PromptVeil sits between your keyboard and every AI chat on your Mac. It catches API keys, passwords, card numbers, and personal data the moment you press Return or paste, and swaps them for placeholders you can reverse later. Everything stays on your Mac.
No account. No cloud. One permission, explained up front.
Copy-time scanners can't know where text is going. Browser extensions miss the desktop apps. PromptVeil watches the two keystrokes that actually move data into a chat.
Use ChatGPT, Claude, Gemini, or any other AI chat exactly as you do today. PromptVeil is invisible until it has something to say.
When you press Return or paste inside an AI chat, PromptVeil reads the text box and scans it on your Mac in a few milliseconds.
Sensitive values become placeholders like [EMAIL_1]. Send the redacted version with one click, whitelist a value forever, or stop the message.
Three real prompts, each stopped a keystroke before sending. Every value shown here is a documented test number, and every catch is exactly what the shipped rules produce.
Document markers such as “Dear Investor” are warn-only: they hold the send so you can think twice, but nothing in the sentence is rewritten. US identifiers include Social Security and taxpayer numbers, bank routing numbers with checksum, EINs, and Medicare IDs.
Security tools get disabled when they nag. PromptVeil is built to stay quiet, stay fast, and stay out of the way until it earns an interruption.
Holds Return in an AI chat when the message contains something sensitive, and offers a redacted version.
Scans the clipboard on ⌘V into a chat. Redacts for that paste only and puts your original clipboard back.
Copy an answer containing [CARD_1] and the real value is restored on your clipboard. Nothing is lost.
Recognizes investor letters, statements, payslips, HR and medical material, and material marked confidential. Warns without altering.
One click marks a value as safe forever. Only a fingerprint is stored, never the value itself.
Pause for ten minutes or an hour from the menu bar when you are working with data you own. It resumes on its own.
Every catch is logged locally with masked previews. Reveal or copy originals when you need them, or keep them off entirely.
Project codenames, customer names, internal hostnames. Add them once and they are redacted everywhere.
Rules are validated, not just matched: card numbers pass a Luhn check, IBANs a checksum, Aadhaar its Verhoeff digit. Fewer false positives, so the warnings you do see mean something.
| Category | What is caught |
|---|---|
| API keys & tokens | OpenAI, Anthropic, Google, AWS, GitHub, Slack, Stripe keys · private key blocks · JSON Web Tokens · bearer tokens |
| Credentials | Password and secret assignments in config or code · database connection strings with embedded passwords |
| Financial | Credit and debit cards · IBAN · US bank routing numbers · EIN · GSTIN · IFSC codes · UPI IDs · account, folio, policy and customer numbers |
| Personal | Email addresses · phone numbers · US Social Security numbers · ITIN · Medicare IDs · PAN · Aadhaar · Indian mobile numbers · optional on-device name detection |
| Documents | Investor and customer letters · account statements · tax forms · payslips · offer letters · medical records · anything marked confidential or internal |
| Network | Internal IP ranges and hostnames (off by default) |
| Yours | Any custom term list, matched as whole words, case-insensitive |
PromptVeil makes no network requests. There is no account, no telemetry, no cloud scanning. Detection rules run on your Mac, the activity log is a file in your own Library folder, and the allow-list stores fingerprints rather than values.
It asks for one permission, Accessibility, because that is what lets a Mac app see a keystroke and read a text box in another app. It only looks at the apps you have listed, and only when you press Return or paste.
Early access builds are free and fully featured. This is the planned pricing once PromptVeil ships.
For developers, freelancers, and anyone handling other people's data.
For companies that need an answer to "how do you control AI data leakage".
Sold directly, outside the Mac App Store, because the App Store sandbox does not allow the keystroke interception PromptVeil relies on.
No. It never opens a network connection. Scanning happens on your Mac with rules you can read in the settings. The only data that leaves your Mac is what you choose to send after PromptVeil has checked it.
macOS only lets an app see keystrokes and read text boxes in other apps through Accessibility. PromptVeil uses it for two things: noticing Return and ⌘V in AI chats, and reading the message you are about to send. It does not watch other apps.
The Claude, ChatGPT, and Perplexity desktop apps, plus Safari, Chrome, Brave, Arc, Firefox, and Edge when the tab is an AI chat such as ChatGPT, Claude, Gemini, Copilot, Grok, DeepSeek, or Mistral. You can add any app or site in settings.
No. Nothing happens while you type. The scan runs only when you press Return or paste in an AI chat, and takes a few milliseconds.
If the answer contains placeholders such as [EMAIL_1], PromptVeil restores the real values on your clipboard, so pasting into your editor or email just works.
Not yet. PromptVeil inspects typed and pasted text. Attachment scanning is on the roadmap.
It is a guardrail against accidents, not a barrier against a determined insider. For most individuals and small teams that is exactly the risk that matters, at a fraction of the cost and setup.
Early access builds are free. Tell us which AI apps you use and we will send you a build and a short setup guide.
macOS 14 Sonoma or later · Apple silicon and Intel