Using Noviscan from your phone
Who this is for: anyone who wants to check their alerts away from the computer that runs Noviscan. Assumes: Noviscan is running on a computer, at least one source feeds it, and you have an account on that instance. A viewer account is enough to look; naming a person requires an operator account. Applies from version: 0.1.3
⚠️ This page covers how to use the app, not how to install it. The app is not publicly distributed to date: only an internal test track exists. There is therefore no "download it here" step yet, and this page does not pretend to have one.
The phone does not replace the web interface, and it is not an accidental cut-down version of it: it carries what you do standing up — looking at an alert, putting a name to a face — and leaves to the web interface what you do sitting down: detection settings, sources, accounts, groups.
What the phone never does
Saying this first saves a long search:
- it stores none of your images durably, and sends them nowhere: they come from your instance and go back to it;
- it sends nothing to Secufor — no usage statistics, no crash reports;
- it creates no account: yours already exists on your instance, the phone pairs with it;
- it recognises no face itself: all the computing stays on your instance.
Pairing the phone with your instance
Pairing is the one moment when both devices must talk to each other for the first time. Do it at home, on your own Wi-Fi, before any use away from it.
- On the computer, in the web interface: Security → Pair a device. An administrator account is required. A QR code appears — it expires, and it works only once.
- On the phone, when the app opens: "Scan pairing QR code". Allow the camera if asked — that is all it is used for.
- The phone then asks you to confirm the address before sending anything: "Only pair if these addresses really are those of YOUR Noviscan instance." Read it. It is the only safeguard against a QR code that is not yours, and it is there on purpose.
- "Device paired" appears, and you land on the dashboard.
If the QR code will not scan, the pairing screen accepts manual entry: instance address, pairing secret, and — if the web interface shows them — the certificate fingerprint and the certificate authority. The web interface displays all four values just below the QR code.
Those last two values, in plain words. When Noviscan encrypts the traffic, it makes its own certificate: no public authority vouches for it, so it is up to your phone to learn to recognise it. The certificate fingerprint is its short summary — a string of hexadecimal characters — and the certificate authority is a block of text starting with
-----BEGIN CERTIFICATE-----. Neither is meant to be retyped: on the computer showing the QR code, use the copy button next to each value, then paste into the phone's field. Paste the whole block,BEGIN/ENDlines included.
⚠️ Always prefer the QR code to manual entry. Manual entry does accept the certificate authority, but it carries it only if you remember to paste it; the QR code carries it automatically. That omission — not an impossibility — is the most common cause of an "Instance unreachable" when everything else is correct.
If your instance announces itself on the network, it appears on its own under "Instances discovered on the network" and fills in the address for you.
When pairing fails, what the message means
| What you see | What to check |
|---|---|
| Instance unreachable — check the address and that the phone is on the same network | Is the phone on the same Wi-Fi? A "guest" network is a different network. |
| Unrecognized QR code (not a Noviscan pairing QR) | You scanned something else — the pairing QR code comes from Security → Pair a device, nowhere else. |
| Incomplete pairing QR code | The QR code was cut off on screen: display it in full again. |
| No instance address responded — same Wi-Fi network? | Same cause as the first row, observed across several addresses. |
| This instance cannot be paired remotely | The QR code did not carry what is needed to go through the relay — the Secufor service that puts the two in touch when the phone is not on your Wi-Fi, described under "Leaving the local network". Pair on site first. |
| Instance unreachable, and roaming is disabled on it | You are away from home, and roaming — the setting that lets this instance be reached through the relay — is not enabled. It is set on the instance, not on the phone: see "Leaving the local network" below. |
The four tabs
- Dashboard — the state of monitoring: start or stop it, run a one-off scan, see the detection chart. Tapping a slice of the chart opens that day's alerts.
- Alerts — what called you.
- Review — the faces Noviscan could not name. Nothing here alerted you: this screen is waiting for your opinion, it is not reporting an incident.
- Settings — the instance, appearance, language, lock, roaming.
Looking at an alert
The list filters by period — Today, 7d, All —, by free text search (name, source, file name) and by person. Pull the list down to refresh it.
In the detail of an alert, four gestures are worth knowing, because none of them is written on screen:
- pinch the image to zoom — ⚠️ on iPhone and iPad; this gesture relies on a zoom built into iOS, and nothing equivalent is provided for Android in this version;
- swipe left or right to move to the next or previous alert, in the order of the list as you filtered it;
- double-tap the image to play the video, when there is one;
- long-press the image to export or share it — the app then hands over to your phone's own sharing.
The "Zoom on face" button switches between the cropped face and the whole scene. It and video replay belong to the Premium plan; without it, the button says so instead of disappearing.
Putting a name to a face
From an alert as from the review queue, the same gestures:
- 🚩 Suspect — a reserved person name, never whitelistable;
- one of the suggested people, which Noviscan ranks by likeness;
- a free-text name, which creates the person if they do not exist yet;
- Undecided / Decide later — the face leaves the queue unassigned, and turns up in Review the undecided, reachable from the Review tab;
- Skip →, which simply sends the face to the back of the queue, deciding nothing.
⚠️ Naming a face has a lasting consequence: a named face is no longer purged automatically, unlike an anonymous one. Name what you want to keep.
Leaving the local network
By default, the phone reaches your instance only on the same network. To reach it from outside, turn on Settings → Roaming → "Access outside the local network". The link then goes through an encrypted relay that puts the two devices in touch: your images do not travel through it in the clear, and the relay cannot read them.
This section only appears if your instance supplied, at pairing time, what is needed to find it from outside. If it is missing, the pairing did not carry those elements — pair again by QR code, on site.
Below the setting, two lines say what is actually happening: Connection (Local network or Relay) and Real-time (connected or disconnected). They are not decoration: they answer "why is this slow?" without guesswork.
Protecting access on the phone
Settings → Security → "Biometric unlock" requires your face or fingerprint when the app opens and when it returns from the background. The phone asks you to authenticate before the setting turns on — so that a lock you cannot open never gets installed.
That unlock is your phone's own: Noviscan sees neither your face nor your fingerprint, and keeps nothing of either.
Logging out and unpairing are not the same thing
- Log out closes your session on all your devices. The phone stays paired: you sign back in with your password.
- Unpair this device forgets the instance on this phone — address, secret, certificate — and first tells the instance to revoke this device's token, which frees its quota slot — your licence bounds how many phones may be paired at the same time, and a device forgotten without revocation goes on occupying one — without an administrator. ⚠️ That revocation is an attempt bounded to a few seconds: if the instance is unreachable, the local removal happens anyway and the revocation does not. That case, and only that one, requires revoking from the web interface, Security → Devices. When in doubt — lost phone, unpaired while offline — check there that the device is gone from the list.
Unpairing stays possible even when the instance is unreachable, from the "Instance unreachable" screen: a lost device must not remain attached to an instance you can no longer reach.
What stays on the phone, and what does not
In the phone's secure store (Keystore/Keychain), erased on unpairing: the instance address, the pairing secret, the certificate fingerprint, the certificate authority and the instance name.
In the phone's cache: the images and videos you have viewed are written there so they are not downloaded again. ⚠️ They are not encrypted by the app at that point, and no retention period erases them: their removal is left to your phone's own cache management. An image deleted on the instance may therefore remain for a while on the phone. A phone used to look at alerts should be treated as a device that holds copies of them.
What this page does not cover
Installing the app, detection settings, adding a source, managing accounts and person groups: they live in the web interface, and in the other pages of this documentation.
Applies to Noviscan 0.1.3. This page was written by reading the app, not by using it: none of its walkthroughs has yet been retraced by a reader on a real phone.