Private Provider is an Android app that runs a full ARM64 Linux runtime —routstrd, Node, Bun, the Pi coding agent, git, ngit and a real shell
toolchain — sandboxed inside the app. No root, nothing to stand up on a
server, no laptop. Then it makes your phone a place you can ship from.
Build it, sign it, publish it. Install the optional pinned toolchain (JDK,
aapt, apksigner, R8) and Pi builds an unsigned APK on the device; the app signs
it with an app-private keystore and the agent never sees the key.
Your repos, on Nostr. Clone any ngit project from a nostr:// URL, then
work with pull requests, issues and releases — with publishing targets beyond
git: Blossom storage, GRASP servers, Zapstore catalogues, NIP-5A static sites
and OCI container images.
Private AI you can audit. Attested tinfoil-* models are served byprivateprovider.xyz, and the attestation shown comes from the daemon's real
TEE verification events, not a badge the UI painted on. Choosing any other
model requires explicit "Not private" approval.
Your money, your keys. A self-custodial Cashu/Lightning wallet behind a
mandatory recovery-phrase backup, with provider API-key escrow and NPC
usernames.
Five windows — Chat, Pi Agent, Files, Wallet, Monitor — over one sandboxed
runtime. Plain Java, no AndroidX, no Compose.