Your devices,
as one fleet.
One device is the Commander and issues orders. The others are Nodes — they report status and carry those orders out. Built for a household, or one person’s own devices.
Commander
The device you are holding. It sees the status of every node in the fleet and issues orders to them. Orders are signed here, on the device, before they go anywhere.
Node
Every other device in your fleet. A node reports its own status — battery, storage, thermal state and so on — and carries out the orders it receives, after verifying the signature.
What it does
A short list, described as it actually works.
Fleet status at a glance
Battery level and charging state, Low Power Mode, thermal state, free and total storage, output volume, uptime, and whether a lockdown is active — for every device in the fleet.
Locate, on request
A commander can send a Locate order to get an approximate position, if that device granted location permission. Nothing is tracked continuously and no location history is kept — only the most recent fix.
Clipboard push and pull
Send text to a node, or pull a node’s clipboard back to the commander. Pulled text is stored in the receipt record — see the Privacy Policy before using it.
Speak and Alert
Make a node speak a message or raise an alert — useful for finding a device in the house. The message text is stored as the command payload.
Lockdown
Shield apps on a node using Apple’s Screen Time framework. It sets and clears restrictions only — it never reads usage data. It can be undone from Settings, so it is not a security product.
Direct on local network
When devices share a local network they talk directly over MultipeerConnectivity. That traffic is encrypted and never reaches our servers.
How it is built
Cloudflare Worker and D1 database, currently served from an EU region, plus Apple Push Notification service. That is the whole backend.
🔑 No accounts, no identity
There is no email, name, password or payment identity anywhere. Devices identify themselves with an Ed25519 keypair generated on the device and a random UUID. The private key never leaves the Keychain — the server only sees the public key.
✍️ The server cannot forge an order
Orders are signed on the sending device and verified on the receiving device. Our server relays them, but it holds no private key, so it cannot fabricate one.
🚫 No trackers, no brokers
No third-party analytics, advertising or tracking SDKs. Nothing is sold or shared. The only third parties are Cloudflare for hosting and the database, and Apple for push notifications.
🗑️ Retention, stated plainly
Queued commands expire after 24 hours. There is currently no automatic purge of historical command and receipt rows — they persist until you remove the device from the fleet, which deletes its records.
⚠ Two things worth knowing before you use it
Clipboard content can be stored. A Pull Clipboard order returns a node’s clipboard text to the commander, and that text is written to the receipt record in the database. Speak and Alert message text is stored as the command payload too. If a clipboard might hold a password or a private message, do not pull it.
Lockdown is not tamper-proof. It restricts apps using Apple’s Screen Time framework and can be undone by anyone with access to the device via Settings. It is not a security or anti-theft product, and we will not describe it as one.
For your own devices
CommandCenter is meant for a household or one person’s own devices. Using it to monitor or restrict someone else’s device without their knowledge and consent is prohibited under our Terms of Service.
No public release yet
CommandCenter is still being built and is not available to download. We do not have a release date to announce. If you want to hear when it ships, or you have a question about how it works, email us.
support@plenum.gr →
Bundle identifier gr.plenum.commandcenter • requires iOS 27 or later • iOS Only