Free during the betaVersion 0.4.4macOS & Windowsproprietary licenceRead what to expect
Privacy

Privacy notice.

Prompt to Page is built so your work doesn't leave your machine. Here's exactly what that means in practice.

On-device by design

All prompts, generated pages, accessibility-check results, and exports stay on your device — macOS or Windows. There is no Prompt to Page account and no cloud sync. During the closed beta the app sends two limited usage events, described below — nothing else is collected.

What leaves your device

The only outbound network traffic Prompt to Page initiates is:

  • The one-time model download when you choose the built-in runtime, fetched from the model provider you select.
  • Update checks against the GitHub releases page — on by default, and new versions install only with your consent. You can turn checking off in Settings → Updates.
  • Two beta usage events (Aptabase) — see below.

If you use the Ollama or LM Studio routes, traffic stays between Prompt to Page and those local services on your machine.

Beta usage events

During the closed beta, Prompt to Page sends two limited usage events (app_started and app_exited) to Aptabase by default when your device is online, to measure aggregate use and improve the app. They never include prompts, generated pages, project content, model names, file paths or persistent install/account identifiers. Turn them off any time in Settings → Privacy.

Aptabase, the analytics processor, derives a daily rotating identifier from connection data and states that analytics may be stored for up to five years. A previously saved opt-out is always respected. The complete UK-GDPR privacy notice (lawful basis, retention, your rights) is being finalised; this section is the factual description of what is sent today.

Feedback and error reports (optional)

Reports are user-initiated only — the app never sends anything in the background. You can start one in two places: a feedback card that appears once after your first prototype export, and a ‘Share this error report’ button shown alongside an error. Before anything is sent you see the full report, and it leaves your device only when you press Send.

A report carries the app version, your platform and setup details (things like your operating system, the backend and model in use, and recent local setup diagnostics), plus anything you type in the message box. The only contact detail a report can contain is a reply email, and only if you choose to type one so the maintainer can respond. A report never contains your prompts, your generated pages, or any project content, and it carries no install or device identifier, so reports cannot be tied back to a machine or linked to one another.

Reports are sent over HTTPS to infrastructure operated by Courtney Allen (hosted on Cloudflare), where they are stored and emailed to the maintainer. They are kept only to investigate problems and improve the app. If a send fails, nothing is queued or retried — the app offers to copy the report or open it in your email client instead. To have a report deleted, email the address above; if you supplied a reply email, sending from it helps us find your report.

Share for testing

The Share for testing feature serves your prototype on your local network only, and shows a QR code so a teammate on the same Wi-Fi can open it on their phone. Nothing is uploaded to a hosted service, and the link only works inside that network.

Works offline and behind a firewall

After the one-time model download, generation, preview, checks and exports all run offline — the app's core work needs no connection, so it runs on isolated networks and in environments where outbound internet is restricted.

“Offline” here describes the work, not the whole application. When the device is online, the app still checks for updates and sends the two usage events above unless you turn them off (Settings → Updates and Settings → Privacy). With both turned off, and the model already downloaded, Prompt to Page makes no outbound connections of its own.

What on-device processing does and doesn't change

Keeping generation local removes a category of risk: there is no hosted model, no prompt log held by a third party and no service content in transit. That is a real reduction, and it is the reason the app is built this way.

It is not a substitute for your organisation's own assurance. Installing any desktop application still raises questions your IT, security and data-protection colleagues are entitled to ask — software and model provenance, update and signing behaviour, endpoint security, and what content people are allowed to put into a prototype in the first place. Where a prototype would involve personal data, your organisation still needs to decide whether a DPIA is required. Prompt to Page running locally changes the shape of those questions; it doesn't answer them for you.

If you're assessing the app for a public-sector organisation and need detail that isn't on this page — hostnames, dependencies, model provenance — email the address below and ask. Anything I can document, I will.

What to put in a prototype

Prototypes are for testing ideas, so synthetic content is the right default. Made-up names, addresses and reference numbers test a journey exactly as well as real ones.

Please don't paste real case files, resident or patient records, unpublished identifiable research, or anything else you wouldn't want sitting in a prototype folder on a laptop. The app keeps that content on your device, but it applies none of the controls a live service would — no access control, no retention rules, and an export or a local-network share can move it somewhere you didn't intend.

Contact

Privacy questions: courtney.rj.allen@gmail.com.

Not affiliated with GOV.UK

Prompt to Page is an independent project by Courtney Allen. It is not affiliated with, endorsed by, or connected to the Government Digital Service, the Crown, or any UK government body.