PHNTM One
Autonomy · software 0.8

A computer that looks after itself.

PHNTM One heals itself, repairs with an undo and keeps score of every fix, in every mode, with the internet unplugged. And when you want it to act for you, Autonomous mode takes your instructions from Telegram and waits for your yes before it sends an email or changes your calendar.

Works offlineBudgeted, never franticConfig and index repairs have an undoNever touches your accounts on its own
The self-maintenance loop Five steps in a ring: detect, decide, repair, verify, record. At the centre, the undo for configuration and index repairs: if any check fails, the device puts back exactly what was there and checks that too. undoconfig · index 01 Detectsomething died, driftedor filled up 02 Decidean allowed fix, inshipped order unlessits record clearly differs 03 Repairsnapshot, stage,apply 04 Verifycheck again,live 05 Recordkeep score ofhow it went
Self-maintenance

Three layers, each narrower than the last.

None of this needs the internet, and all of it runs in Private mode too. What it did shows under SYSTEM → Activity on the screen, in plain words.

Available now

It heals.

When the assistant, the model server or the Telegram bridge dies, it restarts it. It has its own fixes for memory pressure, a frozen screen, a failed boot self-test, a stale warm-up and a dropped Wi-Fi connection (it rejoins a network it already knows, and never asks for or changes a password). When the disk is nearly full it trims logs, clears the package cache and, if needed, deletes older backups, always keeping the newest.

Every fix is checked afterwards. At least two minutes apart, at most three in thirty minutes; when the budget runs out it waits before trying again (six hours, for the assistant itself) and tells you, unless you've set notices to Never; a notice about the assistant itself arrives either way.

Available now · early

It repairs, with an undo.

Some faults need more than a restart: a configuration file that drifted from what the release ships, or a memory or conversation search index that no longer matches what you told it. Those are repaired as a transaction: snapshot, stage, check, apply, check again live.

The change is kept only if every check passes. If not, it puts back exactly what was there, checks that too, and leaves a notice in your Journal. Your own words are never rewritten from an index; the index is rebuilt from them.

Available now · early

It keeps score of every fix.

Every incident and every repair outcome is recorded on the device. Where it has more than one allowed fix (today: an unresponsive model server and the two search indexes), it can try one out of the shipped order first: once each of the fixes it is weighing has been tried at least five times, across at least three separate incidents, and one has a clearly better record.

It can also hold back a fix that keeps failing, for up to 30 minutes. It only ever chooses among fixes it was already allowed to make, every unit starts with no evidence, and many units may never see one fault often enough to use it.

Alongside those, it watches for trouble coming, like a disk filling up or memory creeping, and may warn you. Those parts only watch and record. They never act.

Autonomous mode

Message it. It acts, after you say yes.

The third brain choice, next to Private and Boosted. It is Boosted plus actions you ask for from your own Telegram. It is off until you turn it on, it uses Claude on your own Anthropic key (so it costs you money), and turning it on from a phone needs your device password.

What you can ask it to do
  • Check how the device is doing
  • Set, list and cancel reminders, and show your open loops
  • Search and read your email, draft a message or a reply, and send it
  • List your Google Calendar, and add, change or delete events

Only your own paired Telegram account, in a private chat, is listened to. On the screen and the phone app it never sends email or changes your calendar; those actions come only from Telegram.

How it asks first
  1. Every email is shown to you in full before it's sent (recipients, subject, body), and every calendar change is spelled out before it happens.
  2. Nothing is sent or changed until you reply yes. Anything else drops it, and it expires after ten minutes.
  3. The approval is bound to exactly what you saw. If the draft or the event changed since, it refuses.
  4. A forwarded message can never approve anything.
What leaves the box

Not private, and it says so at setup. On a Telegram turn, what you ask, the recent messages in that chat, your and the assistant's names, your language and time zone, your recent email and calendar listings, and the results of the actions it runs (which can include full email bodies) go to Anthropic. Your messages and its replies travel through Telegram. The email and calendar actions you ask for, searching, reading and listing included, reach your email provider and Google Calendar; only sends and changes wait for your yes.

Every call to Anthropic, every email sent and every calendar request is written to the device's own egress ledger. Switch back to Private, and disconnect Telegram and email, and the wire goes quiet again.

The boundaries

What self-maintenance never does.

Touch your accounts.Self-maintenance never reads or acts on your email or calendar. If Telegram is connected, it may send you a notice about what it did.
Browse the internet.Healing, repair and keeping score all work with the router unplugged.
Update itself.Updates are always yours to start, and they roll back if the self-test fails.
Act on an AI model's decision.No model can start a repair or a restart. There is no tool for it.
Hide what it did.Fixes and budget stops show under SYSTEM → Activity; an undone repair leaves a notice in your Journal.
Ready when you are

An AI that keeps itself running.

Made to order, built by hand, and burned in for at least 24 hours before it ships. $549 once, with no subscription, ever.

ships within 7–10 business days after payment · free US shipping · 30-day returns

$549 once · no subscription
Order