How PalmDesk is secured
Software that can see your screen and move your pointer has to earn trust. Here is exactly what protects a PalmDesk session, and what our servers can and cannot see.
Updated September 24, 2026 · Applies to PalmDesk 1.0
Quick answer
PalmDesk sessions are end-to-end encrypted between your iPhone or iPad and your Mac. Devices pair once with a one-time code and a fingerprint check, keep their private keys in the Keychain, and exchange connection details in sealed, signed envelopes that the signalling server can’t read. Video, pointer and keyboard travel in WebRTC’s DTLS-SRTP encryption, even through a relay.
Technical summary
| Layer | Protection |
|---|---|
| Device identity | Ed25519 signing key and X25519 key-agreement key per device, stored in the Keychain as this-device-only (not synced to iCloud) |
| Pairing | One-time QR or 9-digit code, valid for 2 minutes and approved once; fingerprint confirmed on both screens |
| Signalling | HPKE (X25519, SHA-256, ChaCha20-Poly1305) sealed envelopes, signed with Ed25519, over HTTPS/WSS |
| Nearby signalling | TLS 1.2 with a pre-shared key and AES-GCM on the local network |
| Media and control | WebRTC DTLS-SRTP for video and every data channel |
| Relay | TURN with short-lived credentials issued per session; carries encrypted packets only |
| Revocation | Removing a device on the Mac deletes its trust record; later messages from it are rejected |
What our servers can see
- Random device identifiers and public keys, to route a request to the right Mac.
- Whether a paired Mac is online.
- Pairing invitations, for up to three minutes, then deleted.
- Standard connection metadata such as IP address and time, kept briefly for operations and abuse prevention.
What they can’t see
- Your screen, your keystrokes, your clicks or anything you type.
- The contents of connection envelopes; they’re sealed to your devices’ keys.
- Your name, email or phone number; PalmDesk has no accounts.
- Usage analytics; the apps and this website have no trackers.
Controls on the Mac
Privacy Zones
Chosen apps are removed from screen capture and the window list. If one comes to the front while you watch the active window, the image freezes.
Hide sensitive screens
An optional setting that pauses Live Display while a password field or a macOS authorization dialog is visible.
Pause and remove
Pause PalmDesk from the menu bar at any time, turn internet connections off, or remove a paired device for good.
Where it runs
Signalling and the relay run on Cloudflare’s network. Neither stores screen content, and neither holds the keys needed to decrypt a session. Details are in the Privacy Policy.
Found a security issue? Please write to support@palmdesk.app with “Security” in the subject. We read every report.
Questions
Can someone on my Wi‑Fi control my Mac?
No. Only devices that completed pairing and hold a trusted key can connect, and local signalling is encrypted with a key derived from the two paired devices’ keys.
Can PalmDesk see my screen?
No. Video goes from your Mac to your own device inside an encrypted session. Even when traffic passes through the relay, it stays encrypted end to end.
What happens if I lose my iPhone?
Remove it from the Devices list in PalmDesk for Mac. Its trust record is deleted and it can’t connect again without a new pairing on the Mac.