Plakken! is a standalone Ubuntu Touch tool for copying and pasting text between a phone and a PC browser on the same reachable network.

No separate server is required. The phone serves the browser interface only while the Plakken! process is running.

First-run privacy choice
- Plakken! does not start its web server until first-run setup is completed.
- Memory-only paste storage is selected by default.
- In memory-only mode, paste contents are not written to device storage and disappear when the app process ends.
- Optional persistent mode stores paste contents as unencrypted UTF-8 JSON in the app's private storage and keeps them across restarts.
- The setup screen explains the advantages and disadvantages of both modes before the user continues.
- The storage mode can be changed later in Settings.

Local paste sharing
- The app shows the exact HTTP and/or HTTPS URL to open from a PC, including the phone's current IPv4 address and configured port.
- Example: http://192.168.1.42:8787/
- Example: https://192.168.1.42:8788/
- Create and use multiple paste threads.
- PC browser pastes and phone pastes share the same in-process data store.
- Copy, paste, and delete controls are available in both interfaces.

Embedded web server
- HTTP and HTTPS can be enabled or disabled independently.
- HTTP and HTTPS ports are independently configurable.
- Ports are restricted to non-privileged values from 1024 through 65535.
- Defaults are HTTP 8787 and HTTPS 8788.
- HTTPS uses a per-install self-signed certificate generated by the app.
- The TLS SHA-256 fingerprint is shown in Settings.
- The listener stops when the app process stops and may be unavailable while Ubuntu Touch suspends the app.

Optional browser authentication
- HTTP Basic Authentication can be enabled in first-run setup or Settings.
- Username and password are configurable in the app.
- Authentication is disabled by default.
- Authentication protects the browser page, static assets, and JSON API.
- HTTP is plaintext and does not protect Basic Authentication credentials from interception. HTTPS should be used when credentials or paste contents require transport encryption.

Browser security
- Strict same-origin Content Security Policy.
- Separate HTML, JavaScript, and CSS files with no inline script or style.
- Explicit UTF-8 handling for HTML, JSON, JavaScript, CSS, settings, optional persistent paste data, and backups.
- No CORS permission is granted to unrelated origins.

Backup and migration
- Backup and restore is available through Ubuntu Touch Content Hub.
- Backups include the selected storage mode, web-server settings, and current paste threads.
- Exporting a backup can intentionally persist paste contents even when memory-only mode is selected.
- Browser username and password are excluded by default.
- Including credentials/secrets is optional and off by default.
- The generated TLS private key and certificate are never exported.

Privacy
- no advertising
- no analytics
- no tracking
- no telemetry
- no external paste server
- memory-only storage by default

Ubuntu Touch integration
- Native Qt/QML application for Ubuntu Touch 24.04 on arm64.
- Package ID: plakken.barrydegraaff
- Display name: Plakken!
- Light and dark mode.
- Content Hub JSON backup/restore.
- AppArmor uses only networking, connectivity, content_exchange, and content_exchange_source.

Plakken! is released under MIT No Attribution, SPDX identifier MIT-0.

MIT No Attribution

Copyright 2026 Barry de Graaff

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Browser workflow:
- Paste field is focused when the web page opens or a thread is selected.
- Enter sends; Shift+Enter inserts a newline.
- Advertised URLs are limited to active LAN-style interfaces, avoiding cellular RMNET addresses.
