Documentation
Everything, in one place.
How to install and run PromptDust, how to read what it finds, exactly how exposure is scored, and the privacy guarantees in full. Start with the overview, or jump to what you need.
Getting started
Overview PromptDust maps where AI tools store your conversations, caches, and credentials on your own machine, and shows what makes each copy more exposed. Read-only, local-only, metadata-only. Quickstart Install PromptDust and run your first scan in about a minute, on macOS, Windows, or Linux, with the desktop app or the command line. Install and verify Install the PromptDust desktop app and command line on macOS, Windows, and Linux, get past the first-launch warning, and verify a download with checksums, provenance, and SBOMs.
Using PromptDust
The desktop app How to run a scan in the PromptDust desktop app, read the results, keep a history of past scans, reveal a store on disk, and export a report. CLI reference Every PromptDust command and flag, what each one prints, and the environment variables that control telemetry and crash reporting. Reading your results What a PromptDust finding means, how to read the exposure level, what each amplifier is telling you, and what you can do about it. How exposure is scored The exposure level is deterministic and additive. Here is the exact model, base sensitivity plus amplifier weights, and why critical always means off-machine exposure.
Trust and privacy
Privacy and threat model PromptDust is a tool about privacy, so it holds itself to a strict standard. The four guarantees, what it can send and the consent rules, what it touches, and what it deliberately does not do. Telemetry PromptDust telemetry is opt-in and off by default. The exact anonymous payload, how to manage it, the per-run random id, and every way it stays off.
Reference
FAQ Common questions about PromptDust, what it sends, whether it reads your conversations, whether it deletes anything, and why a synced folder can score critical. Contributing coverage PromptDust is developed in-house, but its coverage is community-built. How to describe a tool it does not map yet, or fix an entry that is wrong, safely.