Privacy, without absolute promises.
Website
This site ships no analytics script, advertising tracker, or account form. There is no login gate on promtect.org, so the public site sets no Promtect session cookie. Cloudflare still processes operational request metadata such as IP address, user agent, URL, status, and timing for security and reliability. The staging site stays access-controlled for maintainers. Promtect itself does not add a marketing or analytics cookie.
Core beta
Core runs as a local loopback proxy and contains no Promtect telemetry or hosted control-plane dependency. Detection and the per-request vault run locally. Promtect forwards the remaining masked prompt and unchanged authorization headers to the upstream you configure; that upstream's privacy and retention terms apply.
Detection and audit limits
Only recognized matches in supported, uncompressed UTF-8 request bodies routed through Promtect are within the protection scope. Audit records are designed to contain detector names and counts, not detected values. The per-request vault zeroizes values it owns on drop; Promtect does not claim every memory copy made elsewhere is zeroized.
Waitlist contact
If you email the waitlist or support address, that message and the address you sent it from reach me and the email provider that carries it. I use it to tell you when there is something to try, and for nothing else.
Your choices
You can avoid waitlist contact, run Core without a Promtect account, select your upstream, use strict mode to prevent plaintext restoration, and remove local audit files. For access or deletion questions about data you sent to Promtect, email privacy@promtect.org. Requests to an upstream or Cloudflare must follow that provider's process.