# Roadmap (original 5 phases + missing pieces filled in) Legend: [ ] todo, [~] in progress, [x] done and tested on a real device ## Phase 0 - Foundations (was missing) - [~] Repo, license, README, architecture doc - [ ] Tech stack decision: Kotlin + Jetpack Compose UI, Room (SQLCipher), native llama.cpp via JNI (NDK, arm64-v8a only to hold size down) - [ ] CI: GitHub Actions / HF Jobs build, lint, unit tests, signed release APK, R8 shrink + resource shrink - [ ] Size budget gate: CI fails if base APK > 15 MB - [ ] Crash reporting (local only, no telemetry), logging ## Phase 1 - UI / UX - [ ] Universal Capture Bar (text, voice, share-intent, clipboard) - [ ] Dashboard + cards, glassmorphism and flat themes, dark/light/system - [ ] Responsive layouts (phone, tablet, foldable), accessibility (TalkBack, font scale) - [ ] GUI <-> raw CLI instant toggle - [ ] Onboarding + permission explainer screens (missing in original) ## Phase 2 - Core architecture and storage - [ ] Room database with SQLCipher - [ ] AES-256-GCM vault, key in Android Keystore, optional biometric unlock - [ ] Backup / export / import (encrypted), wipe-all - [ ] Settings + migration framework (missing in original) ## Phase 3 - Model station - [ ] Device profiler: SoC, ABI, RAM total/free, GPU (Vulkan/OpenCL), storage speed - [ ] Tier matrix: Ultra-Light 1-3B, Balanced 7-8B, Power 14B+ -> quant, ctx, est. tokens/s - [ ] Downloader: HuggingFace, Ollama registry, direct URL; resume, checksum (SHA-256), Wi-Fi-only, disk-space check - [ ] GGUF loader (llama.cpp), ONNX Runtime backend, cloud fallbacks (OpenAI, DeepSeek, Anthropic) with keys in vault - [ ] Hot-swappable storage dir (mount / unmount / wipe), user override for oversize models - [ ] On-demand localization: fetch 20-50 KB JSON locale, hot-swap, persist or purge ## Phase 4 - Power modes and plugin sandbox - [ ] 7-tap hidden dev menu - [ ] Foreground service with wake-lock management and battery-optimization guidance - [ ] PRoot rootfs installer (Ubuntu/Alpine/Debian), terminal emulator, apt/apk/pip - [ ] App functions exposed as CLI commands - [ ] Termux bridge (RUN_COMMAND intent), ADB-over-wifi, optional root/su - [ ] Plugin runtime: manifest, declared permissions, sandboxed execution, event hooks, signature check - [ ] Accessibility / overlay services, off by default, explicit consent (Play-policy aware) ## Phase 5 - Testing and updates - [ ] Unit + instrumented tests, benchmark suite for tokens/s - [ ] In-app updater: signed update manifest, SHA-256 + signature verification (replaces unsafe "hot reload" in release builds) - [ ] Debug-only local OTA / hot-reload server - [ ] Test-build distribution, changelog, versioning - [ ] Release checklist: APK attached only after install + smoke test on device ## Notes on gaps in the original roadmap Security model, CI, size budget, updater signing, migrations, accessibility, onboarding and legal/licensing of downloaded models were absent and are added above.