Security & privacy
Exactly what stays local, and what doesn’t
“Private” only means something if it’s specific. Here is where your data goes.
On your computer
- Your documents
- Search index
- Embeddings
- AI model (llama.cpp)
- Conversations & reports
Never uploaded. Works with the network unplugged.
Separate, optional online services
- Installer downloadOnce, from this site
- Model downloadOnly when you click Download
- Licence activationPro only, when launched: key + device ID
- Update checksOff unless you turn them on
In the desktop app
- Documents are read where they are. Pramvex does not copy them to any server.
- The search index, embeddings, conversations and reports are stored in Pramvex’s folder on your computer.
- The local engine and model server listen only on 127.0.0.1 and use a per-launch access token.
- AI answers are generated by a model running on your computer. Your questions are not sent anywhere.
- Update checks and diagnostics are off unless you turn them on.
When Pramvex uses the internet
- Downloading the app from this website.
- Downloading a model, only when you click Download in Settings › Models. Files come from pinned releases and are checked against published SHA-256 hashes.
- Licence activation, once Pro launches. It will send a licence key and an anonymous device identifier, never document content.
On this website
- No analytics, advertising or tracking cookies.
- No document uploads, ever. Support never asks for your files.
- Card payments, when Pro launches, are handled entirely by the payment provider’s hosted checkout.
Installer integrity
Pramvex installers are not code-signed: like our other B2R apps, we don’t use a paid Apple or Microsoft certificate, so macOS and Windows warn you once on first launch. Instead every installer (macOS, Windows and the Linux AppImage, .deb and .rpm) is published with its SHA-256, so you can confirm a file is exactly the one we built. Installers are versioned and never silently replaced. See releases for checksums.
Reporting a security issue
Please report vulnerabilities privately through the support page. Don’t include personal documents.
Full details are in the privacy policy.