiers include Social Security and taxpayer numbers, bank routing numbers with checksum, EINs, and Medicare IDs.

Features

A guardrail people leave switched on.

Security tools get disabled when they nag. PromptVeil is built to stay quiet, stay fast, and stay out of the way until it earns an interruption.

Send guard

Holds Return in an AI chat when the message contains something sensitive, and offers a redacted version.

Paste guard

Scans the clipboard on ⌘V into a chat. Redacts for that paste only and puts your original clipboard back.

Reversible placeholders

Copy an answer containing [CARD_1] and the real value is restored on your clipboard. Nothing is lost.

Document warnings

Recognizes investor letters, statements, payslips, HR and medical material, and material marked confidential. Warns without altering.

Allow-list

One click marks a value as safe forever. Only a fingerprint is stored, never the value itself.

Pause

Pause for ten minutes or an hour from the menu bar when you are working with data you own. It resumes on its own.

Activity log

Every catch is logged locally with masked previews. Reveal or copy originals when you need them, or keep them off entirely.

Custom terms

Project codenames, customer names, internal hostnames. Add them once and they are redacted everywhere.

Detection coverage

Global identifiers, plus the ones other tools forget.

Rules are validated, not just matched: card numbers pass a Luhn check, IBANs a checksum, Aadhaar its Verhoeff digit. Fewer false positives, so the warnings you do see mean something.

CategoryWhat is caught
API keys & tokensOpenAI, Anthropic, Google, AWS, GitHub, Slack, Stripe keys · private key blocks · JSON Web Tokens · bearer tokens
CredentialsPassword and secret assignments in config or code · database connection strings with embedded passwords
FinancialCredit and debit cards · IBAN · US bank routing numbers · EIN · GSTIN · IFSC codes · UPI IDs · account, folio, policy and customer numbers
PersonalEmail addresses · phone numbers · US Social Security numbers · ITIN · Medicare IDs · PAN · Aadhaar · Indian mobile numbers · optional on-device name detection
DocumentsInvestor and customer letters · account statements · tax forms · payslips · offer letters · medical records · anything marked confidential or internal
NetworkInternal IP ranges and hostnames (off by default)
YoursAny custom term list, matched as whole words, case-insensitive
Privacy

A privacy tool that phones home would be a contradiction.

PromptVeil makes no network requests. There is no account, no telemetry, no cloud scanning. Detection rules run on your Mac, the activity log is a file in your own Library folder, and the allow-list stores fingerprints rather than values.

It asks for one permission, Accessibility, because that is what lets a Mac app see a keystroke and read a text box in another app. It only looks at the apps you have listed, and only when you press Return or paste.

Pricing

Free while in early access.

Early access builds are free and fully featured. This is the planned pricing once PromptVeil ships.

Personal

$29 one-time

For developers, freelancers, and anyone handling other people's data.

  • All detection rules and India pack
  • Send guard, paste guard, reversible placeholders
  • Allow-list, pause, activity log
  • One year of updates, use on all your Macs
Get early access

Team

$6 per seat / month, billed yearly

For companies that need an answer to "how do you control AI data leakage".

  • Everything in Personal
  • Policy file deployable by MDM
  • Shared custom terms and allow-lists
  • Audit export and invoiced billing
Talk to us

Sold directly, outside the Mac App Store, because the App Store sandbox does not allow the keystroke interception PromptVeil relies on.

FAQ

Questions people ask before installing.

Does PromptVeil send my prompts anywhere?

No. It never opens a network connection. Scanning happens on your Mac with rules you can read in the settings. The only data that leaves your Mac is what you choose to send after PromptVeil has checked it.

Why does it need the Accessibility permission?

macOS only lets an app see keystrokes and read text boxes in other apps through Accessibility. PromptVeil uses it for two things: noticing Return and ⌘V in AI chats, and reading the message you are about to send. It does not watch other apps.

Which apps are covered?

The Claude, ChatGPT, and Perplexity desktop apps, plus Safari, Chrome, Brave, Arc, Firefox, and Edge when the tab is an AI chat such as ChatGPT, Claude, Gemini, Copilot, Grok, DeepSeek, or Mistral. You can add any app or site in settings.

Will it slow down my typing?

No. Nothing happens while you type. The scan runs only when you press Return or paste in an AI chat, and takes a few milliseconds.

What happens when I copy the model's answer?

If the answer contains placeholders such as [EMAIL_1], PromptVeil restores the real values on your clipboard, so pasting into your editor or email just works.

What about files and images I attach?

Not yet. PromptVeil inspects typed and pasted text. Attachment scanning is on the roadmap.

Is this a replacement for enterprise DLP?

It is a guardrail against accidents, not a barrier against a determined insider. For most individuals and small teams that is exactly the risk that matters, at a fraction of the cost and setup.

Early access

Be the first to try PromptVeil.

Early access builds are free. Tell us which AI apps you use and we will send you a build and a short setup guide.

macOS 14 Sonoma or later · Apple silicon and Intel