Quick Start
owner edition · the printed 5×7 card in the box is the short form of this page
In the box
- PHNTM One (Raspberry Pi 5 · 8 GB · 10.1″ touchscreen · speaker)
- USB microphone — tap-to-talk (15 s), Notes dictation (60 s), optional local wake phrase (off by default)
- Mini wireless keyboard with thumb touchpad (its USB receiver is pre-installed)
- Power supply (27 W USB-C)
- The printed card, and a business card whose back carries this unit's serial
- Questions, anything at all: [email protected] — a person answers
Getting started
- Plug it in. That's the whole install.
- The screen shows startup progress while the assistant runs its boot self-test. Readiness and model warm-up take time; check the screen before starting a conversation.
- First boot opens setup on the touchscreen. Follow the steps for: language · network (Ethernet = zero config; Wi-Fi optional) · time zone · a name for the assistant · the username and password that become this device's login · your phone (optional) · the brain choice (Private, Boosted or Autonomous) · voice on/off. No cloud account, no app store, no computer needed.
- Pair your phone: tap Settings → Show pairing code (the device asks for your password), scan the QR with your phone camera, and a private chat opens in your browser — served from the device over your network, encrypted (HTTPS). No cloud relay in between. The first time, your browser says the connection is not verified: continue only if the certificate fingerprint it shows matches the one on the device screen. Want it verified every time? Install the device's own certificate on the phone (the pairing screen shows how); it is limited to this one device's name and trusts nothing else.
Things worth knowing up front
- Local chat by default. Private mode runs the model, memory search, transcription and speech on this device. Paired phone chat crosses your LAN. Telegram, if connected, carries messages through Telegram in every mode; optional cloud answers send context to your provider. Local chat needs no cloud account or internet connection.
- Say “remember that …” and the fact is written to disk before the answer is generated. Wait for the save confirmation; sudden power loss can still damage storage.
- When does memory update? Use the direct memory editor, explicitly say “remember …”, or let background extraction consider a fact from your conversation. “Remember …” is saved explicitly and appears in Library → Memories after confirmation. Everything else you say is considered by a background pass a few minutes after the conversation goes quiet; it keeps at most one fact per exchange. Library → Memories lists stored facts; deleting one removes it from active memory and recall. Copies in older backups are separate.
- What does it already know? General knowledge from its model (Gemma 3 — think “well-read, not up to the minute”), the facts about itself in the manual, and the handful of setup facts you see in Library → Memories on day one (your name for it, language, time zone, brain mode). Nothing about you until you tell it — and then it grows with you.
- Wi-Fi later: Settings → Wi-Fi settings (or Device › Connect) (new router, new house).
- It speaks. Answers to spoken questions and status updates come through the built-in speaker.
- Written language. Setup and Settings select the preferred language for written answers. Manual speech recognition and spoken replies currently use English assets; other spoken languages are not qualified.
- Talk to it. Tap the 🎤 next to Send (or press Alt+M on the keyboard), speak, and your words appear in the chat box for you to review before sending — then the full answer's prose comes back out loud after the answer finishes. Code blocks and citation metadata stay on screen. Stop speaking stops playback and the remaining queued speech. Tap the microphone again to stop recording early — or just stop talking, it notices. Manual Talk captures up to 15 seconds; Notes captures up to 60 seconds. Optional Hello Phantom uses the microphone continuously when enabled. Detection pauses during playback, setup and maintenance, but ambient audio may still be captured and discarded. Manual recording takes priority. It starts off. Use Settings → Wake phrase to enable or stop it. Typed questions are answered silently. Volume lives in the Settings menu.
- The full manual is on the device: this page, plus this unit's burn-in certificate
at
/docs/certificate (on your own device). The manual and certificate work offline. - SSH is yours (never required, never removed):
ssh <your-username>@phntm-one-<serial>.local— the username and password you chose during setup are this device's login, for the Terminal, forsudoand for SSH. Or use the IP shown on the device's screen. Thephntm-one-<serial>name is the unit's serial, so it is easy to spot in your router's client list.
The nav — left edge of the screen
| Home | conversation and voice, tasks, measured system and network readings, connected Linux computers and project activity; Layout chooses the widgets |
| Chat | the conversation |
| Tasks | reminders — it speaks up on time; presets, pause, skip |
| Notes | saved originals, dictation and reviewed drafts |
| Library | Memories (yours to read and delete) · Documents (the vault — PDFs and photos in, cited answers out) · Open loops |
| Device | health, gauges and the live count of external connections · Activity · Journal · Connect · Care |
The orb and the health line sit above every view; tap Settings (top right) for the full menu.
Reminders are stored on this device separately from their Telegram alerts. The Reminders view shows remote alerts as pending, sent, failed or unknown. Unknown means delivery was not confirmed. Retry asks you to accept that a previous attempt may already have arrived and a duplicate can be sent.
If something looks wrong
- Screen dark but the device answers? Touch the screen to wake it. If it stays dark, use a paired phone to check status and save a diagnostics bundle before recovery. Contact support for a persistent dark panel; software health readings cannot prove that the physical panel is displaying. Avoid interrupting an update or cutting power while data is being written.
- Anything else: the technical notes explain services, logs, and factory reset — or email me directly. You get the builder, not a queue: [email protected]
What it does
These system instruments run on this device. Routine proactive speech follows your voice setting and quiet hours; urgent temperature or storage warnings may bypass quiet hours. Successful automatic repair and network-restoration notices stay quiet with the default Important updates setting.
Useful spoken updates
Proactive updates come from recorded events, such as a persistent warning, a completed backup or an update result. With All updates selected, a recovery can be spoken after a meaningful fault you were told about. These queued updates wait while you are talking, listening or hearing a reply; expired or resolved warnings are discarded. Silent voice or Never updates suppress queued proactive speech. This event-driven lane does not create an announcement just because time passed.
Spoken Ambient updates are separate from the visual Ambient face above. This optional setting allows occasional spoken facts about this device. It requires Voice Speaks and Updates: All, respects quiet hours and yields while you are using the assistant. The device chooses among currently supported health, privacy, memory and backup readings and stays quiet when it cannot support a line. Turning it on does not promise speech at a particular time.
Ask about this device
Ask “What operating system are you running?” for this device's operating system, kernel and PHNTM One version. Chat also receives measured CPU, temperature, memory, storage and health readings when available. Vitals and health retain their original sample ages; old or missing readings are reported as unavailable, and an unverified wall clock is identified.
Computer Black Box
When you connect a supported Linux computer, you can separately grant Black Box recording. PHNTM One then keeps a bounded history of numeric CPU, memory, storage, aggregate network-byte and uptime readings, plus temperature and GPU readings where Linux exposes them. Samples recorded during the current PHNTM boot age out after 24 hours; samples from earlier PHNTM boots remain subject to the 6,000-sample and storage caps. The timeline holds at most 100 recent bookmarks and observations. Five-minute summaries, sustained threshold observations, owner-written incident bookmarks and a JSON evidence export help you inspect what was happening around a slowdown. Measurements are companion-reported, not independently verified; a threshold is an observation, never a diagnosis. Missing readings stay unavailable. The computer clock is labeled unverified and never used to order events across devices. The history is stored on this PHNTM One, not sent to PHNTM or a cloud service. Process names are off by default; a separate permission can retain up to five same-user process names and CPU/memory readings, without PIDs, arguments, paths or window titles. File contents, screen contents, clipboard, audio and network payloads are not collected. Removing a permission stops new readings of that kind after the companion receives the change; retained readings remain subject to the retention bounds or can be erased by you. Revoking a computer stops future collection but preserves retained history subject to those bounds. Black Box history is not included in the regular device backup; export it separately if you want to keep a copy.
Resting Face
Ambient mode is enabled by default when no layout preference has been saved. After three minutes without interaction, the face shows a dim system pulse, time and date, measured CPU usage and temperature, and a labeled activity color. Each pulse acknowledges a new system sample (normally every five seconds); it is not a CPU cycle or proof that every service is healthy. Mint means ready, teal listening, blue speaking, violet processing or approved work, amber waiting or degraded health, and grey unavailable readings. Missing instrument values show a dash. Stale system samples stop the pulse. The clock is labeled unverified until status confirms time synchronization. After twelve minutes it dims further; the resting layer shifts slowly to vary pixel placement. Touch or press a key to wake. Critical health conditions wake the full interface. Layout can turn ambient mode off; an existing saved choice is respected. This is a dimmed UI, not a panel power-off or a guarantee against image retention.
Local Mode (Own the Unplug)
If the internet goes away, the screen says so plainly and keeps working — chat, memory, reminders, notes and voice all run here, with or without a connection. Restoration is recorded quietly by default; All updates can speak a meaningful recovery after an earlier spoken warning.
Watch the Wire
In Settings → Data & Privacy, tap Watch the Wire for a 60-second observation. Talk to the device and watch two separate meters counted from the device’s own instruments: your conversation (the assistant’s own network connections and any logged sends — expected to be zero for local chat when external integrations are disconnected) and the whole machine (sampled internet byte totals, including OS and desktop-app traffic). These samples do not reveal packet contents and can miss short connections. The byte display can lag during the run; Start and Stop request fresh readings. Unreadable sources, a reboot or a detected counter reset make the observation incomplete. Process permissions can prevent socket attribution even when the device is operating normally.
Backups
The device backs itself up every night to ~/phntm-one-backups (or a USB backup destination you configure). Every archive is encrypted before it is written: on this device it opens by itself for a restore;
on another device it needs your device password or your recovery code — a lost stick is unreadable without them.
Until you have signed in (or used your password on the screen) once after the update that added this, archives can
be opened on this device only; older unencrypted archives are kept until then, and replaced by encrypted ones
after. An archive opens elsewhere with the password or recovery code that was current when it was made:
after you change your password or make a new recovery code, new archives carry the new one (and never the old one)
once you have used it on the device, and the backup list shows which archives today's password or code opens. After
an update, backups open elsewhere again once you have used your password once (a recovery code: once you have used
it or made a new one); until then "Back up now" says the backup opens on this device only.
Take Everything
In Settings → Data & Privacy, tap Export My Data to write a portable copy of your data to a USB stick: your memories, reminders (as a calendar file), open loops, the documents you gave the device, and your preferences — with a manifest and checksums. The reminder calendar file contains active events; reminders.json preserves recorded delivery/completion timestamps and pause state. Importing the calendar file does not promise an alarm or recreate PHNTM One reminder execution. Your device’s secrets (keys, pairing, passwords) never go on the stick. The copy is only marked complete once every file is written and verified; a stick pulled early is never mistaken for a finished one.
Your conversation history
Completed conversation turns are stored here, indefinitely by default, and are searchable locally — ask “when did I talk about the noisy fan?” to search for related retained messages. Retrieval can miss a match or return an imperfect one; interrupted turns may be incomplete. Your history stays here until you decide otherwise: choose a shorter retention window, or clear it, under Data & Privacy, and it’s included when you Take Everything. The search runs on the device; your conversations are never sent anywhere to index them.
Send files here (PHNTM Drop)
Send files to your PHNTM One from any computer or phone on your home network. On the PHNTM One screen, open Data & Privacy › PHNTM Drop to see the exact web address — it looks like https://phntm-one-<serial>.local:8843/drop — and a QR you can scan. Open that address in a browser on your network and drag files onto the page (PDF, text, Markdown, JPEG and PNG). They cross your own network to the device, are read and indexed here. Photos and scanned pages use local text recognition (OCR), which can misread or miss text; this is not general image understanding. In Private mode, document questions are answered locally. Optional cloud answers can include retrieved document excerpts. Answers can include file/page references when the source-use check finds support in retrieved passages; a citation does not guarantee the answer is correct. Delete files in Library → Documents; Take Everything exports it all.
Memory Constellation
In Memory, switch to Constellation to see what the device remembers as a map. Every dot is a real memory; a line between two dots means they share a keyword — nothing is invented to make the picture prettier. Tap a memory to read it or forget it; forgetting removes it here and from the searchable copy. Open loops are kept separate — they are not durable memories.
Command center
The home screen brings together conversation, due work, system instruments, network readings and selected computer projects. Open a card for details. Layout lets you choose the home widgets and ambient mode; your choices are saved on this device. The activity indicator labels observable stages such as listening, processing, speaking and approved computer work. If its readings stop arriving, it shows disconnected or stale state instead of continuing to imply activity.
CPU is measured from processor-counter changes; network traffic is measured from interface-counter changes. A link rate is the connection’s negotiated capacity, not an internet speed test. Network neighbors are a partial passive view, not every device on your network. Missing readings say unavailable. Performance separates recorded transcription, response and speech synthesis durations where observed; synthesis excludes playback. Response percentiles cover measured model-route requests and include routing and retrieval. Old or missing health and model readings are identified rather than filled with estimates.
Connect Computer — Linux
Open Workspace → Connect computer. The setup address and instructions appear before you create a code. Open that HTTPS address on the Linux computer you want to connect. For a first connection, the touchscreen shows separate SHA-256 fingerprints for the website certificate and appliance CA. If your browser warns about the website certificate, inspect its SHA-256 fingerprint before trusting it and compare it with the website fingerprint on PHNTM One. Continue only when the full fingerprint matches, using trust limited to that certificate and website. If the browser cannot show it or it differs, stop and use a trusted local CA transfer instead. After verifying the website, download its public CA and compare the CA fingerprint separately. An unauthenticated download alone does not authenticate the installer; never disable certificate verification globally. Download the personalized ZIP, extract it, open a terminal in its phntm-computer folder and run sh install.sh. Setup uses desktop dialogs when Tk and a desktop display are available, with terminal prompts otherwise. It shows this appliance’s address and fingerprint for confirmation and asks for a code privately. Create the single-use, five-minute code on PHNTM One when the installer is ready. After successful pairing, setup starts the user service and checks for an authenticated heartbeat. A pairing alone does not mean the computer is connected. If startup cannot be confirmed, setup reports that and retains the pairing. The included README explains requirements, recovery and selecting repositories, folders and named workflows.
The companion runs as your computer user, opens no listening port and defaults to read-only telemetry. Content access and workflow execution require separate permission on both computer and appliance. Workflows execute the approved program and arguments as your user; approve only code you trust. There is no unrestricted remote-shell request or automatic screen/clipboard capture. Windows, macOS and computer inference routing are not supported.
Stop the connection with systemctl --user stop phntm-computer. Revoke it on PHNTM One to invalidate its token. Revocation blocks further communication, but already launched work can finish locally; stop that work on the computer if needed. Disconnects retain the last observed readings and durable receipts, marked with their availability. Work is not automatically repeated after restart or disconnect; an unknown outcome stays unknown. Appliance request deduplication covers retained receipts, so do not retry an old request after its receipt has been evicted. The companion also bounds receipt history by encoded bytes: acknowledged history may expire early to reserve final evidence before execution; insufficient space refuses work. Oversized optional evidence is explicitly marked truncated without changing the recorded process outcome. Stop the companion before pairing or unpairing. Each pairing has its own durable receipt queue; re-pairing never submits older or unbound legacy receipts under new credentials. The companion’s unpair command removes local credentials and retains receipt evidence as inactive local archives. Archives are bounded to 32 queues of at most 2 MB each, plus a legacy file of at most 4 MB; pairing refuses at capacity rather than deleting evidence. The status command identifies the current queue for safe export of older archives; sh uninstall.sh removes the program and service while retaining local configuration for inspection.
Project Resume and outcome receipts
Inspect a selected repository to see its reported branch, tracked-file dirty state, recent commits, contribution counts and project note. The heatmap covers all authors in the observed Git history, not just your contributions. Project Resume combines that context with available job receipts and your approved note. The timeline shows commits and requested jobs as separate evidence streams; it does not infer that a nearby commit caused a test result or deployment. Computer-reported results remain identified as such. Repository-associated receipts can show what an approved workflow observed, but complete request-to-commit-to-deployment linkage is not implemented.
Closing Veil
On the device screen, Device → Care → Reset & power has a Power Off control. Confirm it, then wait until the screen is dark before disconnecting power. The control sends a shutdown request; its response does not prove shutdown has finished. It is unavailable from a paired phone.
When the device restarts, resets or installs an update, it covers the technical shutdown with its own screen and a plain message (“Restarting…”, “Installing an update — keep me connected to power.”). The message identifies the requested operation. If a handled error occurs, the interface reports it; a power loss, failed service or dark physical panel can prevent the UI from showing the result. Check status after recovery.
Technical Notes
Support: [email protected] — the builder answers. Include the serial from the back of the business card and, if it helps, the diagnostics bundle from the phone app (it contains no conversations, memories or credentials).
everything here is inspectable over SSH — poke at all of it
Burn-in certificate
This unit's own measurements — every boot it has logged, first-try pass rate, benchmark
numbers — are rendered at packing time and served by the device at
/docs/certificate (on your own device). Nothing estimated; a value that was
never measured prints as a dash.
Notes and ideas
Open Notes in the left rail. Type or record a thought, review the recognized text, then choose Clean up, Develop idea, or Project checkpoint. AI processing stays on this device in every mode. Your original is saved before generation; drafts remain separate. Review suggestions before choosing Keep draft. AI can make mistakes and suggestions are not verified facts. Notes never execute a plan or automatically become memories.
Project checkpoint groups your original statements under section labels chosen by the model, preserving their wording and order. It does not invent progress or next actions. At the text limit, statements take priority over headings.
Develop idea separates unverified AI suggestions from a verbatim copy of your original note. Suggested steps and possible tradeoffs still need your review. Originals are limited to 6,000 characters; saved AI drafts can include up to 12,000 characters so the original and suggestions fit together.
Notes generation uses the primary local model. If it cannot run, your original stays saved and you can retry; Notes does not switch to the smaller chat fallback. Long notes and cold model loads can take several minutes.
Each recorded clip is limited to 60 seconds. Once speech begins, thinking pauses do not end a Notes clip; a clip with no initial speech ends after 10 seconds. Use Stop & transcribe or Discard clip. Add another clip after transcription. Raw audio is temporary; saved text and revision history are included in data exports and database backups. Deleting a note does not remove earlier exports or backups.
Hello Phantom
In Settings → Wake phrase, explicitly enable local phrase detection. Say Hello Phantom, wait for the Listening indicator, then ask a general question. This is a two-step interaction. Detection pauses during the device's speech, manual recording, setup and maintenance. The detector is English-only. Similar-sounding speech can trigger it, and noise or distance can cause missed detections. A detected phrase does not identify who spoke.
Hands-free answers use a temporary local conversation, without your personal memories, documents, notes or action tools. Ambient audio is neither saved nor sent online. Turning wake detection off stops its capture; manual Talk and Notes remain available. This setting is software control, not a physical microphone disconnect. A fault is shown as unavailable, rather than Ready. Use Test phrase for detection-only feedback.
Hardware
| Compute | Raspberry Pi 5, 8 GB RAM, quad-core Cortex-A76 |
| Display | 10.1″ 1920×1200 IPS, 5-point touch (HDMI panel) |
| Audio | Built-in speaker (the assistant talks) |
| Microphone | USB microphone (included) — manual recording plus optional local “Hello Phantom” detection (off by default) |
| Keyboard | Mini wireless keyboard with thumb touchpad (included; Alt+M = talk shortcut; Tab moves focus) |
| Power | 27 W USB-C PD supply, included |
| Cooling | Active fan, thermally governed by the Pi 5 firmware trip points — quiet at idle, ramps under load |
| Storage | 256 GB microSD; the filesystem expands to the full card on first boot (NVMe is an upgrade path, not the shipped configuration) |
| Network | Gigabit Ethernet + Wi-Fi (2.4/5 GHz) |
| Battery / RTC | No device battery, UPS, or RTC coin cell is installed. Time comes from NTP; after an offline cold power loss, wall-clock time may be unknown until network time returns. |
Software stack
| OS | Debian 13 (trixie), stock kernel, systemd |
| Inference | Ollama / llama.cpp, bound to 127.0.0.1 only, run with --offline |
| Chat model | phntm-one:chat — Gemma 3 4.3B, Q4_K_M, 8K context configured |
| Fallback model | llama3.2-phntm-one:fallback — Llama 3.2 3B, Q4_K_M (RAM-pressure fallback, chosen by a boot-time RAM ledger) |
| Embeddings | nomic-embed-text (local memory/RAG recall) |
| Speech-to-text | whisper.cpp (base.en q5_1), on-device, runs per-utterance and exits; the separate optional wake detector captures continuously when enabled (off by default) |
| Voice out | Piper TTS (en_GB-northern_english_male-medium), on-device |
| App | Python/FastAPI (uvicorn) on port 8800 |
| Face | Firefox ESR (kiosk window, user unit phntm-one-face) in a minimal desktop session showing http://127.0.0.1:8800/screen — Settings → Exit to desktop; double-tap PHNTM One to come back |
| Apps | Settings → Apps (or the Apps tile on the desktop): Files, Text Editor, LibreOffice, Browser and Terminal open in their own window, as your own account, in front of the assistant. The desktop panel also carries a small network item: which link is up (Ethernet, Wi-Fi, both) and how far it goes — green only when the internet was confirmed by traffic this device already makes (the clock sync), pale when there is a way out nobody has verified, amber for local-only or a sign-in page, grey when offline. A sample document to try the vault on ships in Documents/Try PHNTM-One. |
Where things live
- Runtime + code:
~phntm/phntm-one(Python; readable, greppable). The assistant runs as its own service account,phntm, separate from your own login. - Models:
/usr/share/ollama/.ollama/models(standard Ollama layout) - Memory / conversations / settings:
~phntm/phntm-one/data(SQLite in WAL mode withsynchronous=FULL— commits use fsync for durability, but sudden power loss can still damage storage — plus JSON state and a local Chroma index; your data, in files you can read and delete) - Logs:
journalctl -u phntm-one -u phntm-one-loops· the face:journalctl --user -u phntm-one-face
Services
| unit | role |
|---|---|
| phntm-one | Assistant API — brain, memory, RAG, web UI (port 8800) |
| phntm-one-loops | Health monitor and the caretaker: the self-maintenance below, plus briefings |
| phntm-one-warm | Loads models into RAM at boot (one-shot) |
| phntm-one-selftest | Boot proof, six checks: ledger, brain (a real generate and a real embed), disk, thermal, services, speaker — audio is skipped when voice is off or quiet hours apply. A permitted skip is not proof of speaker hardware; setup uses a chime |
| phntm-one-face (user unit) | The touchscreen face |
| phntm-one-update | Applies a staged update — self-test gated, auto-rollback |
Restart the assistant services: sudo /usr/bin/systemctl restart phntm-one.service phntm-one-loops.service phntm-one-telegram.service. Restart the touchscreen separately from the device user’s session: systemctl --user restart phntm-one-face.
Network posture
Open ports — this is the complete list (ss -tulpn will agree):
- 22 (SSH), 8843 (the phone app, HTTPS only) and 8800 (the device's own screen; from the network it only redirects to 8843 and handles nothing — no password, pairing code or cookie is ever processed on an unencrypted connection) — answering to private LAN ranges only (nftables, policy drop; other new TCP is rejected with a reset rather than dropped, so a phone that tries the unit's global IPv6 first falls back to IPv4 instantly)
- 5353/udp (mDNS — so
<hostname>.localresolves; avahi also holds two random high UDP ports for legacy-unicast replies, dropped from the LAN) - Ollama (11434) and llama.cpp workers — localhost only, run with
--offline; in addition theollamauser is dropped on every non-loopback packet by the firewall, so the inference server has no path to the internet regardless of its own configuration. Its API has no password, so the firewall also lets only the system, the assistant's own account and Ollama itself connect to it — another account's browser or program on the device cannot, and the assistant's own pages are only allowed to send requests and forms to the assistant itself, never to Ollama
Trust model: anything from the LAN arrives over HTTPS on 8843 and needs a paired phone's credential — that includes memories, notes and documents (they are yours, from your paired phone). Control routes (power off, factory reset, restart, account, network changes, the mailbox) are device-screen only and can't be reached from the network at all; a DNS-rebinding guard rejects requests addressed by any hostname but the unit's own. Nothing answers from the internet — no port forwarding, no relay, no cloud endpoint.
At the screen, everyday use needs nothing — but the actions that hand the device to someone else need your device password: Exit to desktop, Terminal and Files, showing the pairing code, linking Telegram, changing where backups go, turning on Boosted or Autonomous, restoring a backup, Take Everything, LibreOffice (its macros can run programs), changing the Telegram bot or connecting a calendar, clearing history, unpairing a phone, forgetting a Wi-Fi network, and a factory reset (which also accepts the one-time recovery code shown when you set up the device — keep it; you can make a new one from Settings with your password). Optional screen lock (Settings → Screen lock…, off unless you turn it on): after the idle time you choose, the screen asks for your password. The certificate the phone app uses is the device's own: its authority is restricted to this device's name, so installing it on your phone trusts this device and nothing else.
Encryption at rest
On a device provisioned for it, everything that holds your data or credentials is encrypted on the drive by
the Linux kernel (ext4 encryption, AES-256): the app's data and settings (memories, conversations, documents, the
search index, logs, API keys), local backups, the screen browser's profile and cache, your own home folder, the
saved Wi-Fi passwords and the system journal. The key lives in the Raspberry Pi's one-time-programmable memory, so
the device still starts by itself after a power cut. What this protects: a drive or card taken out of the device,
thrown away, or copied — it is ciphertext. What it does not protect: a thief who takes the whole
device (another operating system started on the same board can read the key), or anyone who is already root on
the running device. Temporary files live in memory, and swap is memory-only (zram, with Raspberry Pi OS's
copy-to-disk write-back turned off). A unit that ran before it was encrypted may still hold older fragments in the
flash's free blocks: they are trimmed when a store is encrypted, but flash does not guarantee erasure — a full reset
and re-flash is the clean start. Check it yourself: sudo phntm-at-rest status, and the Privacy Proof
reports it.
The two-brain design
- Private (default): everything above. No network required, no account.
- Boosted (optional): your own Anthropic API key, entered on-device, used only when you enable it. Every answer is labeled with which brain produced it. Delete the key to remove it from active settings. The trade is stated in the UI, not buried: on a Boosted answer your question, the memories and document excerpts pulled in as context, your name and language, and the recent turns leave the box. Memory filing, voice, documents and search stay local, and the morning briefing is always local.
- Autonomous (optional): Boosted, plus you can message the device from your own Telegram and ask it to act — check its status, set reminders, search and draft email, send an email, and manage your Google Calendar. You turn it on yourself; enabling it from a phone needs your device password. Every email send and every calendar change is confirmed by you first and is bound to exactly what you approved. Those messages, and the actions you confirm, leave the box: they go to Claude and to the accounts you connected. Turn it off and the device is back to Private/Boosted.
Updates
Shipped units have no update channel — there's no repo remote, no phone-home, nothing polls, and no automatic OS updates (the Debian update timers are off on purpose). Updates are owner-initiated: a documented local procedure applies a release you provide (the supported path checks its signature and every file's hash first), runs the boot self-test, and rolls itself back automatically if the self-test fails. Your unit will not change behavior underneath you.
Shared chat capacity
Overlapping model chats share the local runner and can take longer. Two model requests may be admitted; an additional request receives a busy response. Wait for an answer to finish, then retry. Deterministic answers that do not need a model bypass this limit. Current response measurements are shown on Home; older benchmarks are not a timing promise.
Memory semantics
- An explicit “remember that …” is saved durably before the save confirmation. Semantic indexing follows asynchronously; recall by meaning can be limited while indexing is pending.
- Everything else you say is considered for memory by a background pass that runs once the conversation has been idle for about five minutes (to reduce competition with your next question for the model). It files at most one fact per exchange and says nothing it did not hear from you.
- Library → Memories shows stored facts; delete removes both the record and its index entry.
Open loops (Follow-Through)
Beyond remembering facts, the device keeps track of what you still have open — a task you haven't finished, something you're waiting on, a decision that's blocked. The HOME screen's OPEN LOOPS card shows them, and you can tap any one to mark it done or drop it.
- Where they come from — you. A loop is created only from your own first-person words: “I'm still waiting on the electrician,” “I need to renew the county permit,” “I'm blocked until the survey comes back.” It has to have a clear finish line, or it isn't created. Vague musings (“maybe someday…”), questions, and anything the assistant said are ignored. There is no machine-invented busywork — the device never makes up tasks for you.
- It brings them back when they're relevant. If you later mention something clearly about an open loop, the device may surface one short line — “Last time you were waiting on the electrician — did that come through?” — then get out of the way. It won't repeat the same one, it respects a cooldown, and uses recent interaction as a signal of owner presence; it does not physically detect whether someone is in the room.
- You close them. “That's done,” “mark the permit done,” or the ✓ on the card. If more than one open item could be what you mean, it asks rather than closing the wrong one. “Forget that” / ✕ drops one for good — it won't come back.
- You decide when they are done. Adding a related document leaves the task open. Mark it done explicitly when its completion condition is met.
- It's quiet and local. There is no always-on thinking behind this — detection is simple, deterministic, and runs only as you talk. Loop records are stored locally and are not directly added to the memory index or exposed through a cloud loop-listing tool. Conversation text can contain loop details: those messages may be included in later optional cloud answers, and Telegram carries messages and replies through its service. Private mode with local chat keeps that conversation on the device (paired phone traffic stays on your LAN).
- Reset removes them. Open loops are your data: a factory reset and an ownership transfer erase them along with your memories and conversations.
Factory reset
Settings → Factory reset — wipes memories,
conversations, pairing, settings, API keys; the wizard owns the next boot. Documented in the
on-device README.
Reset deletes the managed app state and its databases and index. Use the full reset when transferring the whole device, including the owner’s computer account. Separately exported files, detached backup media and copies on other devices are not erased by resetting this one. On a device without encryption at rest it is not a forensic secure-erase of the flash — a lab with the raw card could recover fragments from unallocated blocks, as with any SD card. With encryption at rest, the full reset (device and computer) also destroys the encryption's per-install secret: whatever the flash still holds of the ENCRYPTED stores is ciphertext no key opens any more (fragments from before the unit was first encrypted are not covered — see Encryption at rest). Passing an unencrypted unit on and that matters? Re-flash a fresh card from the Golden Master image or destroy the old card.
Known Limitations
Found something not on this list? [email protected]
we'd rather you hear these from us than discover them and wonder what else we didn't say
Speed — the big one
Supported questions about device status, privacy and time can be answered directly from device readings without model inference. Open-ended replies use the selected model and vary with prompt length, retrieval, other work and whether the model must reload. A short local answer can take tens of seconds; a long or cold-model turn can take longer than a minute. Earlier benchmark results are historical measurements, not a current speed guarantee. The Home performance card shows recorded timings where available, and this unit’s burn-in certificate reports measurements taken for that unit. Optional cloud answers require internet access and send context to the configured provider.
Model capability
Gemma 3 4B (Q4_K_M) is genuinely useful — conversation, questions over your own memories, summaries, drafts — but it is a small model. It will occasionally be confidently wrong, shallow on deep technical questions, and it can't compete with frontier models on hard reasoning. We say which brain answered every time so you always know what you're getting.
Memory timing
Only an explicit “remember that …” is written immediately. Other facts are filed by a background pass about five minutes after the conversation goes idle; a power cut inside that window can lose a fact that was never asked for explicitly. Completed conversation turns are stored locally according to the retention setting; interrupted turns may be incomplete.
Real-time clock
The RTC header has no battery fitted. Time comes from your network (NTP); with no internet the restored clock may be old or unverified. Reminders can be mistimed until a time source is reachable, and creating one is refused when the clock has no believable time.
Memory ceiling
8 GB total. The RAM ledger budgets the chat model and embedding model against available memory, reserving headroom for the UI and context. Residency is not permanent; idle models may be released and reloaded on demand. if RAM pressure forces it, the device drops to the 3B fallback model and says so. Big models don't fit — that's the honest reason a beefier SKU is on the roadmap.
Context window
Configured to 8K tokens for RAM headroom (the architecture supports far more; the RAM doesn't). Very long conversations eventually roll context; memory (RAG) is the long-term store, not the context window.
Boot and readiness
The face shows startup state while the device checks readiness. Boot time and model loading depend on storage, memory pressure and the installed build. Older development-unit timing does not establish this unit’s current performance. Check the burn-in certificate for recorded results. Models can be released while idle, so the first answer after a quiet spell may need a reload.
Fan
The Pi fan is thermally governed and can ramp under sustained inference. Temperature depends on enclosure cooling, room temperature and workload. Home shows measured temperature and Device shows available health readings; inspect current throttling state rather than assuming older open-bench temperatures apply to an enclosed unit.
Vision
Library → Documents and PHNTM Drop accept JPEG/PNG photos and scanned PDFs for local OCR. You can ask about recognized text with document citations. OCR can miss handwriting, poor scans or unsupported text. Compare cited excerpts with the original file. There is no full recognized-text preview; a citation or answer is not proof that every page was read correctly. General visual scene understanding and direct image conversation are not provided by this OCR path.
Network features
- Phone chat requires phone and device on the same network (no cloud relay exists — that's a feature, but it means no remote access out of the box).
- If your AP isolates clients ("guest mode" / "AP isolation"), the phone can't reach the device — that's the router blocking LAN traffic; Ethernet + a normal SSID fixes it.
.localhostnames need mDNS; some routers block it — the device's screen always shows its real IP as the fallback.
What "autonomous" means here (and doesn't)
Two separate things share the word. The device always maintains itself (the section below says exactly what that covers), and that self-maintenance never browses the internet on its own and never touches your accounts. Separately, Autonomous mode is an optional brain mode you turn on: there, and only there, the device can act on the accounts you connect (Telegram, email, Google Calendar) — always from a message you sent (or, for the calendar card on the screen, a Refresh you tap), and every send or calendar change is confirmed by you before it happens. It does not run open-ended agent tasks or browse the web on its own.
How it fixes itself
A supervisor checks the device every 90 seconds — services, the model server, memory, disk, temperature, the network, the screen, its own configuration files and the indexes it builds from your memories and conversations (the deeper index and configuration comparisons less often) — and keeps a record of what it saw. When a check confirms a fault, one of a fixed set of repairs may run. There are fifteen repairs aimed at a fault, listed below. Beyond them the device only does housekeeping on its own: trimming its logs and caches when the disk runs low, and cleaning up after its own rehearsals and test workspaces — none of which touches your data. Each repair is limited (for example no more than three restarts of one service in half an hour, and no more than two rollbacks a day on any one thing, with no automatic retry on it for six hours after a rollback), each one is written down with the reason it was chosen, and the seven that touch files or indexes run inside a transaction that is verified and undone if it did not work. The device keeps score of how well each repair has worked on this unit and, where it has a choice, prefers what has worked here; a repair aimed at a symptom is withheld when the evidence says the cause is elsewhere. It also rehearses: once it has first proved its own safe window, on quiet days it introduces a small, disposable fault into something built to be broken and watches the real repair path handle it. What it does not do: it does not change its own code, does not install updates by itself, and does not touch your messages, notes or reminders while repairing anything.
| repair | what it fixes | reversible? | limit |
|---|---|---|---|
| Restart the assistant | the chat service stopped answering | no (a restart) | 3 per 30 min |
| Restart the model server | the local model server stopped answering, or grew past its baseline | no | 3 per 30 min |
| Restart the Telegram bridge | the remote control plane went down | no | 3 per 30 min |
| Re-warm the models | a model dropped out of memory | n/a (a reload) | load capacity |
| Relieve memory pressure | memory critically low for two checks in a row | no | 3 per 30 min |
| Restart the face | the screen stopped painting | no | 3 per 30 min |
| Re-run the boot self-test | the start-up check had not passed | n/a (a check) | 3 per 30 min |
| Rejoin Wi-Fi | the device is off a network it knows | no (changes no credential) | 3 per 30 min |
| Restore a configuration file | a shipped session file drifted from its known copy | yes — verified, undone if wrong | 3 per 6 h, 2 rollbacks/day |
| Regenerate the public-facts file | the non-secret facts file drifted from its generator | yes | 3 per 6 h, 2 rollbacks/day |
| Reconcile the memory index | the search index disagrees with what it remembered, entry by entry | yes | 3 per 6 h, 2 rollbacks/day |
| Rebuild the memory index | the search index is too far gone to reconcile | yes | 1 per day (counts against the 3 per 6 h), 2 rollbacks/day |
| Reconcile the conversation index | the conversation index disagrees with your kept messages | yes | 3 per 6 h, 2 rollbacks/day |
| Rebuild the conversation index | the conversation index is too far gone to reconcile | yes | 1 per day (counts against the 3 per 6 h), 2 rollbacks/day |
| Rebuild replayed history | the device's own derived history diverged from its shipped record | yes | 3 per 6 h, 2 rollbacks/day |
Beyond these, the device observes and reports. It can tell when a fault is the cause and when it is a consequence, or say honestly that it cannot tell; it can propose what evidence would settle a question it cannot answer; and it can build and test a small change, handed to it, in a sealed workspace on the device that cannot reach the running assistant, your data or the network. None of that changes the device: a change reaches it only as an update you install yourself, and the supported release path checks the signature and every file's hash before anything is touched, then rolls back if the self-test fails.
This is a hand-built early unit
This is hand-built early hardware. When available, this unit’s qualification
certificate (on your own device) records its qualification results. Development
results do not replace qualification of the unit in front of you.
Privacy Verification
the central claim, provable with standard tools — no PHNTM cooperation required
1 · See every open port
ss -tulpn
Expected: sshd (22), the app (8843 HTTPS for phones, 8800 for the screen), mDNS (5353/udp), and Ollama/llama.cpp bound to
127.0.0.1 only. Nothing else listens for you. nmap from another machine
should agree: 22, 8800 and 8843, LAN-only; a UDP scan also shows 5353 and the OS's own
time-sync and DHCPv6 client sockets (systemd-timesyncd, NetworkManager).
2 · Watch the wire while you talk to it
tcpdump ships on the unit. Over SSH:
sudo tcpdump -i any -nn 'not (net 192.168.0.0/16 or net 10.0.0.0/8 or net 172.16.0.0/12 or net 127.0.0.0/8 or net 224.0.0.0/4 or net fe80::/10 or net fc00::/7 or net ff00::/8 or host 255.255.255.255)'
Then have a conversation on the touchscreen, create memories, recall them. Expected, on a
unit in Private mode with no cloud or messaging connected: no conversation content sent to an external service by the assistant. This is not a promise of packet silence. If you
have connected Telegram, you will instead see a steady TLS connection to
api.telegram.org — the device polls it to receive your messages, in every mode; and
in Boosted/Autonomous you will see traffic when the cloud brain answers or a confirmed action
runs. The egress ledger records supported app-level sends, not every packet from every process. You may also see traffic
at the OS level (documented, not hidden):
- NTP time synchronization and its DNS lookups; the actual server depends on the installed time-sync configuration
- DHCP renewals from your router
- mDNS multicast on your LAN
None of these carry conversation content, and none go to any PHNTM server — there is no PHNTM server.
3 · The kill test
Unplug your router's WAN (or the router entirely). Then:
- Talk to it on the touchscreen — works
- Create and recall memories — works
- Reboot the whole device with no internet — comes back, still works
- Phone chat still works if the LAN is up (it never used the internet)
4 · Inspect the processes doing the work
ps aux | grep -E 'ollama|llama|uvicorn'
Note --offline on the llama.cpp worker and the 127.0.0.1 bindings;
sudo nft list ruleset shows the rule that drops every non-loopback packet from the
ollama user. The model
files are on disk at /usr/share/ollama/.ollama/models — hash them (the
directory is owned by the ollama service account, so read it with sudo);
they are the standard published weights.
5 · Boosted and Autonomous are the documented exceptions
If you configure your API key and select Boosted or Autonomous mode, cloud-model answers
sends your question, the memories and document excerpts pulled in as context, your name and
language, and the recent turns to your model provider, billed to you, labeled in the UI per-answer. tcpdump during a
Boosted answer shows TLS to your provider. In Autonomous mode, the actions you confirm (and the
calendar reads you ask for from the screen) also reach the accounts you connected — your email provider (SMTP/IMAP) and
www.googleapis.com for your calendar. Separately, if you connect Telegram the device
keeps a continuous connection to api.telegram.org to receive your messages, in every
mode. These integrations are off by default. The on-device egress ledger records supported
application events, including preparation and attempted sends; it is not a complete network history
and does not record every continuous polling request. Switching back to Private stops cloud-model requests. Disconnect other configured integrations separately; operating-system network traffic can continue. Deleting a configured key removes it from active settings; copies outside those settings must be managed separately.
6 · What happens if PHNTM (the company) disappears
Local chat, memory, documents and voice keep working without PHNTM servers. Your local owner account and locally stored data stay on the device; there is no PHNTM cloud account or license-server dependency. Optional third-party integrations still depend on their providers. Future updates or support could become unavailable. This manual is stored on the device.
Licenses & Notices
Built with Llama. Llama 3.2 is licensed under the Llama 3.2 Community License,
Copyright © Meta Platforms, Inc. All Rights Reserved. The fallback chat model on this device
(llama3.2-phntm-one:fallback) is built from Llama 3.2 3B.
Gemma is provided under and subject to the Gemma Terms of Use found at
ai.google.dev/gemma/terms; the primary chat model (phntm-one:chat) is built
from Gemma 3 4B, and use is subject to the Gemma Prohibited Use Policy at
ai.google.dev/gemma/prohibited_use_policy.
The following texts are served by this device (no internet needed):
- NOTICE — a summary of third-party components and terms
- LICENSE — the PHNTM One source license
- Llama 3.2 Community License
- Gemma Terms of Use
- nomic-embed-text (Apache-2.0)
- Piper 1.4.2 engine (GPL-3.0)
- Piper voice dataset attribution
- Gemma Prohibited Use Policy
- Sherpa-ONNX (Apache-2.0)
Piper TTS 1.4.2 is GPL-3.0-or-later; whisper.cpp is MIT-licensed; Firefox ESR is MPL-2.0; Debian packages carry
their own terms in /usr/share/doc/*/copyright on the device.
AI Cam · USB camera preview
Attach a USB webcam to PHNTM One, open AI Cam on its touchscreen and tap Connect camera. The face shows a small live preview from the connected webcam. Disconnect releases the camera; leaving AI Cam, resting or locking the face also turns it off. Reconnect explicitly to resume.
This first version is preview only. It does not record audio, save photos, send camera images to the assistant or detect whether you are at your desk. A missing, unplugged or busy camera is reported on screen. Camera compatibility depends on browser and Linux support.