Private Provider Private Provider is an Android app that runs a full ARM64 Linux runtime — routstrd, Node, Bun, the Pi coding agent, git, ngit and a real shell toolchain — sandboxed inside the app. No root, nothing to stand up on a server, no laptop. Then it makes your phone a place you can ship from. Build it, sign it, publish it. Install the optional pinned toolchain (JDK, aapt, apksigner, R8) and Pi builds an unsigned APK on the device; the app signs it with an app-private keystore and the agent never sees the key. Your repos, on Nostr. Clone any ngit project from a nostr:// URL, then work with pull requests, issues and releases — with publishing targets beyond git: Blossom storage, GRASP servers, Zapstore catalogues, NIP-5A static sites and OCI container images. Private AI you can audit. Attested tinfoil-* models are served by privateprovider.xyz, and the attestation shown comes from the daemon's real TEE verification events, not a badge the UI painted on. Choosing any other model requires explicit "Not private" approval. Your money, your keys. A self-custodial Cashu/Lightning wallet behind a mandatory recovery-phrase backup, with provider API-key escrow and NPC usernames. Five windows — Chat, Pi Agent, Files, Wallet, Monitor — over one sandboxed runtime. Plain Java, no AndroidX, no Compose.