How it worksIn development

Describe it. Check it. Keep it.

A model proposes a typed plan. Deterministic admission checks it against a closed capability contract. The native host runs only capabilities it actually supports, with explicit permissions.

01 / PIPELINE

Four responsibilities

01compile

Describe

What you need, in plain language.

02compile

Typed plan

A model proposal, never execution authority.

03compile

Admit

Deterministic checks against a closed capability contract.

04execute

Native Space

Reviewed capabilities, local persistence, no generated code.

01

Describe what you need

Start with your purpose in plain language.

02

A model proposes a typed plan

The proposal describes state, views and actions; it is not executable code or permission.

03

Deterministic admission validates it

The plan is checked against a closed capability contract and the native runtime's supported surface.

04

A native Space you keep

Your Space persists on your phone. It runs only reviewed capabilities, never generated code.

02 / AUTHORITY

A proposal is not permission

Open-ended purposes. Bounded execution authority.

The typed plan describes state, views and actions. Deterministic compilation and admission reject invalid structure or unsupported operations. A plan cannot approve itself, grant file access or introduce executable model-written code.

Passing structural checks does not mean every runtime can execute the plan. The Android host still decides capability availability, current state, permissions and operation bounds. Failures are surfaced rather than hidden behind a fallback.

03 / LOCAL LIFE

A native Space you keep

Persistence, export and deletion belong to the product.

Admitted Spaces use on-device state. Image operations preserve the original and keep derived results separate. Export requires an explicit user request; the deletion flow offers a complete-Space backup before confirmed deletion.

Current limits

Android-first, in development. Image Spaces run in debug builds and are not enabled for production users. Image formats, resource bounds, real-photo behavior and accessibility are still being verified. See the real phone captures on the Product page for examples of the current debug build.