Telemetry & Privacy
Last updated Reviewed against Prism v0.3.26
All of your traffic stays local
Prism is a local proxy. Your agent requests go from your machine to the provider you configured, and Prism is only the hop in between. The admin UI, the stats database and the managed SearXNG instance all listen on loopback only.
| Direction | What leaves your machine |
|---|---|
| Agent requests | Proxy traffic to your chosen LLM provider — exactly as if the agent called it directly. |
| Search tool calls | Only if your active search provider is a cloud one (Exa, Tavily, Brave or Serper). Managed SearXNG queries metasearch engines directly. |
| Remote MCP servers | Tool calls to servers you added, like any MCP client. |
| Telemetry | One anonymous heartbeat per day. |
What the heartbeat contains
| Field | Example | Purpose |
|---|---|---|
| distinct_id | a random UUID | Distinguishes installs. Generated locally, not derived from anything about you. |
| version | 0.3.26 | Which release is in use. |
| os | windows | Platform support priorities. |
| arch | amd64 | Platform support priorities. |
| used_today | true | Whether Prism proxied at least one request in the last 24 hours. |
| requests_24h | 10-99 | A coarse bucket: 0, 1-9, 10-99 or 100+. |
That is the complete payload. Notably absent: prompt text, response text, model names, provider names, token counts, file paths, API keys, client names, error messages and IP-derived identity.
Verify it yourself
Set PRISM_ANALYTICS_DEBUG=1 and Prism logs the exact payload it would send and then sends nothing. This is the intended way to audit telemetry rather than trusting a description of it.
# PowerShell $env:PRISM_ANALYTICS_DEBUG = "1" # bash export PRISM_ANALYTICS_DEBUG=1
Turn it off
| Method | Effect |
|---|---|
| Admin UI | Toggle telemetry off in the settings; the preference is saved in config.json. |
| Tray menu | Same toggle, reachable without opening the browser. |
| PRISM_ANALYTICS_DISABLED=1 | Hard kill switch. Overrides every other setting and also suppresses the first-run notice. |
# PowerShell $env:PRISM_ANALYTICS_DISABLED = "1" # bash export PRISM_ANALYTICS_DISABLED=1
The environment variable is designed for managed machines and CI, where a per-user toggle would not survive a reinstall.
Where the install id lives
The identifier and the last ping date are stored in analytics_id.txtin Prism's config directory — deliberately not in config.json, so pasting your config into a bug report cannot leak your tracker id.
# Windows %APPDATA%\prism\analytics_id.txt # macOS ~/Library/Application Support/prism/analytics_id.txt # Linux $XDG_CONFIG_HOME/prism/analytics_id.txt
Deleting the file gives you a fresh random id on the next start. Combined with removing config.json and stats.db, that removes every trace of local usage history.
Where it is sent
To PostHog's EU endpoint at https://eu.i.posthog.com/capture/, using a project key that is ingest-only by design and safe to ship in an open-source binary. The request has a 10-second timeout, so telemetry can never hold up startup.
The stats database is separate
Prism's dashboard data — requests, tokens, per-client breakdown, TPS history — lives in a local stats.db SQLite file that never leaves your machine. It stores metadata only, never request or response bodies. See Stats Dashboard.
First-run notice
On first launch Prism shows a short notice saying telemetry exists and how to disable it, and records that you saw it in analytics_notice_seen. If the kill switch is set, the notice is never shown, because there is nothing to disclose.