PocketPilot

PocketPilot 1.4.0

Choose your computer.

Install on the computer you want to control. Your phone or tablet connects in its browser.

Windows

Windows 10 or 11 · 64-bit

EXE installer · 105.64 MiB

Not digitally signed. Windows may block the installer or show an unknown-publisher warning. Read Windows setup

Download for Windows

macOS

macOS 14 or later · Apple Silicon

DMG installer · 123.68 MiB · M1 or newer

Not Apple-notarized. macOS may block the first launch. Read Mac setup

Download for Mac

Core controls are free. PocketPilot Anywhere is included with Premium.

← Back to PocketPilot

Website and Anywhere privacy

Website privacy notice

This notice covers the website, Premium checkout, licensing, support, and optional PocketPilot: Anywhere connections. Free local Wi-Fi control does not use the relay.

Published by Christian Tchobansky · Appler's ShopUpdated 10 September 2026Plain-text copy ↗
01

Mac app permissions

Permissions stay under your control

On macOS, Screen Recording allows picture sharing, Accessibility allows approved input controls, and Automation may be requested for system power controls. Audio is not captured. The app checks permission status locally; this status is not a website analytics event. Permission requests do not send a test power command. You can revoke permissions in System Settings.

Mac pairing and activation secrets are stored locally using the app's protected storage. The same optional Anywhere connection processing described below applies to Windows and Mac.

02

Who is responsible

Your privacy contact

Christian Tchobansky, trading as Appler's Shop, is responsible for the processing described here.

Privacy requests: PocketPilot website support form

03

Website and support

Only the data needed to operate the service

The website host processes ordinary request information such as IP address, time, requested page, device/browser information, and security signals to deliver and protect the site. PocketPilot does not use advertising trackers or create marketing profiles.

PocketPilot keeps daily aggregate totals of qualifying website entries and installer download starts. A website entry is counted only when a public page is opened directly or from outside PocketPilot. Reloads, navigation within the site, background loading, administrative traffic, and excluded networks are omitted. Each ordinary aggregate record contains only the UTC day, metric name, and total count. This ordinary site counter does not use an analytics cookie or store a visitor identifier, referrer, page-by-page history, or exact event time. These totals are estimates, not unique-person counts, and may still include automated traffic.

To exclude the owner's network from these totals, Cloudflare's edge-provided network address is normalized and converted to a server-keyed one-way value before comparison or storage. IPv6 addresses are reduced to their network prefix for this purpose. PocketPilot does not store or display the raw address. The resulting pseudonymous exclusion value is used only to prevent owner and test traffic from entering the aggregate counters.

Administrative areas are restricted and protected. Their access process and security configuration are intentionally not published. Short-lived abuse-prevention data is used only to protect those areas and is not used for advertising or visitor profiling.

When you use the support form, your name, reply email, optional purchase reference, request category, and message are encrypted with a server-only key and stored in the website database so the owner can review and answer the case through PocketPilot's protected support system. Administrative replies are encrypted there as well. The private notification email contains only the case reference, category, and a private case-management link—not the customer's contact details or message. For a referral-link deletion request, the server uses the secure referral receipt cookie to attach the correct referral reference and approval state; the form does not send a referral ID. The raw source IP address is not stored. One-way values derived from the request token, payload, source address, and email address support duplicate protection and abuse limits.

When you request a referral link, PocketPilot stores the public name, requested link, sharing plan, request status, reference, review times, completed-download total, and the time of a statistics reset or link-name change. The raw source IP address is not stored; a server-keyed one-way value is used only for short-term abuse limits. A secure, HttpOnly request-receipt cookie lets the same browser check the decision, view private referral statistics, change an approved link name, and submit a verified deletion request. The cookie lasts for up to 180 days and its lifetime is refreshed when that browser successfully opens its referral statistics.

An approved referral link first shows a choice. If you agree to referral attribution, PocketPilot sets a secure, HttpOnly, SameSite cookie for 30 days containing a signed referral reference, expiry, and random nonce. If one complete Windows installer is then delivered, PocketPilot stores a server-keyed one-way attribution value, the referral reference, release version, and completion time. This prevents the same signed attribution receipt from being counted twice without storing an IP address, email, user-agent, browsing history, or the raw cookie. Declining sets no referral attribution and never blocks the site or download.

04

Payments and licensing

PayPal handles payment credentials

PayPal and, when selected, the PayPal-backed Apple Pay or Google Pay integration process payment credentials and billing contact data. PocketPilot receives and keeps payment references and status, a one-way browser purchase-claim identifier, the recorded checkout acknowledgement version and time, license issuance and email-delivery details, and activation records. An activation record includes its activation identifier, the installation's public key and derived public identifier, activation and verification times, and the related purchase reference. Raw Windows hardware serials and the installation's private key are not uploaded. PocketPilot never receives complete card details.

The owner may issue a complimentary Premium license without PayPal. PocketPilot then keeps the license environment, an opaque license identifier, a private owner label, issuance and rotation times, generation, active or revoked status, and activation details. The formatted signed license key is shown to the owner when created or rotated but is not stored as a full key in the complimentary-license ledger. Complimentary grants are kept separate from purchases and revenue.

A secure, HttpOnly payment-claim cookie lets the same browser recover its verified purchase. It lasts for up to one year and is not used for advertising. A payer email returned by PayPal or Google Pay, or a license-delivery email the buyer explicitly enters after verified payment, may be sent to the transactional email provider for delivery but is not stored in PocketPilot's payment database.

05

Service providers

Limited, purpose-specific recipients

  • Cloudflare hosts the website and encrypted support-case database, and provides the HTTPS edge and tunnel used to reach the Anywhere controller and relay.
  • PocketPilot's server operator and network providers operate and connect the separate Anywhere relay; this is not the website payment or support database.
  • PayPal processes checkout, PayPal payments, and the PayPal-backed Apple Pay and Google Pay options.
  • Google provides the Google Pay wallet interface and the private inbox used to receive case notifications.
  • Resend delivers purchase emails, support acknowledgements, case notifications, and owner-written support replies when configured.

These providers receive only the data needed for their role and may process information in countries outside the EEA under their applicable safeguards and terms.

06

Retention and legal basis

Kept only while there is a reason

Purchase, payment, licensing, and purchase-related support data is processed to perform the Premium contract or take requested steps connected with it. Accounting and consumer-law records are processed to meet legal obligations. Site security, abuse prevention, reliable message delivery, general support, referral-request review, and the establishment or defence of legal claims are processed for the seller's legitimate interests in safely operating and supporting PocketPilot. Optional referral attribution is processed only after the visitor's consent. The digital-delivery confirmation is recorded as part of the purchase contract.

Encrypted support-case content, encrypted owner replies, and related delivery metadata in the website database are assigned an expiry 730 days after submission and are deleted during later support-system maintenance activity. The encryption key remains server-only. One-way rate-limit values are removed after their applicable short abuse-prevention windows. Case notifications and correspondence held by email providers are kept only while needed to handle the request or establish or defend claims, subject to the mailbox retention process. Data may be kept longer when required for a dispute or by law. Purchase and accounting records are retained for the periods required by applicable law.

Pending and rejected referral requests are assigned an expiry 180 days after submission and are removed during later referral-system maintenance. Approved and later-deactivated link details and the non-identifying completed-download total remain so the owner can operate active links and preserve the admin history. Pseudonymous referral conversion records provide the last-30-days and latest-completion statistics; they are assigned a 730-day expiry and later deleted without reducing the stored total. The owner can reset a link's visible completed-download total to zero. A reset does not delete existing pseudonymous conversion records, because they remain necessary until expiry to prevent the same signed attribution receipt from being counted again; conversions completed before the reset are excluded from the recent and latest-completion statistics. Changing a link name keeps the same referral reference and statistics, while the former name is retired so it cannot be reassigned. If the owner approves a verified deletion request, the referral link and its pseudonymous conversion records are deleted and the public name remains retired to prevent later takeover. The 30-day attribution cookie can be removed at any time through browser settings; a later visit to a referral link asks again before replacing it.

Complimentary-license records, including revoked tombstones and their activation history, remain so PocketPilot can enforce revocation, prevent reuse on another installation, and preserve the owner's license audit history. Revocation stops new activation and online renewal, but an already signed offline activation lease may remain valid until its expiry. Updated releases use 7-day leases. Older releases continue receiving legacy 30-day leases during the compatibility period and must update before legacy issuance is retired; the seven-day maximum therefore applies only after an installation has converted to the current lease version.

No solely automated decision with legal or similarly significant effects is made about you.

07

Your choices

Access, correction, deletion, and objection

You may ask for access to or correction of your personal data, and where applicable request deletion, restriction, portability, or object to processing. You may also complain to the competent data-protection authority.

Use the website request form. Identity or purchase verification may be requested before disclosing or changing records.

08

Optional Premium connection

PocketPilot: Anywhere data handling

Anywhere is an opt-in internet connection available to every Premium user with version 1.4.0 or later. Your PC and paired browser connect through relay.pocket-pilot.net; the mobile controller is served at remote.pocket-pilot.net. Free local Wi-Fi control does not use this relay. No Windows password or PIN is requested, and your Premium key is not used as a relay password.

To enable and renew access, the PC sends a signed Premium activation proof and proves possession of its protected activation identity. The relay verifies these proofs and stores a one-way binding derived from the license and installation identifiers, alongside the connection registry. It does not receive payment-card details or the installation's private activation key. Verification uses short-lived challenges; the PC renews access automatically while enabled.

Control messages, entered text, app information and icons, and transient screen pictures are encrypted between the paired devices. The relay forwards this encrypted content and is not designed to decrypt or record it. It does not carry PC audio. Connection infrastructure can process IP addresses, request times, browser information and security signals. The relay can observe random connection/device identifiers, connection timing, traffic size, and disconnect reasons; encryption does not hide this metadata.

The relay registry stores random PC-room and mobile-peer identifiers, one-way hashes of transport credentials, expiry times, and aggregate traffic accounting. Device names, chosen permissions and trusted device identities are held on the Windows PC. The paired browser stores its own non-extractable private key and connection credentials in IndexedDB; this is necessary connection storage, not an advertising cookie. Clearing it requires a new pairing. The invitation secret is carried in the URL fragment, removed by the controller, and is not included in the page request.

Active socket state and unused invitations are held in memory and disappear on expiry or service restart. Removing a phone revokes its active registry entry. Expired mobile entries are also pruned when another controller is enrolled. PC registrations and remaining registry entries do not have a scheduled automatic deletion job: expiry blocks access but is not deletion. They remain until operator removal. Local registry backups retain the latest 14 scheduled snapshots, so removed records can remain in those backups until rotation. The application event log contains fixed service events rather than control content and retains seven rotations. Infrastructure providers have their own operational retention; these local periods do not describe Cloudflare's records.

Connection processing is necessary to provide the optional service you request; abuse controls and limited operational records support the legitimate interest in keeping it secure and reliable. Switching Anywhere off stops new relay connections without deleting saved pairings. Use Windows → Devices, or Forget on a connected phone, to remove access. For registry deletion or other data rights, use private support; never include a registration file, pairing link, or private key. Browser storage can be cleared separately after access is removed.

Fresh session keys provide forward secrecy for connections using the updated protocol: later theft of saved identity keys alone should not reveal previously recorded session content. This does not change the protection of older traffic. Independent security review is pending. A compromised paired device or controller page can expose access and content while in use. Read the security guide before sensitive activity.

09

Windows remote

Your PC screen stays separate from the website

In local Wi-Fi mode, the Windows companion serves the remote directly on your trusted private network. Anywhere instead forwards encrypted screen pictures through its separate relay. Neither mode uploads screen pictures to the marketing website, PayPal, or the support system unless you choose to share a screenshot yourself.