Private Provider

Android
Android

Private Provider is an Android app that runs a full ARM64 Linux runtime —
routstrd, Node, Bun, the Pi coding agent, git, ngit and a real shell
toolchain — sandboxed inside the app. No root, nothing to stand up on a
server, no laptop. Then it makes your phone a place you can ship from.

Build it, sign it, publish it. Install the optional pinned toolchain (JDK,
aapt, apksigner, R8) and Pi builds an unsigned APK on the device; the app signs
it with an app-private keystore and the agent never sees the key.

Your repos, on Nostr. Clone any ngit project from a nostr:// URL, then
work with pull requests, issues and releases — with publishing targets beyond
git: Blossom storage, GRASP servers, Zapstore catalogues, NIP-5A static sites
and OCI container images.

Private AI you can audit. Attested tinfoil-* models are served by
privateprovider.xyz, and the attestation shown comes from the daemon's real
TEE verification events, not a badge the UI painted on. Choosing any other
model requires explicit "Not private" approval.

Your money, your keys. A self-custodial Cashu/Lightning wallet behind a
mandatory recovery-phrase backup, with provider API-key escrow and NPC
usernames.

Five windows — Chat, Pi Agent, Files, Wallet, Monitor — over one sandboxed
runtime. Plain Java, no AndroidX, no Compose.