Repository navigation
Phase 17: on-device intelligence, private in both builds - #32
Merged
Merged
Conversation
AndyScherzinger
force-pushed
the
feature/phase-17-intelligence
branch
3 times, most recently
from
October 6, 2026 06:54
1e12b72 to
facc6f6
Compare
A new core module holds what the on-device features share: whether the language model can be used, the shield that keeps mentions, hashtags and links out of a rewrite's reach and rejects one that loses or adds any, alt text put together from what a picture shows with people only counted, and the prompts. Every build reads pictures with open software that reports to no one: an EfficientNet-Lite0 image classifier on LiteRT, bundled with its labels, and Android's own face detector for the count. The Play build adds Gemini Nano through ML Kit's Prompt API as an optional binding. ML Kit no longer starts with the app, and the Play manifest removes the transport backend its reports would go through, so the uploader deletes them unsent. The generic build carries no Google library apart from the open-source LiteRT runtime, drafts alt text, and has no rewriting or summaries. Settings gain an Intelligence section with one switch per feature, all off. Nothing asks the device about its language model until a switch that needs it is on. Each build words its own paragraph of the privacy statement: what reads what, and who, if anyone, learns of it. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
With Draft alt text on, a picture without a description offers a draft: from the sparkle on its card, which drafts it in place, and in the media editor. The device names what it recognises and counts people, nothing more about them. In the editor the draft lands as text to edit, under "Generated, please check". A draft left as drafted ends with " (AI generated)", counted toward the 1,500 characters and sent to the server with it; the writer's first edit drops the mark, as the words are theirs then and the AI Act asks for no label on reviewed text. The warning about media without descriptions can draft them all, one picture after the other, with a way to stop. Drafts nobody has looked at in the editor are said before posting, with the first one a tap away. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
With Rewrite on and Gemini Nano on the device, the composer's toolbar offers to proofread, shorten to the characters left, rephrase, or make the draft friendlier, more formal or more concise. Mentions, hashtags and links are masked before the model sees the text; a rewrite that loses, doubles or makes one up is turned down, as is one that does not fit. The result shows in a sheet beside the draft, word by word what changed in each, said to be generated: Replace, Copy or Cancel. Nothing is put in place unasked. With Summarise on, a thread's new menu summarises it in a sheet from its posts in order with their authors; a post behind a content warning is read as its warning alone. The summary is never kept and never shown in the thread. Until a feature is on, the model is not asked anything. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
The thread's menu offers Translate thread when a post in it is written in a language the reader does not read. One tap translates each of them as a single post's Translate does, by the server where it can and on the device where it cannot, and the replies that arrive while the thread is open as well. A post the reader turns back with Show original stays so; Show originals turns them all back and ends it. Nothing is translated without the tap, and the choice ends with the thread. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
Intelligence describes alt-text drafts, rewriting, summaries and thread translation from the code: which build has which, by what software, when they are offered, and how a result is marked. A telemetry table goes part by part: what each could report, from which process, with which identifier, what the app does about it, and how that was checked. Architecture names the new core module and what only the Play build holds. The store page answers for both builds, with ML Kit's reports cut off in the Play build. Status lists Phase 17 in progress. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
Phase 17 grows the release APKs to 32,674,294 bytes (generic, +357.2 %) and 33,098,790 bytes (gplay, +363.2 %): LiteRT's native libraries for four ABIs, about 19 MB, and the EfficientNet-Lite0 model, 5.2 MB, which both builds draft alt text with; the Play build adds ML Kit's Prompt API. A phone needs one ABI, about 9.5 MB of it; per-ABI APKs and an App Bundle would bring the download down to that. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
A refused attachment squeezed the server's reason into the title line beside its retry and remove buttons, where a phone held upright cut it to a few letters. The card now titles itself "Couldn't upload" and gives the whole reason on lines of its own under the picture, with the retry below it. A refusal was logged only as an attempt that failed, at info level and without the reason. It is now a warning with the server's reason, the file's size and type, which is what tells a server's upload limit from anything else. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Andy Scherzinger <info@andy-scherzinger.de>
AndyScherzinger
force-pushed
the
feature/phase-17-intelligence
branch
from
October 6, 2026 07:07
facc6f6 to
be4cfc0
Compare
📱 QA build
The QA build installs alongside any other Aloha build, so you can keep using your existing install while testing, and it updates an earlier QA build in place. Downloading the file requires a GitHub account, so open this link on the device you want to test on, or transfer the APK to it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Phase 17, intelligence: on-device features, each off until the reader turns it on, none acting without a tap, and each build telling the reader exactly who, if anyone, learns of them.
generic)gplay):core:intelligence: availability,EntityShield, the alt-text assembly, the prompts and the open picture reader; the language model and each build's privacy paragraph are optional Hilt bindings. Words written in pictures are read in neither build: no open text recognition is on the build's repositories, and ML Kit's would add some 39 MB of native code.docs/10-intelligence.mdhas a telemetry table part by part (what each could report, from which process, with which identifier, what the app does, how it was checked);docs/12-store.mdanswers Data safety for both builds.Test plan
:core:intelligence: the shield over a corpus (handles local and remote with Unicode domains, tags in any script and with·, upper-case links, fragments), dropped, doubled, invented and added entities, token brackets in a draft, the alt-text assembly, the classifier's label selection, the summary cap.generic's runtime classpath has no ML Kit, Play services, Firebase or data transport, and its merged manifest no Google component;gplay's merged manifest has noMlKitInitProviderand noCctBackendFactory; the transport uploader deletes events without a backend (transport-runtime3.1.9 bytecode).detekt ktlintCheck lint alohaArchitectureCheck,alohaUnitTests,alohaScreenshotTests, both flavours assembled. Universal release APKs: 32.6 MB (F-Droid) and 33.0 MB (Play), up from 7.1 MB, almost all LiteRT's native code for four ABIs (~19 MB) and the model (5.2 MB); about 9.5 MB on an arm64 phone. Per-ABI APKs and an App Bundle would bring the download down to that and are a follow-up. Not run on a device: the emulator has no AICore, so Gemini Nano is tested through fakes, and LiteRT inference runs only on a device.Checklist
detekt ktlintCheck lint alohaArchitectureCheckgreen, no baseline grownpaneTitleon new screens, 200 % font previewstrings.xmlwith translator commentsdocs/updated where behaviour changedAssisted-by:)New dependencies:
com.google.ai.edge.litert:litert1.4.2 (Apache-2.0, TensorFlow Lite's open-source successor; no reporting code; native libraries 16 KB-aligned) and the bundled EfficientNet-Lite0 model (Apache-2.0, 5.4 MB, SHA-256 inACKNOWLEDGEMENTS.md).gplayImplementation):com.google.mlkit:genai-prompt1.0.0-beta4. No permission; ML Kit's services in the merged manifest are not exported; its start-up provider and transport backend are removed.912D2C0ECCDA55C0(a Google signer, expired 2020, absent from keys.openpgp.org); its artifacts are pinned by checksum.