Version 0.7.3 · latest release
Confidential AI, Pay Privately, Publish without Permission
Research, build, collaborate, pay and monitor — from anywhere.
Private Provider is a phone-first AI workspace for Android (ARM64). It runs a
bundled local runtime with routstrd and the Pi coding agent, pays for
inference with a built-in Cashu wallet, and publishes projects through ngit with an
external Amber signer.
Signed with certificate 2b356f863d6d752ca7767c68251fea91ab85a2f4ca33366f973bcb37c59bacfa.
Please read the known limitations before installing.
What's new in 0.7.3
- The project folder shows which draft you're on — the status line names the branch it describes, so it's clear what "ahead" or "behind" refers to.
- "Go to main" button — when a project sits on a pull-request or feature draft instead of the default branch, the project page offers a one-tap return to the default branch. Local only: it never fetches, pushes, or signs.
What's new in 0.7.2
- Pi can ask the app to do ngit actions — ask Pi to open a pull request, comment, label, or file an issue, and the app shows a consent dialog with the exact command. You approve; Amber signs. Merge, push-to-main, close and resolve are offered only for repositories you maintain, and Pi never gets your signing key.
- New ngit runtime (ngit 3.0.3, runtime 0.1.8) — fixes pull-request pushes when the change is already committed on your default branch, and keeps multi-line PR descriptions intact.
- Accurate project sync status — the project page now compares the checked-out branch against its configured upstream, so a branch that is ahead reads "N commits to push" instead of "up to date".
- Push and preview safety — "Push to main" requires the default branch to be checked out; a conflicted PR merge is no longer reported as success; the PR preview no longer modifies your Git index; and same-title PRs get a free branch name instead of failing.
What's new in 0.7.1
- Project page checks for updates — opening a project's ngit page now fetches the Nostr remote first, so the status line and the Update button show a real "N behind" instead of a stale "up to date".
What's new in 0.7.0
- Requests keep running in the background — Chat and the Pi agent continue when you switch apps or lock the screen, with a notification to cancel.
- Guided tour — a short tour over the real five panels replaces the old onboarding text, with a new first-run splash.
- Pi PR assist — ask Pi to review a pull request's diff, Draft with Pi a PR, or draft a review comment. Pi never gets your signing key, and you approve every publish.
- Redesigned recovery-phrase backup screens that match the app's look.
- Fix: a branch that is ahead of the remote but has a clean working tree can now be proposed as a pull request.
Why it's different
Confidential AI
Choose a tinfoil-* model and your prompt is encrypted to the
attested enclave. The app verifies the hardware measurement and shows the TEE
evidence per prompt. Non-attested models are clearly labelled
“not private” and need your explicit approval.
Pay privately
Top up a Cashu wallet and pay per query. No accounts, no email, no
subscriptions, no credit cards, no KYC. No telemetry, no analytics, no tracking
identifiers. You pay only for what you use.
Publish without permission
Every project directory is a full git repository. Publish it to Nostr with
built-in ngit — open issues, comment, send pull requests, cut releases — all in
the app. Signing goes through Amber (NIP-46), and your npub stays pseudonymous.
No platform gatekeeper.
What's included
Chat
Multi-turn chats. tinfoil-* models are verified by hardware
attestation and sent encrypted to the attested enclave. Choosing a
non-attested model requires an explicit “Not private” approval.
Save any exchange as an artifact file in your workspace.
Pi Agent
A coding agent that works in the app's /workspace. It can build
Android APKs on the phone with an optional, separately downloaded build
toolchain. Pi never receives your Nostr signer.
Files
A project workspace with ngit publishing, releases, pull requests and issues.
Publishing is performed by the app and signed through Amber (NIP-46). Amber is
optional unless you publish.
Wallet
A Cashu wallet with Lightning top-up and Cashu send. A recovery-phrase backup
is required before the wallet is used.
Monitor
Usage, providers, logs, attestation evidence, a privacy statement and
data-clearing controls.
A full Pi Agent and on-device APK builds — no laptop required.
Clone any ngit repo, open pull requests and issues, comment, and collaborate over Nostr — all in the app.
Get the app
Version 0.7.3 (274), for Android 8.0+ (API 26+) on an
ARM64 device.
Requirements
- Android 8.0 or newer on an ARM64 device.
- About 185 MB to download, and roughly 2 GB free storage on first launch while the local runtime installs.
- The optional on-device build toolchain is a further ~82 MB download.
- A small Bitcoin / Lightning balance for paid inference.
Download
-
Preferred: open the
release page,
find 0.7.3, and tap the APK asset. It downloads from Blossom and Android offers
to install it.
-
Direct download from Blossom (same file, byte-identical):
Verify what you install
The APK is content-addressed, so the URL itself is the SHA-256 of the file.
- File —
private-provider-0.7.3-274-product.apk
- SHA-256 —
a19da920f8698e392ef03cf4c2836d9328733e0bafe0ffd2da912e3165a0dc84
- Signing certificate SHA-256 —
2b356f863d6d752ca7767c68251fea91ab85a2f4ca33366f973bcb37c59bacfa
To check on a computer, download the APK and compare its hash:
sha256sum private-provider-0.7.3-274-product.apk. Future updates will be
signed with the same certificate.
Install on the phone
- Download the APK (either way above).
- Android will ask to allow that browser or file manager to install unknown apps — allow it only for the app you're using.
- Tap Install, then open Private Provider.
- First launch needs ~2 GB free; onboarding installs the local runtime in the background.
About the attestation
Attested tinfoil-* inference is the core of the app. The Monitor tab
shows the trusted-execution-environment (TEE) evidence and a verified
Attested status — the hardware measurement matches the signed
build.
Why it matters: your prompt is encrypted on your device and can only be decrypted
inside the secure enclave. A trusted execution environment (TEE) is a
sealed part of the processor that runs code in isolation from the rest of the
phone, and it can prove cryptographically which code is running. That proof is the
attestation — the app shows it, so you can check the claim instead of trusting it.
Not every model is private. Models that are not attested are labelled
“not private” and require your explicit acknowledgement
before use. The app does not pretend otherwise.
Status and limitations
Version 0.7.3 is the latest public release. It has not been
independently audited. These limitations are real — please read them:
- Wallet recovery is not available. The recovery phrase cannot currently restore funds in the app. Keep only small amounts and protect the device.
- Non-attested models are served by third-party providers that can read the prompt.
- Pi sessions and workspace files are protected by Android's sandbox and device encryption, but are not additionally encrypted by the app.
- Background operation requires the app to remain open. Tor routing is not yet available.
- Tested primarily on a Google Pixel 6a. Other ARM64 devices may work but have not been broadly verified.
This site describes what the app does today, not a promise of what it will do.
Learn more
The application source is free software under the GNU General Public License,
version 3 or later. It is distributed without warranty. Bundled native components
keep their own licenses.