Questions and answers
Simple answers about PonoLens.
Learn what PonoLens does, what it cannot do, and how it handles your information.
PonoLens Support
What can we help you solve?
Ask about setup, missing activity, privacy, billing, or connected AI tools. Answers come from verified PonoLens help information.
What is PonoLens?
PonoLens helps you see what your AI coding tools do. It keeps a private history on your Mac and shows your prompts, changed files, and possible private information. PonoLens is not a firewall or antivirus app.
Does PonoLens upload my prompts?
No. PonoLens checks supported activity on your Mac and saves its activity list there. Redacted receipts and separately encrypted prompt originals stay on that Mac; they are not uploaded to the PonoLens website. Account and payment services receive only the small amount of information needed for your account and purchase. If you change saved-prompt redaction while signed in, account synchronization sends only the preference and its decision time, never prompt contents or encryption keys.
Can I turn off redaction for prompts saved on my Mac?
Yes, but saved-prompt redaction is on by default and recommended. With redaction on, the packaged Mac app saves the redacted receipt used by Prompt History, Search, and reports. It may also save the complete original separately in encrypted form so you can review a possible false positive. Turning redaction off requires accepting a warning because future prompt text is then stored in readable form. Commands, file paths, tool inputs, and other receipt fields remain redacted. Turning redaction back on sanitizes previously readable prompt text.
How do I view an original prompt after it was redacted?
Open the prompt receipt and select Show encrypted original. The private key is protected by macOS Keychain and tied to that Mac. PonoLens requests Touch ID where it is available; otherwise it relies on the signed-in Mac Keychain. The unlocked text appears temporarily in the receipt. It is not added to Search, PDF, CSV, or JSON exports. Deleting the receipt also deletes its encrypted original.
Can I recover encrypted originals on another Mac?
Not currently. Copying ponolens.db to another Mac is not enough because the private key remains protected by the original Mac’s Keychain. If that Keychain material is deleted or lost, redacted receipts remain readable but encrypted originals may be permanently unrecoverable. PonoLens does not store a recovery key on its website and does not offer a PIN reset for this feature.
What should I do if I send private information by mistake?
Stop the AI task and check the PonoLens activity card. If you sent a password, API key, or access token, turn it off and make a new one right away. If you sent customer, health, payment, work, or other private information, tell the person in charge and follow your incident steps. You can ask the AI provider or account owner to delete the chat, but deleting it does not undo the original send.
Which computer-changing commands need review?
When a supported AI tool exposes the command, PonoLens flags commands that may install or remove software, use elevated permission, change files, permissions, services, or settings, administer a remote service, or upload or download files. This includes common Homebrew, package-manager, Git transfer, deployment, release, cloud-storage, and file-transfer commands. When the tool also reports a completion result, PonoLens uses it to distinguish completed and failed activity. Coverage still depends on what the AI tool provides.
Does PonoLens flag Python, Perl, Node, and shell scripts?
It flags script commands with stronger warning signs, such as running from Downloads or a temporary folder, installer, deployment, update, or removal script names, risky inline code, a download piped into an interpreter, or making a file executable and immediately running it. Routine scripts are recorded only when ordinary experimental command monitoring is on. Commands run in an unrelated Terminal window are not visible.
Which AI tools work with PonoLens?
PonoLens works with Codex, Claude CLI, Cursor, and Windsurf, with Report Only coverage for Grok Build, Muse Code, Google Antigravity, OpenCode, the Oh My Pi (OMP) CLI, OpenClaw, Hermes Agent, and macOS Harness. With Codex chat, PonoLens can show what happened after a prompt was sent, but it cannot stop that prompt first. OpenClaw uses a native Report Only plugin; Hermes uses a Python Report Only plugin. Both report supported prompts and pre-action tool input without storing tool output. macOS Harness activity is reported only when its invocation is exposed by a configured Codex or Claude CLI parent session. Claude Desktop is not supported.
Which harness versions have been tested?
The minimum tested versions for this PonoLens build are Codex 0.155.1, Claude CLI 2.1.280, Cursor 3.19.19, Devin Desktop 3.10.35 for the Windsurf/Devin integration, Grok Build 1.0.25, Muse Code 1.3.0-R3401.1, Google Antigravity 2.12.2, OpenCode 1.18.30, Oh My Pi 18.1.18, OpenClaw 2026.9.6, and Hermes Agent 0.21.5+3084.gca16be5. These are the oldest versions verified on the current test Mac. Older versions may work but have not been tested. macOS Harness is not installed on the test Mac, so its minimum tested version has not yet been established.
How does the OpenClaw connection work?
PonoLens installs a local OpenClaw plugin and records supported agent prompts and pre-action tool input through OpenClaw’s native hooks. When OpenClaw supplies the fields, PonoLens also reports the selected model, provider, and token usage without storing model response content. Coverage is Report Only: PonoLens does not change prompts, tool input, approvals, or responses, and it never stores tool output. OpenClaw 2026.9.6 is the minimum version tested for this PonoLens build; older versions may work but have not been verified. Activity that bypasses those hooks is not visible to PonoLens.
How does the Hermes Agent connection work?
PonoLens installs a local Python plugin for Hermes CLI and Gateway sessions. It records supported submitted prompts and pre-action tool input. When Hermes supplies post-request metadata, PonoLens adds provider, model, and token counts to the same prompt receipt. Coverage is Report Only: the plugin sends no block or modification directive and PonoLens does not store conversation history, model response text, or tool output. Activity that bypasses the plugin hooks is not visible to PonoLens.
Why can a short Hermes prompt show high token usage?
Hermes reports tokens for the complete model request, not only the words typed in the visible prompt. Input can include Hermes system instructions, tool definitions, plugin context, and relevant conversation history. Cached input is shown separately. Reasoning tokens are normally included within output rather than added to the total again. PonoLens displays the counts Hermes reports and does not estimate missing usage, so a short question can legitimately have a large reported input count.
How do I verify that PonoLens is set up correctly?
Open PonoLens before the AI tool. Go to Agent status and choose Scan again. Confirm that the tool appears as installed, choose Enable system-wide if needed, then fully quit and reopen the AI tool. Use Test connection; this checks the local connection without sending a prompt to a model. Finally, send one short prompt containing only made-up information and confirm that a new receipt appears.
Why are prompts not appearing?
Keep PonoLens open and confirm that its collector says it is monitoring. In Agent status, scan again and verify that the AI tool connection is enabled. Fully quit and reopen the AI tool because many tools load plugins only at startup. Run Test connection, then create one new prompt using made-up information. Prompts sent before the connection was active cannot be recovered, and activity that bypasses supported hooks is not visible. If the test works but a new prompt is still missing, open a support request with the PonoLens version, AI-tool version, approximate test time, and a screenshot with private information removed.
Why are provider, model, or token details missing?
PonoLens shows these details only when the AI tool reports them for that request. Update to at least the minimum tested tool version, restart the tool, and create a new prompt receipt; older receipts are not backfilled. A valid receipt may still say “Not reported by this harness.” PonoLens does not estimate missing usage or inspect model responses to fill in missing metadata.
How do I review an AI tool’s computer access?
Open Sessions → Harness Details and select the active tool. PonoLens shows the access it can identify from local configuration and macOS. The result is not a complete macOS permission audit: the tool’s settings, terminal access, project folders, plugins, and approval rules can also affect what it can do. Remove access in macOS System Settings and in the AI tool when it is not needed.
Why does a PonoLens harness connection need a credential?
Listening only on localhost prevents another computer from reporting activity, but it does not identify which process on this Mac sent a receipt. PonoLens therefore gives each managed HTTP-based harness a separate random credential and rejects missing or cross-harness credentials. PonoLens installs and rotates built-in credentials automatically. Developers use a separate integration token from Settings → Developer integrations. This makes forged receipts harder, but it does not make the history tamper-proof if the Mac or user account is compromised.
Can PonoLens stop every prompt?
No. An AI tool must give PonoLens a supported way to check the prompt before it is sent. “Report Only” is the normal setting. “Redact” and “Block” are test features and work only with supported before-send connections.
What do green, orange, and red mean?
Green means PonoLens did not find private information or unusual movement. Orange means it found something you should review. Red means a supported connection truly stopped the action before it finished.
Why would I use PonoLens?
AI coding tools may send your words, code, files, passwords, email addresses, health details, or payment information to an online service. PonoLens helps you see what supported tools send and warns you when private information may be included.
How much does PonoLens cost?
Each installation has one 30-day free trial, started by its first owner account. Creating another account does not restart it. Personal Annual is $11.99 a year. Lifetime purchases are not currently offered. Family / Small Business is $49.99 a year for up to 6 accounts. Medium Company is $199 a year for up to 25 accounts. Each account can use up to two Macs.
Can I use a coupon code?
Yes. Select a purchase option and enter a valid promotion code in Stripe Checkout. Coupon availability, discount amount, eligible plans, redemption limits, and expiration are controlled by the promotion code configured in Stripe.
What happens after the 30-day free trial?
PonoLens keeps collecting activity locally, but activity sections, Search, reports, policies, and detail pages show the subscription screen until access is restored. Choose a plan on the Purchase page to reopen them.
Can another account use the same installation and history?
No. One Firebase UID owns an installation and its local database. An owner can request a transfer in desktop Settings. If Support approves it, PonoLens deletes the previous owner’s local database before the new owner is confirmed. The installation’s trial history remains, so a transfer does not create another trial.
How do I create and share a report?
In the Mac app, select Generate Report below Support. Choose the dates, activity, AI tool, outcome, and project. PDF is easy to read and share, CSV works well in a spreadsheet, and JSON works with technical tools. Reports may include the redacted prompt saved in the receipt, but never the separately encrypted original. PonoLens creates the report on your Mac and does not email or upload it. Review it before sharing.
Where is my login information kept?
The Mac app keeps your login and proof of purchase in macOS Keychain. It also uses Keychain-backed protection for the private key that opens encrypted prompt originals. These secrets are not stored as readable fields in the activity list. Simple display choices, such as text size, may be saved in local browser storage.
Does PonoLens guarantee that I follow every privacy law?
No. PonoLens can help with privacy work, but it cannot promise that you meet every law or rule. If private information was already sent, deleting it later does not undo the send.
Which computers can run PonoLens?
PonoLens Personal runs on macOS 13 or newer. There are separate downloads for Apple silicon Macs and Intel Macs. Windows and Linux are not supported yet.
How do I install PonoLens?
On the Download page, choose Apple silicon for newer Macs with an M-series chip, or Intel for an Intel Mac. Open the DMG, drag PonoLens.app onto the Applications folder, and then open PonoLens from Applications. This beta has not finished Apple’s signing and approval steps, so macOS may show an extra safety message.
How do I update PonoLens?
Open Settings in PonoLens. The App version & updates section compares the version on your Mac with the latest website version. If an update is available, select Update now. You can also choose Help → Check for Updates. Quit PonoLens, open the new DMG, drag PonoLens into Applications, choose Replace, and reopen it. Your local history and settings stay in ~/.ponolens. This beta does not install updates by itself.
How do I add an AI coding tool to PonoLens?
First install the supported AI coding tool. Keep PonoLens open, go to Agent status, and select Scan again. Find the tool and select Enable system-wide. Fully quit and reopen that AI tool so it loads the PonoLens connection. Expand its row and use Test connection, then use a made-up test prompt or Test event. Detection only means PonoLens found the tool; the test confirms that its PonoLens connection is ready.
How do I remove an AI coding tool from PonoLens?
This beta does not yet have a one-click remove button. Removing a connection requires editing that AI tool’s hook settings. Back up the settings file first, then remove only entries that mention ponolens-hook.mjs, src/adapters/hook.mjs, or the ponolens MCP server. Do not delete the whole settings file because it may contain your other tools and hooks. Fully quit and reopen the AI tool afterward. If you are not comfortable editing a settings file, ask PonoLens Support for help.