Start here
Use a trusted private network
A paired phone or tablet can control the active Windows session. Use local Wi-Fi mode only on a home or otherwise trusted Private network. For internet access, use optional Premium Anywhere with its separate approval flow.
- Never create a router port-forward for port 8787.
- Never publish the setup page, pairing code, Anywhere QR link, or registration file.
- Allow Windows Firewall access on Private networks only; Anywhere does not require a public inbound rule.
Pairing
Short-lived codes and trusted sessions
Local pairing uses a rotating, single-use six-digit code shown by the Windows application. A successful local pairing creates an HttpOnly, SameSite session cookie on that device.
Stored local session tokens are one-way SHA-256 hashes. Anywhere uses a separate QR and device-key flow, not this cookie. PocketPilot does not store a Windows password, PIN, or Windows Hello secret.
Control boundary
Only fixed PocketPilot actions are accepted
The companion accepts a defined allow-list of media, app, pointer, display, and power actions. It is not a remote terminal and does not accept arbitrary scripts or commands.
Network safeguards
Public traffic and unknown hosts are rejected
The local companion rejects public-source addresses, unrecognized hostnames, cross-origin command requests, oversized requests, unknown fields, and actions outside its allow-list.
Anywhere makes outbound connections to a dedicated relay. It does not publish the local HTTP service or act as a general-purpose proxy. The PC checks device approval, permissions and Premium status before accepting controls.
Premium internet access
Anywhere: approve the connection, keep control on the PC
Anywhere is available to every Premium user with PocketPilot 1.4.0 or later. Select it from the Overview address dropdown, read the notice, and enable it deliberately. Premium is verified automatically; no registration file is required. Choose permissions, create a QR code, scan it privately, compare both device fingerprints, and approve the request on Windows. Reject a mismatch. No router port forwarding or separate VPN is required.
Control messages and screen pictures are encrypted between devices with identity checks, replay protection and expiring credentials. The relay sees connection metadata, not ordinary plaintext control content. Windows remains responsible for authorization. Local and Anywhere pairings are separate; possession of a relay transport token alone does not authorize Windows commands.
Every connection uses newly generated session keys for forward secrecy. Later theft of saved device identity keys alone should not reveal earlier recorded session content. This applies to sessions using the updated protocol, not traffic from older releases. Reconnecting discards the old session and does not replay input commands.
Keep the PC awake and online. Premium verification renews automatically; an extended verification outage, a stopped app, an expired phone token or an outage stops the connection. A token renews while connected; after more than 24 hours offline, a fresh QR may be needed. No audio, file transfer, wake-from-offline or protected Windows screen control is provided.
The paired browser keeps its keys in its own storage. Use that same browser when returning; clearing storage or changing browsers requires pairing again. Read the privacy notice for relay records, metadata and deletion.
Device access
Review and remove old devices
Use the Devices tab in Windows to review permissions, rename, pause or remove devices. Removing an Anywhere device also revokes its relay access. Forget on a connected phone waits for Windows to confirm removal before clearing its pairing; if offline, remove it from Windows instead.
Turning Anywhere off stops internet connections without deleting saved pairings. Use device removal when access should end permanently. Keep QR codes, registration files and license keys out of public support posts.