Skip to content

End-to-end encryption

When you pair your phone, it and your computer agree on keys that only the two of them hold, using the Noise protocol. Every message after that is sealed with those keys before it leaves one end and opened only at the other, so the remotxai relay in the middle forwards data it cannot read. It does not protect you from everything. The computer sees your conversation in plain text, because the agent runs there. The relay and remotxai still see who connected, when and how much data moved. The web app on your phone is delivered by remotxai, so end-to-end encryption cannot protect you from a malicious version of the app itself. The first connection is protected by the verification code: you type a code at the computer that both ends derive from the handshake, so a relay cannot swap in its own key unnoticed.

  • Treat the computer as the trusted place. Anyone with access to it can read your sessions.
  • Check the verification code character by character when you pair. See Pair your phone.
  • Revoke a lost phone with remotxai pair revoke. The phone holds only its key, not your sessions. The history stays on the computer.
  • Your account: email, sign-in and the list of your computers.
  • Connection facts: timing, size and routing identifiers.
  • Files on disk, on the computer and in your phone’s browser. Use disk encryption on both.

Last updated: