
PrivacyFence
io.github.privacyfencev5.2.1Updated Sep 29, 2026
Needs the PrivacyFence app from privacyfence.eu: human approval and audit for AI access to your data
Installation
In SourceWeft
- Open PrivacyFence in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
PrivacyFence
AI access without giving AI the keys. Approve the sensitive. Automate the routine.
PrivacyFence is an open-source privacy and approval gateway between AI assistants and your business systems. It connects MCP-compatible assistants such as Claude Desktop and Claude Code to Gmail, Google Drive, Calendar, Slack, Salesforce, Jira, Confluence, Telegram, and more.
PrivacyFence enforces, independently of the AI, what an assistant may see and do. Sensitive reads and consequential actions require human approval, while routine requests can be automated by policy. Optional PII detection runs locally before personal data reaches the AI, and every decision is audited.
PrivacyFence runs on an employee’s own computer (macOS, Windows, or Linux) or as a central deployment on infrastructure the organization controls, allowing web clients such as claude.ai to connect as well. Connector credentials stay with PrivacyFence, never with the AI client, and no data passes through PrivacyFence-operated servers — there are none.
Website: privacyfence.eu · Download: privacyfence.eu/download · Docs: privacyfence.eu/docs
Why
Giving an AI assistant access to Gmail, Drive, Slack or Salesforce usually means giving it a standing permission and trusting it to use that permission well. Being allowed to read a record is not the same as wanting it sent to an AI, and a tool name in a client's prompt says little about what is about to change. PrivacyFence puts an independent control point between the assistant and your systems: the AI asks, PrivacyFence decides, and you see what is at stake before it happens.
What it does
- Human approval for sensitive reads and for writes, on cards that show the actual content or change, who is asking and why — not a raw tool name or JSON payload.
- Local PII detection before a read reaches the AI: likely personal data is highlighted, and it sends the request to a card even when a rule would have let it through.
- Policy-based automation: narrow always-allow rules (a sender domain, a Drive folder, a Slack channel, a Jira project) let routine requests run without a card.
- An audit log of every accepted, denied and automatically approved request, chained so that an edit made without its key is detected.
- Credentials stay with PrivacyFence. On a packaged install it runs under its own service account, so the AI client, which runs as you, cannot read them or approve its own request.
- A defined set of connectors, each tool with a gate fixed in code. PrivacyFence is not a generic proxy for arbitrary MCP tools.
How it works
Claude Desktop connects through the PrivacyFence extension (PrivacyFence.mcpb); Claude Code and
other clients that speak Streamable HTTP connect to the local /mcp endpoint directly; in an
organization deployment, clients such as claude.ai and ChatGPT (Developer Mode) sign in with OAuth
through the organization's identity provider. How it works walks one read and one
write through, card by card.
Platforms
Tested with Claude Desktop and Claude Code on every install, with ChatGPT desktop on macOS, and with claude.ai and ChatGPT (Developer Mode) through an organization deployment; any MCP-compatible client can connect. See Platform support.
Connectors
Connectors summarizes what each one reviews and which writes need approval; the Tools reference lists every tool and its gate.
Quick start
- Download the installer for your platform from privacyfence.eu/download and run it.
- Sign out and back in once, so your account's new group membership takes effect.
- Add a passkey when the companion app (menu bar, tray, or applications menu) asks, and keep the recovery code.
- Open Settings from the companion and connect your services.
- Connect Claude Desktop with
PrivacyFence.mcpb, or Claude Code with the/mcpendpoint. - Ask your assistant for something, and approve it on the card.
Step by step for each platform: Getting started, then macOS, Windows or Linux. For claude.ai, ChatGPT or a whole team, see Organization deployment.
Documentation
- Getting started and Connecting a service
- Approvals and policy: cards, the PII check, always-allow rules, the privacy filter
- How it works: the daemon, the MCP endpoint, PrivacyFence's own tools, unattended sessions
- Configuration reference: every
settings.yamland organization-bundle key - Organization deployment: running PrivacyFence centrally
- Security and compliance: trust boundary, privilege separation, audit log
- All published docs: privacyfence.eu/docs. Contributing: CONTRIBUTING.md. Changes per release: CHANGELOG.md.
Limitations
PrivacyFence is independent open-source software, not a certified compliance product. It has no
certification, business-continuity plan or SLA, and does not by itself make a deployment compliant
with any regulation. It does not protect against root or a local Administrator, or against local
code on an install that is not packaged (a source checkout or a pip install). A process running
as you can read the local review screen, though not approve from it, and in local mode the name an
AI client gives is never verified. The full list is
What PrivacyFence does not claim.
To report a vulnerability, see SECURITY.md.
License
Source: README.md at commit cdedb14
Tools
0Version history
1- v5.2.1LatestSep 29, 2026


