Skip to content

Privacy and Security

kenji edited this page Sep 7, 2026 · 1 revision

Privacy and Security

NetWatch separates the Windows interface from the services that contact metadata, indexer, subtitle, and torrent networks. Those backend services share a Docker/WSL network namespace behind the managed WireGuard tunnel.

Network protection

  • The inner WireGuard tunnel is the required Internet route for backend services.
  • Startup checks verify routing, DNS, the kill switch, and egress.
  • Windows-facing backend ports are published on loopback.
  • A Windows host VPN is optional and does not replace the managed tunnel.

The exact guarantees, failure behavior, and limits are maintained in the network threat model.

Android remote access

  • Remote access is off until the user enables it.
  • The gateway binds to one selected private IPv4 interface.
  • Pairing is short-lived and single-use.
  • Android pins the PC identity and does not fall back to cleartext.
  • Each phone has a revocable credential.
  • The Android app does not accept arbitrary gateway, media, magnet, or file URLs.
  • Camera frames are processed on the device for QR scanning.

The full design is in the remote security model. The wire format and endpoint contract are in Remote Protocol v1.

Local data

Windows credentials and managed runtime state are stored in the selected WSL distribution. Android protects its pairing profile with Android Keystore and disables application backup and device transfer. External subtitle files are temporary.

Keep Watching can be disabled. Disabling it removes its local cache and stops further history updates.

Limits

NetWatch does not promise anonymity and cannot protect against a compromised PC, phone, administrator, VPN provider, dependency, or third-party service. Users remain responsible for their providers, indexers, content, and local laws.

Read the project disclaimer before use.

Report a vulnerability

Follow the private reporting instructions in the Windows security policy or Android security policy. Do not open a public issue containing credentials, private keys, or an unpatched exploit.

Clone this wiki locally