Latest: v0.1.4
Download Pretzel Desktop
System-wide AI prompt DLP. Monitors all apps — including Chrome, Safari, and native AI tools — not just the browser.
🍎
macOS
Apple Silicon (M1/M2/M3/M4)
Download (93.7 MB)or via Homebrew
brew install --cask pretzel-desktopSystem requirements
- ✓ macOS 12+ (Monterey or later)
- ✓ Windows 10 / 11 (64-bit)
- ✓ Linux (glibc 2.28+)
- ✓ 50 MB disk space
- ✓ Admin rights for CA cert install
What it does
- 🔍 Inspects HTTPS traffic to AI chat sites only — everything else passes through untouched
- 🛡️ Applies your org policy to every AI request
- 🪟 Works with Chrome, Edge, Safari, Copilot
- 🔔 Decision window for warn/block actions
- 📊 Audit events sent to your dashboard
Not the TLS inspection you're thinking of
If you've read our take on why network-level TLS inspection is the wrong approach to AI DLP, this looks like a contradiction — it isn't. That critique is about corporate-proxy inspection: a gateway decrypting every app's traffic for the whole network, which breaks certificate-pinned apps and needs real IT infrastructure. Pretzel Desktop does something narrower: it runs locally on your own machine and only terminates TLS for four AI hostnames (ChatGPT, Claude, Gemini, and their variants) — every other app and site is blind-tunnelled straight through, untouched. It's the same "read the prompt before it's gone" principle as the browser extension, just extended to native apps that don't run in a browser tab.
After installing
1
Launch Pretzel Desktop
It installs a local CA cert and sets up your system proxy. You'll be prompted for admin password once.
2
Sign in with mykka.ai
Click the tray icon → "Sign in" to load your organisation's policy. Opens in your browser.
3
Done
The tray icon turns green. Every request to a supported AI site — from any app on your machine — is now checked against your policy.