01Describe what you need
Start with your purpose in plain language.
A model proposes a typed plan. Deterministic admission checks it against a closed capability contract. The native host runs only capabilities it actually supports, with explicit permissions.
What you need, in plain language.
A model proposal, never execution authority.
Deterministic checks against a closed capability contract.
Reviewed capabilities, local persistence, no generated code.
01Start with your purpose in plain language.
02The proposal describes state, views and actions; it is not executable code or permission.
03The plan is checked against a closed capability contract and the native runtime's supported surface.
04Your Space persists on your phone. It runs only reviewed capabilities, never generated code.
The typed plan describes state, views and actions. Deterministic compilation and admission reject invalid structure or unsupported operations. A plan cannot approve itself, grant file access or introduce executable model-written code.
Passing structural checks does not mean every runtime can execute the plan. The Android host still decides capability availability, current state, permissions and operation bounds. Failures are surfaced rather than hidden behind a fallback.
Admitted Spaces use on-device state. Image operations preserve the original and keep derived results separate. Export requires an explicit user request; the deletion flow offers a complete-Space backup before confirmed deletion.
Android-first, in development. Image Spaces run in debug builds and are not enabled for production users. Image formats, resource bounds, real-photo behavior and accessibility are still being verified. See the real phone captures on the Product page for examples of the current debug build.