PromptRailPlugins

Privacy & security

A narrow route.
A clear boundary.

This policy explains what the PromptRail plugins for Codex and Claude Code process, what stays local, and what goes directly to your model provider.

Last updated July 10, 2026
Latest promptSent to PromptRail
Provider credentialsStay local
Model responseNot sent to PromptRail
01

Scope

This policy applies to the open-source PromptRail Codex and Claude Code client integrations. It supplements the main PromptRail Privacy Policy, which governs the hosted PromptRail service and account information.

02

Data sent to PromptRail

The UserPromptSubmit hook sends the latest user-submitted prompt to PromptRail’s hosted routing service so it can select an effort grade. The request is authenticated with the private machine authorization created during browser approval.

Codex routing requests include the selected Codex model identifier. Claude Code routing requests do not send the Claude session ID or model identifier to PromptRail.

03

Data that stays local

Provider authentication data, provider account identifiers, system and developer instructions, full conversation transcripts, attachments, tool definitions, and model responses are not sent to PromptRail.

Claude Code uses its session identifier only on your machine to match a hook decision with the corresponding local model request.

04

Local proxy and logs

The local proxy forwards provider requests directly from your machine to OpenAI or Anthropic. It binds only to 127.0.0.1, restricts forwarded paths, and does not log prompts or provider credentials. Operational logs contain only the selected grade, effort, and routing latency.

05

Local files and removal

Router configuration is stored under ~/.codex/promptrail-router or~/.claude/promptrail-router with user-only permissions. Uninstall removes the local authorization file and restores the provider configuration when it is safe to do so.

06

Security and user responsibility

Do not share PromptRail authorization or router configuration files. The clients reject unsupported provider authentication on subscription-only routes and do not follow upstream redirects automatically.

07

Questions and security reports

For privacy questions or data requests, email support@promptrail.ai. Do not open a public issue for a credential, authentication, local proxy, or cross-user data vulnerability; email us with the subject “Security report.”