Privacy
Privacy and security
Porthole has no servers. Your sessions travel between your phone and your computer, and nowhere else.
A phone paired with Porthole can act as you on that computer: run commands, read and write files, answer and approve. That is the product, not a side effect. Pair only your own phone, and revoke it if you lose it.
Privacy policyThe security model
- No account
- Nothing to sign up for, no sign-in, no analytics. Nothing you do in the app reaches ShrimpScript, because there is nowhere for it to go.
- No relay
- The phone talks to your computer over your tailnet, a WireGuard connection between devices you own. Tailscale's servers relay it, still encrypted, only when a direct path cannot be made.
- Tailnet only
portholed listens on the computer's Tailscale addresses, never the local network, and identifies every caller through Tailscale's WhoIs.
- Paired at the desk
- A new phone needs a 6-digit code printed on the computer: single-use, five minutes, ten attempts.
portholed revoke cuts a phone off at once, whether or not it cooperates.
- Browsers refused
- Any connection that carries a browser's Origin header is refused, so a web page open on the paired phone cannot drive the daemon.
- Approvals are yours
- Nothing is approved automatically. A request the phone does not answer in time goes back to the prompt at the desk.
- One request to GitHub
- At most once a day the app asks
api.github.com for Porthole's latest release. It carries nothing about you beyond the IP address any web request carries. Settings > Updates turns it off.