Poket PC is built so that only your own paired devices can read your screen and your input, even when the connection crosses the public internet through our relay. The exception is Ask, which sends what a task needs to the AI model you choose. This page explains what is protected, what metadata still exists on the network path, and what risks remain your responsibility.
Every control session uses an authenticated key exchange based on Noise IK, with X25519 identities and ChaCha20-Poly1305 transport records. In plain terms:
If a packet is modified in transit, it fails authentication and is dropped.
Initial trust is set up with a QR code shown on the Mac and a six-digit code. Pairing works on the same Wi-Fi or, when the two are on different networks, through the relay:
The pairing code is mixed into the handshake transcript, not treated as a cosmetic confirmation screen. A wrong code produces a different transcript and the pairing fails. The pairing window is short-lived and single-use.
The QR code itself contains the six digits. The code stops a device that never saw the QR, such as one listening on the relay path, but not someone holding a photo of it, so keep the QR out of photos and screen shares while the window is open.
Poket PC uses two network paths:
The relay does not terminate app-level crypto. It cannot decrypt session content because keys are negotiated end-to-end by the paired devices.
End-to-end encryption protects content, not transport metadata. Our relay sees this metadata whenever it carries a session. Because the Mac helper keeps a standing connection to the relay for each paired device, the relay also sees the Mac’s IP address and each paired device’s routing token whenever the helper is running. On the relay path it can observe:
It does not reveal what is on your screen or what you type. Because each keystroke travels as its own small encrypted record, the timing and sizes can show when you type and roughly how much.
Security controls cannot remove all operational risk:
Use normal device hygiene: screen lock, OS updates, trusted local accounts, and revoking old paired devices.
At Screen and Tools reach, Ask looks at screenshots of your Mac’s main display and clicks and types on the Mac. Text on a web page, in a document or in a message can be written to look like an instruction, and the model may follow it. This is prompt injection. In 1.0, Poket PC limits what a misled task can reach; it cannot stop the model from being misled.
Keep Tools for tasks whose pages and documents you trust, and pick the narrowest reach that does the job.
You can revoke a paired device from the Mac helper at any time. Revocation immediately ends active sessions for that device and prevents reconnects until it is paired again.
For broader privacy details, including analytics and website cookies, read Privacy. For setup and troubleshooting, start at Support.
No. Screen and input traffic are encrypted end-to-end between your paired devices. The relay forwards ciphertext and does not hold the session keys.
It sees routing metadata needed to connect two endpoints: token, timing, packet sizes and IP addresses. It does not see screen or keystroke content.
Pairing uses a time-limited QR flow with a six-digit code mixed into the handshake transcript, so a mismatched code cannot establish trust.