Kyalulu/docs
GitHub JA
Browse guides⌄

Connect your phone

Remote connections and pairing

Understand the encrypted relay development candidate, its pairing flow, and operational limits.

At a glance

  • Remote is a development candidate connecting a PC Host and PWA through a Relay with Noise encryption.
  • No Internet-facing PC port forwarding is needed. Enroll via QR, then approve the six-digit code on the PC.
  • It adds no cloud inference or automatic fallback. Device, endurance and external review requirements remain.
On this page
  1. At a glance
  2. What the relay carries
  3. Prepare before pairing
  4. Scan the QR and approve on the PC
  5. Recovery and trust limits

What the relay carries#

The PC Host and Android PWA each open outbound WSS connections to Relay and encrypt conversation traffic with Noise. This does not require opening an inbound Internet port on the PC. Relay retains routing metadata and token hashes, never Noise keys, conversation text, or an offline delivery queue.

Characters, SQLite history, memories, and Runtime stay on the PC; LE runs separately. Remote adds no cloud inference, automatic fallback while the PC is down, P2P, or push notifications. Conversations are unavailable while the PC sleeps. For direct HTTPS, use the mobile guide.

Prepare before pairing#

An operator must provide Relay and the PWA and align separate APP/RELAY DNS names, TLS, and the exact Relay Origin in the PWA build. Obtaining the source does not deploy services or purchase hosting. The documented JPY 3,000 monthly figure is a target budget, not a verified quote.

  1. Obtain a one-use Host invitation from the Relay operator.
  2. Enter it interactively with remote_host.py register on the PC and choose durable vault and data directories. Do not put the invitation in command arguments or logs.
  3. Start the Host with remote_host.py serve and run LE independently. Management HTTP is limited to 127.0.0.1:8766.
  4. To adopt existing data, stop every old Runtime/Desktop using it, verify the actual directory, and register with --adopt-existing-data. Back up the DB and image assets together.

Windows protects the vault with the current user's DPAPI; POSIX uses 0600 permissions. Neither protects against malicious code running as that user. Losing the vault requires Host and device re-enrollment.

Scan the QR and approve on the PC#

  1. Open the PC settings for taking this PC's conversations with you and choose phone registration.
  2. Scan the QR on Android, enter a device name in the PWA, and choose registration with this PC.
  3. Enter the phone's six-digit code in the PC approval screen.
  4. After approval, open conversations and optionally install the PWA.

The QR expires within five minutes and permits one enrollment. It contains a Host public-key pin and an enrollment secret; never publish the image. Redeeming a Relay ticket alone cannot access Runtime. Noise identity, secret validation, and PC approval are required.

Each owner can have two Hosts and five approved phones. A registration belongs to one Host; another Host needs its own QR enrollment and does not synchronize history. Revoke a lost phone on the PC. Deleting a phone's local key is different from revoking its server-side registration.

Recovery and trust limits#

Remote uses standard Noise_XX_25519_ChaChaPoly_SHA256 and pins registered keys. A changed key requires re-enrollment. Disconnecting does not cancel an accepted generation. Reconnection repeats Noise and reconciles request IDs and sequences; results outside the short buffer use durable status/history, never automatic resubmission. Inspect ambiguous imports or edits before repeating them.

E2EE does not hide IPs, timing, or transfer sizes. A compromised PWA distributor or endpoint can still capture plaintext. Device drafts are not an encrypted vault; uploads are limited to 16 MiB for the whole multipart body. Production TLS operations, physical Android testing, real Gemma acceptance, 24-hour endurance, and external security review remain release checks. A short loopback test does not establish Internet quality or long-term reliability. Developers can continue to the development guide.

Sources for this article

Edited from public GitHub materials. Links are pinned to the reviewed commit.

Search the docs

↑ ↓ select · Enter open · Esc close