Your AI Tasks conversations stay on your PC,
and the Conoti server cannot read them
AI Tasks in Conoti lets you follow and reply to the AI running on your PC (Claude Code, Codex) from your phone. The Conoti AI app (formerly AI Inbox) on the PC and the Conoti app on the phone set up encryption directly with each other; the Conoti server in between only handles sign-in, passing along ciphertext, and content-free notifications.
Conversation history is stored in Conoti AI's database (SQLite) on your PC. The phone app asks the PC each time and only shows it on screen; it writes no copy of the conversations to disk.
Everything between phone and PC is locked with end-to-end encryption (the Noise protocol, IKpsk2). Keys are created inside each device and are never sent to the server.
The server pairs the two connections and passes the ciphertext through as-is. Pairing state lives only in memory, and passing content is neither decrypted nor logged.
What the server can and cannot see
Saying "the server knows nothing" would be an overstatement. Some information is needed to connect you and send notifications. Here is the boundary, exactly.
👁 What the server can see
- Account — your social sign-in account and sign-in sessions (sign-in tokens kept as hashes, not originals)
- Devices for notifications — notification tokens and language settings
- The outside of a connection — IP address, connection time, message sizes and counts, app version, and a device number that tells it the same phone reconnected
- That a notification was sent — when, what kind (new result, schedule, …), and to which account. With notifications on, also which PC (IP) sends alerts to which account
🔒 What the server cannot see
- What you asked the AI and the replies you send from your phone
- The AI's answers and summaries
- Session names and project folder paths
- Images you exchange
- Encryption keys — device private keys and connection keys
Where each piece of data lives
| Data | Your phone | Conoti server | Your PC |
|---|---|---|---|
| Conversations (requests, AI answers) | on screen | ciphertext | ● |
| Images you exchange | on screen | ciphertext | ● |
| Device private key · connection key | ● secure storage | — | ● owner-only file |
| Account · sign-in session | ● | ● | — |
| Notification token | ● | ● | — |
| IP · time · message sizes and counts · app version · device number | — | visible | — |
One message, three places
Why it can't be intercepted in the middle
Strong encryption is useless if someone swaps the other side's key at the start (a man-in-the-middle attack). Conoti closes that gap at first connection with a camera and your own eyes.
- Your phone's camera scans the QR code on the PC screen directly. It holds the PC's public key and a secret that works once, for five minutes. None of it passes through the server, so the server cannot swap in a different PC key.
- The phone creates its own key on the phone and keeps it in the OS secure storage. The private key never leaves the phone.
- Both screens show the same 6-digit confirmation code. It is computed from the encryption handshake, so if the QR leaked and another device got in first, the numbers would differ.
- A person at the PC must approve before the link is made. Whether that device may send replies is decided separately here.
- Once approved, the PC creates a connection key just for that phone and hands it over inside the encrypted tunnel. From then on, conversations travel only as ciphertext, end to end.
The cryptography
| Part | Method |
|---|---|
| Handshake | Noise IKpsk2 — a Noise-family handshake pattern also used by the WireGuard VPN (with a different hash function) |
| Key agreement | X25519 (a key pair made on each device + fresh ephemeral keys for every connection) |
| Encryption · tamper-proofing | ChaCha20-Poly1305 · SHA-256 hash |
| Transport | WebSocket over TLS (WSS) — the ciphertext is wrapped once more in transit |
The connection path today
The phone and the PC each open an outbound connection to the Conoti server. No incoming port needs to be opened on the PC, and the server only hands over ciphertext. If the other side is offline, it doesn't queue messages; it closes the connection. Phone linking itself is optional and must be turned on in the PC settings.
A way for phone and PC to connect directly without the server (WebRTC) is being prepared. It is not in use, and public builds don't contain its code.
Registering a PC to your account to link devices without a QR code, Conoti sign-in from the PC app, and extra authentication such as passkeys are also in preparation and not in use today. Account linking verifies keys differently, so "Why it can't be intercepted" above describes today's QR connection.
Features that do pass through the server — stated plainly
🎙 Voice conversation (optional · off by default)
If you turn on voice conversation to instruct AI Tasks by speaking, your voice, its transcript, and the recent conversation, AI-answer summaries and session name needed to understand it pass through the Conoti server to a voice AI provider (Google or OpenAI). If you use voice to switch PCs or sessions, the PC name and a one-line preview of other sessions are also passed along. The Conoti server does not store this content and records only usage such as minutes and volume used. What is passed on is handled under each provider's own policy (for example, OpenAI does not train on it and keeps abuse-monitoring logs for up to 30 days). You are asked for separate consent the first time.
🌐 Connecting from a web browser
You can also link the Conoti web app to your PC. In that case the device key and the sign-in token are kept in that browser's storage (localStorage) without extra encryption. Conversations are not stored on the web either, but avoid linking from a browser on a shared computer. Keeping the key in non-extractable storage is in preparation.
📢 Notice rooms · cards posted to rooms · in-app AI chat
These deliver to many people and sync across devices, so they are stored on the server. The same goes for cards an external AI posts to a room through MCP. Retention and handling follow the Privacy Policy.
🤖 The AI running on your PC
AIs such as Claude Code and Codex talk to their own providers' servers as they normally do. Conoti does not sit on that path, and it does not protect that path for you either. The Conoti AI app itself makes no outside connection other than checking for new versions (which you can turn off) unless phone linking is on, and response summaries and history search are off by default — if you turn them on, selected excerpts go to that provider through your own Claude or Codex subscription.
FAQ
If the Conoti server were hacked, would my AI conversations leak?
AI Tasks conversations are not stored on the server, and what passes through is ciphertext that can't be read on its own. Because keys are exchanged directly when you link by QR code and you confirm a code on screen, it is hard for the server to swap keys in the middle. Account information and outside details such as connection times and sizes do live on the server, so that much could be affected.
I lost my phone.
Remove that device in Conoti AI on your PC. The phone's connection key becomes invalid and it can't reconnect.
Can my phone make the PC do anything at all?
The phone can only ask the PC for a fixed list of things (session list, viewing conversations, sending replies, …); there is no channel to read files or run commands directly. Replies are words fed into an AI session, so each device must be allowed on the PC to send them.
Do notifications show conversation content?
No. Notifications carry only fixed text set by the server (such as "New results have arrived"). The content is fetched from the PC when you open the app.
This page is based on Conoti AI's public security document (SECURITY.md), its internal connection spec, and the Conoti server and app code.