🌳 Conoti

한국어

How it works

Your AI Tasks conversations stay on your PC,
and the Conoti server cannot read them

AI Tasks in Conoti lets you follow and reply to the AI running on your PC (Claude Code, Codex) from your phone. The Conoti AI app (formerly AI Inbox) on the PC and the Conoti app on the phone set up encryption directly with each other; the Conoti server in between only handles sign-in, passing along ciphertext, and content-free notifications.

How an AI Tasks connection is builtAn end-to-end encrypted tunnel joins the Conoti app on your phone and Conoti AI on your PC. The Conoti server handles sign-in and notifications, passes along only unreadable ciphertext, and stores no conversations. Conversation history is stored on the PC. Conoti server Sign-in · Notifications Account check · content-free alerts Relay — only ciphertext passes Pairing kept in memory · holds no keys Stores no conversations Your phone Conoti app (decrypts) $ claude Your PC Conoti AI · Claude Code etc. Stores history How an AI Tasks connection is builtAn end-to-end encrypted tunnel joins the Conoti app on your phone and Conoti AI on your PC. The Conoti server handles sign-in and notifications, passes along only unreadable ciphertext, and stores no conversations. Conversation history is stored on the PC. Your phone Conoti app Conoti server Sign-in · Notifications Account check · content-free alerts Relay — ciphertext only Holds no keys Stores no conversations $ claude Your PC Conoti AI History
The locks sit only at the two ends (phone and PC). While passing through the server, content stays encrypted.
One original, on your PC

Conversation history is stored in Conoti AI's database (SQLite) on your PC. The phone app asks the PC each time and only shows it on screen; it writes no copy of the conversations to disk.

Only the two ends can unlock it

Everything between phone and PC is locked with end-to-end encryption (the Noise protocol, IKpsk2). Keys are created inside each device and are never sent to the server.

The server only hands things over

The server pairs the two connections and passes the ciphertext through as-is. Pairing state lives only in memory, and passing content is neither decrypted nor logged.

What the server can and cannot see

Saying "the server knows nothing" would be an overstatement. Some information is needed to connect you and send notifications. Here is the boundary, exactly.

👁 What the server can see

  • Account — your social sign-in account and sign-in sessions (sign-in tokens kept as hashes, not originals)
  • Devices for notifications — notification tokens and language settings
  • The outside of a connection — IP address, connection time, message sizes and counts, app version, and a device number that tells it the same phone reconnected
  • That a notification was sent — when, what kind (new result, schedule, …), and to which account. With notifications on, also which PC (IP) sends alerts to which account

🔒 What the server cannot see

  • What you asked the AI and the replies you send from your phone
  • The AI's answers and summaries
  • Session names and project folder paths
  • Images you exchange
  • Encryption keys — device private keys and connection keys

Where each piece of data lives

● stored · — none · on screen = fetched and shown only while viewing · ciphertext = passed on without decrypting. "Your phone" means the phone app — for a web browser, see "Connecting from a web browser" below.
DataYour phoneConoti serverYour PC
Conversations (requests, AI answers)on screenciphertext●
Images you exchangeon screenciphertext●
Device private key · connection key● secure storage—● owner-only file
Account · sign-in session●●—
Notification token●●—
IP · time · message sizes and counts · app version · device number—visible—

One message, three places

One message, seen from three placesOn the phone and the PC it reads 'Run the tests and tell me the result'; on the Conoti server in the middle it is meaningless bytes. Your phone Run the tests, send results Readable What the Conoti server sees 9f 3a c1 7e 02 b8 d4 5fe1 66 0b 9a 4c f2 13 a75d 88 c0 2e 71 bb 09 e4 Meaningless bytes — only size and timing are visible Your PC Run the tests, send results Readable The keys that unlock it are created inside the phone and the PC and are never sent to the server. Without the keys, the server can neither read the content nor slip in a convincing fake message. One message, seen from three placesOn the phone and the PC it reads 'Run the tests and tell me the result'; on the Conoti server in the middle it is meaningless bytes. Your phone Run the tests, send results Readable What the Conoti server sees 9f 3a c1 7e 02 b8 d4 5fe1 66 0b 9a 4c f2 13 a75d 88 c0 2e 71 bb 09 e4 Meaningless bytes Size and time only Your PC Run the tests, send results Readable Keys are created on the phone and PC and never sent to the server. No keys: it can't read or forge messages.
The bytes shown are an illustration. Real ciphertext differs for every message.

Why it can't be intercepted in the middle

Strong encryption is useless if someone swaps the other side's key at the start (a man-in-the-middle attack). Conoti closes that gap at first connection with a camera and your own eyes.

  1. Your phone's camera scans the QR code on the PC screen directly. It holds the PC's public key and a secret that works once, for five minutes. None of it passes through the server, so the server cannot swap in a different PC key.
  2. The phone creates its own key on the phone and keeps it in the OS secure storage. The private key never leaves the phone.
  3. Both screens show the same 6-digit confirmation code. It is computed from the encryption handshake, so if the QR leaked and another device got in first, the numbers would differ.
  4. A person at the PC must approve before the link is made. Whether that device may send replies is decided separately here.
  5. Once approved, the PC creates a connection key just for that phone and hands it over inside the encrypted tunnel. From then on, conversations travel only as ciphertext, end to end.
A tunnel is closed the moment a single message fails to decrypt. A phone only knows the room number, so it cannot pretend to be the PC. Remove a device on the PC, and that phone's connection key stops working.

The cryptography

PartMethod
HandshakeNoise IKpsk2 — a Noise-family handshake pattern also used by the WireGuard VPN (with a different hash function)
Key agreementX25519 (a key pair made on each device + fresh ephemeral keys for every connection)
Encryption · tamper-proofingChaCha20-Poly1305 · SHA-256 hash
TransportWebSocket over TLS (WSS) — the ciphertext is wrapped once more in transit

The connection path today

Now · defaultRelayed through the Conoti server

The phone and the PC each open an outbound connection to the Conoti server. No incoming port needs to be opened on the PC, and the server only hands over ciphertext. If the other side is offline, it doesn't queue messages; it closes the connection. Phone linking itself is optional and must be turned on in the PC settings.

In preparation · offDirect connection (P2P)

A way for phone and PC to connect directly without the server (WebRTC) is being prepared. It is not in use, and public builds don't contain its code.

Registering a PC to your account to link devices without a QR code, Conoti sign-in from the PC app, and extra authentication such as passkeys are also in preparation and not in use today. Account linking verifies keys differently, so "Why it can't be intercepted" above describes today's QR connection.

Features that do pass through the server — stated plainly

🎙 Voice conversation (optional · off by default)

If you turn on voice conversation to instruct AI Tasks by speaking, your voice, its transcript, and the recent conversation, AI-answer summaries and session name needed to understand it pass through the Conoti server to a voice AI provider (Google or OpenAI). If you use voice to switch PCs or sessions, the PC name and a one-line preview of other sessions are also passed along. The Conoti server does not store this content and records only usage such as minutes and volume used. What is passed on is handled under each provider's own policy (for example, OpenAI does not train on it and keeps abuse-monitoring logs for up to 30 days). You are asked for separate consent the first time.

🌐 Connecting from a web browser

You can also link the Conoti web app to your PC. In that case the device key and the sign-in token are kept in that browser's storage (localStorage) without extra encryption. Conversations are not stored on the web either, but avoid linking from a browser on a shared computer. Keeping the key in non-extractable storage is in preparation.

📢 Notice rooms · cards posted to rooms · in-app AI chat

These deliver to many people and sync across devices, so they are stored on the server. The same goes for cards an external AI posts to a room through MCP. Retention and handling follow the Privacy Policy.

🤖 The AI running on your PC

AIs such as Claude Code and Codex talk to their own providers' servers as they normally do. Conoti does not sit on that path, and it does not protect that path for you either. The Conoti AI app itself makes no outside connection other than checking for new versions (which you can turn off) unless phone linking is on, and response summaries and history search are off by default — if you turn them on, selected excerpts go to that provider through your own Claude or Codex subscription.

FAQ

If the Conoti server were hacked, would my AI conversations leak?

AI Tasks conversations are not stored on the server, and what passes through is ciphertext that can't be read on its own. Because keys are exchanged directly when you link by QR code and you confirm a code on screen, it is hard for the server to swap keys in the middle. Account information and outside details such as connection times and sizes do live on the server, so that much could be affected.

I lost my phone.

Remove that device in Conoti AI on your PC. The phone's connection key becomes invalid and it can't reconnect.

Can my phone make the PC do anything at all?

The phone can only ask the PC for a fixed list of things (session list, viewing conversations, sending replies, …); there is no channel to read files or run commands directly. Replies are words fed into an AI session, so each device must be allowed on the PC to send them.

Do notifications show conversation content?

No. Notifications carry only fixed text set by the server (such as "New results have arrived"). The content is fetched from the PC when you open the app.

This page is based on Conoti AI's public security document (SECURITY.md), its internal connection spec, and the Conoti server and app code.