Skip to content

Phase 17: on-device intelligence, private in both builds - #32

Merged
AndyScherzinger merged 7 commits into
mainfrom
feature/phase-17-intelligence
Oct 6, 2026
Merged

AndyScherzinger merged 7 commits into
mainfrom
feature/phase-17-intelligence

Conversation

@AndyScherzinger

Copy link
Copy Markdown
Contributor

Summary

Phase 17, intelligence: on-device features, each off until the reader turns it on, none acting without a tap, and each build telling the reader exactly who, if anyone, learns of them.

F-Droid (generic) Google Play (gplay)
Alt-text drafts Open software: EfficientNet-Lite0 on LiteRT, Android's face detector The same
Rewrite, summaries Not offered (they need Gemini Nano) Gemini Nano through ML Kit's Prompt API, in Android's AICore
Translate thread Yes Yes
Reports to Google None: no Google library apart from the open-source LiteRT runtime None from the app: ML Kit's start-up provider and its transport backend are removed from the manifest, so its reports are deleted unsent; AICore is Android's
  • :core:intelligence: availability, EntityShield, the alt-text assembly, the prompts and the open picture reader; the language model and each build's privacy paragraph are optional Hilt bindings. Words written in pictures are read in neither build: no open text recognition is on the build's repositories, and ML Kit's would add some 39 MB of native code.
  • Settings, Intelligence: one switch per feature, all off; nothing asks the device about its model before a switch that needs it is on.
  • Alt-text drafts: "Draft a description" in the media editor, people only counted; the draft ends with " (AI generated)", kept through edits, counted in the 1,500 characters and stored on the server with it. "Draft descriptions" drafts every undescribed picture in turn; unchecked drafts are said before posting, also after a draft is kept and reopened.
  • Rewrite: proofread, shorten to the characters left, rephrase, tone shifts; mentions, hashtags and links masked and compared after, so a rewrite that loses or adds one is turned down. A sheet shows draft and proposal word by word, also read out in words, with Replace, Copy and Cancel.
  • Summaries: "Summarise this thread" in a new thread menu, in a sheet, never kept; posts behind a content warning read as their warning, filtered posts left out, a long thread's coverage said.
  • Translate thread: one tap translates every foreign post and the replies that arrive while the thread is open, until Show originals.
  • Documentation: docs/10-intelligence.md has a telemetry table part by part (what each could report, from which process, with which identifier, what the app does, how it was checked); docs/12-store.md answers Data safety for both builds.

Test plan

  • :core:intelligence: the shield over a corpus (handles local and remote with Unicode domains, tags in any script and with ·, upper-case links, fragments), dropped, doubled, invented and added entities, token brackets in a draft, the alt-text assembly, the classifier's label selection, the summary cap.
  • Composer: batch drafting and unchecked drafts, the editor's draft-edit-done flow keeping the mark, rewrites replaced only on Replace and turned down when over the limit, the word diff.
  • Thread: the summary's input (order, handles, warnings, filtered posts), translate thread across new replies and state restoration, Show originals.
  • Screenshots: the Intelligence settings and privacy page, the rewrite sheet, the summary sheet.
  • Builds: generic's runtime classpath has no ML Kit, Play services, Firebase or data transport, and its merged manifest no Google component; gplay's merged manifest has no MlKitInitProvider and no CctBackendFactory; the transport uploader deletes events without a backend (transport-runtime 3.1.9 bytecode).
  • Gates: detekt ktlintCheck lint alohaArchitectureCheck, alohaUnitTests, alohaScreenshotTests, both flavours assembled. Universal release APKs: 32.6 MB (F-Droid) and 33.0 MB (Play), up from 7.1 MB, almost all LiteRT's native code for four ABIs (~19 MB) and the model (5.2 MB); about 9.5 MB on an arm64 phone. Per-ABI APKs and an App Bundle would bring the download down to that and are a follow-up. Not run on a device: the emulator has no AICore, so Gemini Nano is tested through fakes, and LiteRT inference runs only on a device.

Checklist

  • One concern; split if it approaches a thousand changed lines
  • Tests for every non-trivial branch; fixtures from the dev instance where the server is involved
  • detekt ktlintCheck lint alohaArchitectureCheck green, no baseline grown
  • Screenshots re-recorded only where the UI change is intended
  • Accessibility: labels, 48 dp targets, headings and paneTitle on new screens, 200 % font preview
  • Strings in strings.xml with translator comments
  • No new exported component, permission or dependency without a line here explaining it
  • docs/ updated where behaviour changed
  • AI tools were used for this contribution (commits carry Assisted-by:)

New dependencies:

  • Both builds: com.google.ai.edge.litert:litert 1.4.2 (Apache-2.0, TensorFlow Lite's open-source successor; no reporting code; native libraries 16 KB-aligned) and the bundled EfficientNet-Lite0 model (Apache-2.0, 5.4 MB, SHA-256 in ACKNOWLEDGEMENTS.md).
  • Play build only (gplayImplementation): com.google.mlkit:genai-prompt 1.0.0-beta4. No permission; ML Kit's services in the merged manifest are not exported; its start-up provider and transport backend are removed.
  • One new ignored key, 912D2C0ECCDA55C0 (a Google signer, expired 2020, absent from keys.openpgp.org); its artifacts are pinned by checksum.

@AndyScherzinger AndyScherzinger added this to the 1.0.0 milestone Oct 5, 2026
@github-actions github-actions Bot added the AI assisted Commits carry an Assisted-by trailer label Oct 5, 2026
@AndyScherzinger
AndyScherzinger force-pushed the feature/phase-17-intelligence branch 3 times, most recently from 1e12b72 to facc6f6 Compare October 6, 2026 06:54
A new core module holds what the on-device features share: whether the
language model can be used, the shield that keeps mentions, hashtags and
links out of a rewrite's reach and rejects one that loses or adds any,
alt text put together from what a picture shows with people only
counted, and the prompts.

Every build reads pictures with open software that reports to no one: an
EfficientNet-Lite0 image classifier on LiteRT, bundled with its labels,
and Android's own face detector for the count. The Play build adds
Gemini Nano through ML Kit's Prompt API as an optional binding. ML Kit
no longer starts with the app, and the Play manifest removes the
transport backend its reports would go through, so the uploader deletes
them unsent. The generic build carries no Google library apart from the
open-source LiteRT runtime, drafts alt text, and has no rewriting or
summaries.

Settings gain an Intelligence section with one switch per feature, all
off. Nothing asks the device about its language model until a switch
that needs it is on. Each build words its own paragraph of the privacy
statement: what reads what, and who, if anyone, learns of it.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
With Draft alt text on, a picture without a description offers a draft:
from the sparkle on its card, which drafts it in place, and in the media
editor. The device names what it recognises and counts people, nothing
more about them. In the editor the draft lands as text to edit, under
"Generated, please check". A draft left as drafted ends with
" (AI generated)", counted toward the 1,500 characters and sent to the
server with it; the writer's first edit drops the mark, as the words are
theirs then and the AI Act asks for no label on reviewed text.

The warning about media without descriptions can draft them all, one
picture after the other, with a way to stop. Drafts nobody has looked at
in the editor are said before posting, with the first one a tap away.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
With Rewrite on and Gemini Nano on the device, the composer's toolbar
offers to proofread, shorten to the characters left, rephrase, or make
the draft friendlier, more formal or more concise. Mentions, hashtags and
links are masked before the model sees the text; a rewrite that loses,
doubles or makes one up is turned down, as is one that does not fit. The
result shows in a sheet beside the draft, word by word what changed in
each, said to be generated: Replace, Copy or Cancel. Nothing is put in
place unasked.

With Summarise on, a thread's new menu summarises it in a sheet from its
posts in order with their authors; a post behind a content warning is
read as its warning alone. The summary is never kept and never shown in
the thread. Until a feature is on, the model is not asked anything.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
The thread's menu offers Translate thread when a post in it is written in
a language the reader does not read. One tap translates each of them as
a single post's Translate does, by the server where it can and on the
device where it cannot, and the replies that arrive while the thread is
open as well. A post the reader turns back with Show original stays so;
Show originals turns them all back and ends it. Nothing is translated
without the tap, and the choice ends with the thread.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
Intelligence describes alt-text drafts, rewriting, summaries and thread
translation from the code: which build has which, by what software,
when they are offered, and how a result is marked. A telemetry table
goes part by part: what each could report, from which process, with
which identifier, what the app does about it, and how that was
checked. Architecture names the new core module and what only the Play
build holds. The store page answers for both builds, with ML Kit's
reports cut off in the Play build. Status lists Phase 17 in progress.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
Phase 17 grows the release APKs to 32,674,294 bytes (generic, +357.2 %)
and 33,098,790 bytes (gplay, +363.2 %): LiteRT's native libraries for four
ABIs, about 19 MB, and the EfficientNet-Lite0 model, 5.2 MB, which both
builds draft alt text with; the Play build adds ML Kit's Prompt API. A
phone needs one ABI, about 9.5 MB of it; per-ABI APKs and an App Bundle
would bring the download down to that.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
A refused attachment squeezed the server's reason into the title line
beside its retry and remove buttons, where a phone held upright cut it
to a few letters. The card now titles itself "Couldn't upload" and gives
the whole reason on lines of its own under the picture, with the retry
below it.

A refusal was logged only as an attempt that failed, at info level and
without the reason. It is now a warning with the server's reason, the
file's size and type, which is what tells a server's upload limit from
anything else.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
@AndyScherzinger
AndyScherzinger force-pushed the feature/phase-17-intelligence branch from facc6f6 to be4cfc0 Compare October 6, 2026 07:07
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

📱 QA build

Download aloha-qa-pr32.apk
QR code Open the QR code for this download
Commit be4cfc0
Version 0.1.0 (1)
Available until 5 days after this build

The QA build installs alongside any other Aloha build, so you can keep using your existing install while testing, and it updates an earlier QA build in place.

Downloading the file requires a GitHub account, so open this link on the device you want to test on, or transfer the APK to it.

@AndyScherzinger
AndyScherzinger merged commit 3f614f6 into main Oct 6, 2026
7 checks passed
@AndyScherzinger
AndyScherzinger deleted the feature/phase-17-intelligence branch October 6, 2026 07:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI assisted Commits carry an Assisted-by trailer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant