Privacy, in detail

What pcp.gg can and can't see

pcp.gg does not run your PCP and does not hold its keys. It gives the PCP on your computer a public name, and passes connections for that name to it, still encrypted. Here is how, and where the promise ends.

How a connection travels

  1. Your PCP dials out. PCP opens one connection out to pcp.gg and keeps it open, so your router does not have to let anything in. It proves who it is with the connection key from your dashboard.
  2. PCP gets its own certificate. PCP asks Let's Encrypt for an HTTPS certificate for yourname.pcp.gg. The private key is made on your computer and never leaves it. pcp.gg only passes Let's Encrypt's check through to PCP.
  3. Your assistant connects to your name. The very first message of an HTTPS connection names the site it wants, in the clear. pcp.gg reads that name, and only that, then passes every byte down your PCP's connection unopened.
  4. The encryption ends at your computer. Your assistant and your PCP agree on keys that pcp.gg never has. From there on, pcp.gg is carrying a locked box.

The relay that does this holds no certificate and no private key for any owner's name, so it cannot answer as your PCP even if it wanted to. Plain HTTP on port 80 never reaches your PCP at all: pcp.gg answers it with a redirect to HTTPS, except for Let's Encrypt's check.

What we can see

  • Your account's email address and the name you picked.
  • Whether your PCP is connected and when it last was. The connection from your PCP comes from your home internet address, which our servers see while it is open.
  • For each connection to your name, while it passes through: the internet address it came from, when, and how many bytes. The relay does not write any of this down; it logs only that your PCP connected or disconnected.
  • The web server in front of pcp.gg, which it shares with other Kaperkunde services, keeps an ordinary log of the web requests it answers: visits to this site, your PCP's connection to pcp.gg, and plain-HTTP requests to your name. The encrypted connections to your name pass through it unopened and are not in that log.
  • Your name appears in public Certificate Transparency logs once PCP has a certificate for it, as every HTTPS site's name does.

The privacy notice lists everything pcp.gg keeps about you, and for how long.

What we can't see

  • What your assistant asks for, or what PCP answers.
  • Your mail, files, or anything else PCP reads for it.
  • Your passwords, API keys and sign-ins: they stay in PCP.
  • The tokens your assistants use to reach PCP, and the sign-in where you let an app such as claude.ai have one: it happens on your PCP, inside the encrypted connection.

Where the promise ends

We run the DNS for pcp.gg. In principle, whoever controls a domain's DNS can get a certificate for any name under it. If pcp.gg ever did that for your name, it could put itself in the middle. We don't, and the relay is built so that it has nowhere to put such a certificate. But you don't have to take our word for it: every publicly trusted certificate is published in Certificate Transparency logs, so one issued for your name that your PCP didn't ask for can be seen by anyone, including PCP.

Bring your own domain if that is not enough: point a name you own at pcp.gg, and pcp.gg cannot get a certificate for it at all. (Coming after the alpha.)

Your assistant still reads what you let it read. PCP keeps your keys away from the AI company, not the content you allow it to fetch.

Your computer has to be on. pcp.gg stores nothing of yours, so when your PCP is offline, there is nothing for your assistant to reach.

This is alpha software. The code that does the routing is small on purpose, and we will publish it for review.

The pcp.gg app in Claude and ChatGPT

Not available yet. We've built a pcp.gg app for the Claude and ChatGPT app directories, and it's waiting for Anthropic's and OpenAI's approval. It only works once they approve it. Until then, connect your assistant to your own address, as above.

The app has one address for everyone, https://pcp.gg/mcp, so it can be added in one click. That convenience changes what pcp.gg can see, so it is your choice, per assistant:

  • pcp.gg reads app requests to route them. A connection to pcp.gg ends at pcp.gg's own certificate, so to know whose PCP a request is for, pcp.gg decrypts it. It then sends it on to your PCP over a new encrypted connection that checks your PCP's own certificate. While a request passes, pcp.gg could read what the app asks and what PCP answers: the same things the AI company sees. It doesn't keep or log them.
  • Your passwords and keys still never leave PCP. PCP adds them to the calls it makes itself, so they never travel to the app, or through pcp.gg, either way.
  • You give the app a PCP token of its own, made in PCP with the levels you choose, so “ask me first” and blocked actions hold however the app reaches PCP. pcp.gg never stores it: it travels sealed inside the app's own sign-in, which only pcp.gg can open. Disconnect the app on your pcp.gg dashboard, or delete its token in PCP, and it is out.

Your own address stays the private way: there, pcp.gg can't read anything at all.

Don't want a middleman at all?

PCP works without pcp.gg. It has dynamic DNS and Let's Encrypt built in for a home server with two router ports forwarded, and it sits happily behind your own tunnel or proxy. See the self-hosting guide and PCP's source code.

Download PCP