Skip to content

Desktop app (power-up)

The desktop app is a power-up, not a fourth way to use CloakAPI. It runs the native tokeniser on your machine, exposes it to any local client through a one-click local proxy, signs receipts with an on-device key, and can drive complete-local models. The three ways to use CloakAPI stay the same (API / SDK / proxy · Chat · browser extension); the desktop app makes them stronger.

What the desktop app adds — and what it does not

The desktop app does not widen detection coverage. It does not detect more PII than the browser extension or Chat. In our own non-Latin name testing the desktop path detected fewer names than the browser path, not more, so do not install it expecting a stronger detector.

Every surface runs the same detection design: the deterministic structured-identifier lane, plus the name lane’s gazetteer floor and an optional on-device NER model (Xenova/bert-base-multilingual-cased-ner-hrl, quantised ONNX), fetched on first use and cached. The desktop runs it natively; the browser surfaces run it through WebAssembly.

The engine build is not identical across surfaces. Several engine builds and rulesets are live at any one time, and a surface is rebuilt when its product is, so the version and hash that ran your send are the ones recorded on that send’s receipt — read them there rather than assuming one estate-wide build. What each lane does and does not catch is documented on Detection coverage.

What the desktop app genuinely adds:

  • A one-click local proxy. A Local proxy toggle in Settings starts an OpenAI/Anthropic-compatible endpoint on http://localhost:8799/v1, so any local client, script or IDE gets the drop-in proxy without touching a CLI. See Local proxy.
  • It works outside the browser. The extension only acts on its four supported sites; the desktop tokeniser is reachable by anything on your machine that can point at a local endpoint.
  • On-device receipt signing. Receipts are signed with a P-256 key held on your machine, including zero-egress receipts for local runs. For calls that go through the gateway, the gateway countersigns the client attestation; complete-local runs have no gateway countersignature. A locally signed receipt carries its own public key, so checking it shows the receipt was not altered — not who signed it.
  • Complete-local models. Chat turns can be routed to a local model on your own hardware, with no cloud call at all.

Download

Tip version 1.2.5 (Windows and Linux) is published on the downloads page. Neither platform is code-signed. Verify the SHA-256 of the file you downloaded against the downloads page or the release-integrity register before running it. Older versioned installers may still answer HTTP 200; install the tip named below (or whatever the register currently marks available), not an older row because it still downloads.

Linux x86_64 — 1.2.5 (available)

PackageDownloadSHA-256
AppImage (x86_64)CloakAPI-1.2.5-x86_64.AppImagef39ff003f05181780d6d950a652ef5653e50be8dbc1249e0aaa5e8a800677970
.deb (amd64)CloakAPI-1.2.5-amd64.deb7d1e24183ee22dd9b880572b25e47a80d5b4687da9cabaf459f5cc9a61f0e54f

1.2.5 is unsigned. Verify the SHA-256 of the file you downloaded before running it. No .rpm is published yet. macOS is still coming, pending Apple notarisation.

Windows x64 — 1.2.5 (available)

PackageDownloadSHA-256
Portablecloakapi-desktop-1.2.5-x86_64.exe0350444ef02b2789d7009728ad08ada45be791d47b0012c0a15624e202aa8014
NSIS setupCloakAPI-1.2.5-x64-setup.exee06a858c83ee37e9291b300531a0df938c725c06d58a268973338d08ee2d3e42
MSICloakAPI-1.2.5-x64.msia02ab8a41be6e238cc5b944e7d8702daa06da10b83c2f15053ac4ccd19565446

1.2.5 is unsigned. Hashes above were measured from the release-integrity register on 2026-09-26 (http_status: 200). Prefer those three tip packages over older Windows rows that may still download.

Windows x64 — 1.0.0 (withdrawn)

macOS is still coming, pending Apple notarisation, and no Linux .rpm is published yet. Use the Email me when ready button on the downloads page to be notified when those land.

Good to know

  • Paid, key-backed, fail-closed. Local tokenisation requires a CloakAPI account with balance; if it cannot tokenise, it blocks rather than leak.
  • Pricing is usage-based, USD only — a flat markup on the underlying model cost (plus the small client-side metering fee). See pricing.
  • How it works end-to-end: How privacy works.