Poket PC Security: Encryption, Pairing and Relay Limits

Poket PC is built so that only your own paired devices can read your screen and your input, even when the connection crosses the public internet through our relay. The exception is Ask, which sends what a task needs to the AI model you choose. This page explains what is protected, what metadata still exists on the network path, and what risks remain your responsibility.

Session security model

Every control session uses an authenticated key exchange based on Noise IK, with X25519 identities and ChaCha20-Poly1305 transport records. In plain terms:

If a packet is modified in transit, it fails authentication and is dropped.

Pairing trust

Initial trust is set up with a QR code shown on the Mac and a six-digit code. Pairing works on the same Wi-Fi or, when the two are on different networks, through the relay:

  1. On the Mac helper, choose Pair New Device.
  2. In the Poket PC app on your iPhone or Android phone, scan the QR code.
  3. Check that the six digits match on both screens, then confirm on the phone (on iPhone, tap Codes match — Pair).

The pairing code is mixed into the handshake transcript, not treated as a cosmetic confirmation screen. A wrong code produces a different transcript and the pairing fails. The pairing window is short-lived and single-use.

The QR code itself contains the six digits. The code stops a device that never saw the QR, such as one listening on the relay path, but not someone holding a photo of it, so keep the QR out of photos and screen shares while the window is open.

Direct path and relay path

Poket PC uses two network paths:

The relay does not terminate app-level crypto. It cannot decrypt session content because keys are negotiated end-to-end by the paired devices.

Metadata you should assume exists

End-to-end encryption protects content, not transport metadata. Our relay sees this metadata whenever it carries a session. Because the Mac helper keeps a standing connection to the relay for each paired device, the relay also sees the Mac’s IP address and each paired device’s routing token whenever the helper is running. On the relay path it can observe:

It does not reveal what is on your screen or what you type. Because each keystroke travels as its own small encrypted record, the timing and sizes can show when you type and roughly how much.

What this does not solve

Security controls cannot remove all operational risk:

Use normal device hygiene: screen lock, OS updates, trusted local accounts, and revoking old paired devices.

Prompt injection

At Screen and Tools reach, Ask looks at screenshots of your Mac’s main display and clicks and types on the Mac. Text on a web page, in a document or in a message can be written to look like an instruction, and the model may follow it. This is prompt injection. In 1.0, Poket PC limits what a misled task can reach; it cannot stop the model from being misled.

Keep Tools for tasks whose pages and documents you trust, and pick the narrowest reach that does the job.

Revocation and recovery

You can revoke a paired device from the Mac helper at any time. Revocation immediately ends active sessions for that device and prevents reconnects until it is paired again.

For broader privacy details, including analytics and website cookies, read Privacy. For setup and troubleshooting, start at Support.

Can Poket PC read my screen?

No. Screen and input traffic are encrypted end-to-end between your paired devices. The relay forwards ciphertext and does not hold the session keys.

What does the relay see?

It sees routing metadata needed to connect two endpoints: token, timing, packet sizes and IP addresses. It does not see screen or keystroke content.

How does pairing stay safe?

Pairing uses a time-limited QR flow with a six-digit code mixed into the handshake transcript, so a mismatched code cannot establish trust.

Related