← Back to PHNTM One
PHNTMOne · manual

The owner manual. All the details.

This is the public snapshot of the accepted October 7, 2026 device manual (build 4f1c5de). Your own device serves its installed manual locally, including without internet. Device-only addresses and commands below refer to your appliance, not this website. Optional cloud and connected-account features require internet access. This manual contains: the quick start (the printed card is its short form), the technical notes, the honest limitations, how to verify the privacy claims yourself, and the licenses — plus this unit's own burn-in certificate at /docs/certificate (on your own device).

Quick Start

owner edition · the printed 5×7 card in the box is the short form of this page

In the box

Getting started

  1. Plug it in. That's the whole install.
  2. The screen shows startup progress while the assistant runs its boot self-test. Readiness and model warm-up take time; check the screen before starting a conversation.
  3. First boot opens setup on the touchscreen. Follow the steps for: language · network (Ethernet = zero config; Wi-Fi optional) · time zone · a name for the assistant · the username and password that become this device's login · your phone (optional) · the brain choice (Private, Boosted or Autonomous) · voice on/off. No cloud account, no app store, no computer needed.
  4. Pair your phone: tap Settings → Show pairing code (the device asks for your password), scan the QR with your phone camera, and a private chat opens in your browser — served from the device over your network, encrypted (HTTPS). No cloud relay in between. The first time, your browser says the connection is not verified: continue only if the certificate fingerprint it shows matches the one on the device screen. Want it verified every time? Install the device's own certificate on the phone (the pairing screen shows how); it is limited to this one device's name and trusts nothing else.

Things worth knowing up front

The nav — left edge of the screen

Homeconversation and voice, tasks, measured system and network readings, connected Linux computers and project activity; Layout chooses the widgets
Chatthe conversation
Tasksreminders — it speaks up on time; presets, pause, skip
Notessaved originals, dictation and reviewed drafts
LibraryMemories (yours to read and delete) · Documents (the vault — PDFs and photos in, cited answers out) · Open loops
Devicehealth, gauges and the live count of external connections · Activity · Journal · Connect · Care

The orb and the health line sit above every view; tap Settings (top right) for the full menu.

Reminders are stored on this device separately from their Telegram alerts. The Reminders view shows remote alerts as pending, sent, failed or unknown. Unknown means delivery was not confirmed. Retry asks you to accept that a previous attempt may already have arrived and a duplicate can be sent.

If something looks wrong

PHNTM · www.phntmcore.com · [email protected]

What it does

These system instruments run on this device. Routine proactive speech follows your voice setting and quiet hours; urgent temperature or storage warnings may bypass quiet hours. Successful automatic repair and network-restoration notices stay quiet with the default Important updates setting.

Useful spoken updates

Proactive updates come from recorded events, such as a persistent warning, a completed backup or an update result. With All updates selected, a recovery can be spoken after a meaningful fault you were told about. These queued updates wait while you are talking, listening or hearing a reply; expired or resolved warnings are discarded. Silent voice or Never updates suppress queued proactive speech. This event-driven lane does not create an announcement just because time passed.

Spoken Ambient updates are separate from the visual Ambient face above. This optional setting allows occasional spoken facts about this device. It requires Voice Speaks and Updates: All, respects quiet hours and yields while you are using the assistant. The device chooses among currently supported health, privacy, memory and backup readings and stays quiet when it cannot support a line. Turning it on does not promise speech at a particular time.

Ask about this device

Ask “What operating system are you running?” for this device's operating system, kernel and PHNTM One version. Chat also receives measured CPU, temperature, memory, storage and health readings when available. Vitals and health retain their original sample ages; old or missing readings are reported as unavailable, and an unverified wall clock is identified.

Computer Black Box

When you connect a supported Linux computer, you can separately grant Black Box recording. PHNTM One then keeps a bounded history of numeric CPU, memory, storage, aggregate network-byte and uptime readings, plus temperature and GPU readings where Linux exposes them. Samples recorded during the current PHNTM boot age out after 24 hours; samples from earlier PHNTM boots remain subject to the 6,000-sample and storage caps. The timeline holds at most 100 recent bookmarks and observations. Five-minute summaries, sustained threshold observations, owner-written incident bookmarks and a JSON evidence export help you inspect what was happening around a slowdown. Measurements are companion-reported, not independently verified; a threshold is an observation, never a diagnosis. Missing readings stay unavailable. The computer clock is labeled unverified and never used to order events across devices. The history is stored on this PHNTM One, not sent to PHNTM or a cloud service. Process names are off by default; a separate permission can retain up to five same-user process names and CPU/memory readings, without PIDs, arguments, paths or window titles. File contents, screen contents, clipboard, audio and network payloads are not collected. Removing a permission stops new readings of that kind after the companion receives the change; retained readings remain subject to the retention bounds or can be erased by you. Revoking a computer stops future collection but preserves retained history subject to those bounds. Black Box history is not included in the regular device backup; export it separately if you want to keep a copy.

Resting Face

Ambient mode is enabled by default when no layout preference has been saved. After three minutes without interaction, the face shows a dim system pulse, time and date, measured CPU usage and temperature, and a labeled activity color. Each pulse acknowledges a new system sample (normally every five seconds); it is not a CPU cycle or proof that every service is healthy. Mint means ready, teal listening, blue speaking, violet processing or approved work, amber waiting or degraded health, and grey unavailable readings. Missing instrument values show a dash. Stale system samples stop the pulse. The clock is labeled unverified until status confirms time synchronization. After twelve minutes it dims further; the resting layer shifts slowly to vary pixel placement. Touch or press a key to wake. Critical health conditions wake the full interface. Layout can turn ambient mode off; an existing saved choice is respected. This is a dimmed UI, not a panel power-off or a guarantee against image retention.

Local Mode (Own the Unplug)

If the internet goes away, the screen says so plainly and keeps working — chat, memory, reminders, notes and voice all run here, with or without a connection. Restoration is recorded quietly by default; All updates can speak a meaningful recovery after an earlier spoken warning.

Watch the Wire

In Settings → Data & Privacy, tap Watch the Wire for a 60-second observation. Talk to the device and watch two separate meters counted from the device’s own instruments: your conversation (the assistant’s own network connections and any logged sends — expected to be zero for local chat when external integrations are disconnected) and the whole machine (sampled internet byte totals, including OS and desktop-app traffic). These samples do not reveal packet contents and can miss short connections. The byte display can lag during the run; Start and Stop request fresh readings. Unreadable sources, a reboot or a detected counter reset make the observation incomplete. Process permissions can prevent socket attribution even when the device is operating normally.

Backups

The device backs itself up every night to ~/phntm-one-backups (or a USB backup destination you configure). Every archive is encrypted before it is written: on this device it opens by itself for a restore; on another device it needs your device password or your recovery code — a lost stick is unreadable without them. Until you have signed in (or used your password on the screen) once after the update that added this, archives can be opened on this device only; older unencrypted archives are kept until then, and replaced by encrypted ones after. An archive opens elsewhere with the password or recovery code that was current when it was made: after you change your password or make a new recovery code, new archives carry the new one (and never the old one) once you have used it on the device, and the backup list shows which archives today's password or code opens. After an update, backups open elsewhere again once you have used your password once (a recovery code: once you have used it or made a new one); until then "Back up now" says the backup opens on this device only.

Take Everything

In Settings → Data & Privacy, tap Export My Data to write a portable copy of your data to a USB stick: your memories, reminders (as a calendar file), open loops, the documents you gave the device, and your preferences — with a manifest and checksums. The reminder calendar file contains active events; reminders.json preserves recorded delivery/completion timestamps and pause state. Importing the calendar file does not promise an alarm or recreate PHNTM One reminder execution. Your device’s secrets (keys, pairing, passwords) never go on the stick. The copy is only marked complete once every file is written and verified; a stick pulled early is never mistaken for a finished one.

Your conversation history

Completed conversation turns are stored here, indefinitely by default, and are searchable locally — ask “when did I talk about the noisy fan?” to search for related retained messages. Retrieval can miss a match or return an imperfect one; interrupted turns may be incomplete. Your history stays here until you decide otherwise: choose a shorter retention window, or clear it, under Data & Privacy, and it’s included when you Take Everything. The search runs on the device; your conversations are never sent anywhere to index them.

Send files here (PHNTM Drop)

Send files to your PHNTM One from any computer or phone on your home network. On the PHNTM One screen, open Data & Privacy › PHNTM Drop to see the exact web address — it looks like https://phntm-one-<serial>.local:8843/drop — and a QR you can scan. Open that address in a browser on your network and drag files onto the page (PDF, text, Markdown, JPEG and PNG). They cross your own network to the device, are read and indexed here. Photos and scanned pages use local text recognition (OCR), which can misread or miss text; this is not general image understanding. In Private mode, document questions are answered locally. Optional cloud answers can include retrieved document excerpts. Answers can include file/page references when the source-use check finds support in retrieved passages; a citation does not guarantee the answer is correct. Delete files in Library → Documents; Take Everything exports it all.

Memory Constellation

In Memory, switch to Constellation to see what the device remembers as a map. Every dot is a real memory; a line between two dots means they share a keyword — nothing is invented to make the picture prettier. Tap a memory to read it or forget it; forgetting removes it here and from the searchable copy. Open loops are kept separate — they are not durable memories.

Command center

The home screen brings together conversation, due work, system instruments, network readings and selected computer projects. Open a card for details. Layout lets you choose the home widgets and ambient mode; your choices are saved on this device. The activity indicator labels observable stages such as listening, processing, speaking and approved computer work. If its readings stop arriving, it shows disconnected or stale state instead of continuing to imply activity.

CPU is measured from processor-counter changes; network traffic is measured from interface-counter changes. A link rate is the connection’s negotiated capacity, not an internet speed test. Network neighbors are a partial passive view, not every device on your network. Missing readings say unavailable. Performance separates recorded transcription, response and speech synthesis durations where observed; synthesis excludes playback. Response percentiles cover measured model-route requests and include routing and retrieval. Old or missing health and model readings are identified rather than filled with estimates.

Connect Computer — Linux

Open Workspace → Connect computer. The setup address and instructions appear before you create a code. Open that HTTPS address on the Linux computer you want to connect. For a first connection, the touchscreen shows separate SHA-256 fingerprints for the website certificate and appliance CA. If your browser warns about the website certificate, inspect its SHA-256 fingerprint before trusting it and compare it with the website fingerprint on PHNTM One. Continue only when the full fingerprint matches, using trust limited to that certificate and website. If the browser cannot show it or it differs, stop and use a trusted local CA transfer instead. After verifying the website, download its public CA and compare the CA fingerprint separately. An unauthenticated download alone does not authenticate the installer; never disable certificate verification globally. Download the personalized ZIP, extract it, open a terminal in its phntm-computer folder and run sh install.sh. Setup uses desktop dialogs when Tk and a desktop display are available, with terminal prompts otherwise. It shows this appliance’s address and fingerprint for confirmation and asks for a code privately. Create the single-use, five-minute code on PHNTM One when the installer is ready. After successful pairing, setup starts the user service and checks for an authenticated heartbeat. A pairing alone does not mean the computer is connected. If startup cannot be confirmed, setup reports that and retains the pairing. The included README explains requirements, recovery and selecting repositories, folders and named workflows.

The companion runs as your computer user, opens no listening port and defaults to read-only telemetry. Content access and workflow execution require separate permission on both computer and appliance. Workflows execute the approved program and arguments as your user; approve only code you trust. There is no unrestricted remote-shell request or automatic screen/clipboard capture. Windows, macOS and computer inference routing are not supported.

Stop the connection with systemctl --user stop phntm-computer. Revoke it on PHNTM One to invalidate its token. Revocation blocks further communication, but already launched work can finish locally; stop that work on the computer if needed. Disconnects retain the last observed readings and durable receipts, marked with their availability. Work is not automatically repeated after restart or disconnect; an unknown outcome stays unknown. Appliance request deduplication covers retained receipts, so do not retry an old request after its receipt has been evicted. The companion also bounds receipt history by encoded bytes: acknowledged history may expire early to reserve final evidence before execution; insufficient space refuses work. Oversized optional evidence is explicitly marked truncated without changing the recorded process outcome. Stop the companion before pairing or unpairing. Each pairing has its own durable receipt queue; re-pairing never submits older or unbound legacy receipts under new credentials. The companion’s unpair command removes local credentials and retains receipt evidence as inactive local archives. Archives are bounded to 32 queues of at most 2 MB each, plus a legacy file of at most 4 MB; pairing refuses at capacity rather than deleting evidence. The status command identifies the current queue for safe export of older archives; sh uninstall.sh removes the program and service while retaining local configuration for inspection.

Project Resume and outcome receipts

Inspect a selected repository to see its reported branch, tracked-file dirty state, recent commits, contribution counts and project note. The heatmap covers all authors in the observed Git history, not just your contributions. Project Resume combines that context with available job receipts and your approved note. The timeline shows commits and requested jobs as separate evidence streams; it does not infer that a nearby commit caused a test result or deployment. Computer-reported results remain identified as such. Repository-associated receipts can show what an approved workflow observed, but complete request-to-commit-to-deployment linkage is not implemented.

Closing Veil

On the device screen, Device → Care → Reset & power has a Power Off control. Confirm it, then wait until the screen is dark before disconnecting power. The control sends a shutdown request; its response does not prove shutdown has finished. It is unavailable from a paired phone.

When the device restarts, resets or installs an update, it covers the technical shutdown with its own screen and a plain message (“Restarting…”, “Installing an update — keep me connected to power.”). The message identifies the requested operation. If a handled error occurs, the interface reports it; a power loss, failed service or dark physical panel can prevent the UI from showing the result. Check status after recovery.

Technical Notes

Support: [email protected] — the builder answers. Include the serial from the back of the business card and, if it helps, the diagnostics bundle from the phone app (it contains no conversations, memories or credentials).

everything here is inspectable over SSH — poke at all of it

Burn-in certificate

This unit's own measurements — every boot it has logged, first-try pass rate, benchmark numbers — are rendered at packing time and served by the device at /docs/certificate (on your own device). Nothing estimated; a value that was never measured prints as a dash.

Notes and ideas

Open Notes in the left rail. Type or record a thought, review the recognized text, then choose Clean up, Develop idea, or Project checkpoint. AI processing stays on this device in every mode. Your original is saved before generation; drafts remain separate. Review suggestions before choosing Keep draft. AI can make mistakes and suggestions are not verified facts. Notes never execute a plan or automatically become memories.

Project checkpoint groups your original statements under section labels chosen by the model, preserving their wording and order. It does not invent progress or next actions. At the text limit, statements take priority over headings.

Develop idea separates unverified AI suggestions from a verbatim copy of your original note. Suggested steps and possible tradeoffs still need your review. Originals are limited to 6,000 characters; saved AI drafts can include up to 12,000 characters so the original and suggestions fit together.

Notes generation uses the primary local model. If it cannot run, your original stays saved and you can retry; Notes does not switch to the smaller chat fallback. Long notes and cold model loads can take several minutes.

Each recorded clip is limited to 60 seconds. Once speech begins, thinking pauses do not end a Notes clip; a clip with no initial speech ends after 10 seconds. Use Stop & transcribe or Discard clip. Add another clip after transcription. Raw audio is temporary; saved text and revision history are included in data exports and database backups. Deleting a note does not remove earlier exports or backups.

Hello Phantom

In Settings → Wake phrase, explicitly enable local phrase detection. Say Hello Phantom, wait for the Listening indicator, then ask a general question. This is a two-step interaction. Detection pauses during the device's speech, manual recording, setup and maintenance. The detector is English-only. Similar-sounding speech can trigger it, and noise or distance can cause missed detections. A detected phrase does not identify who spoke.

Hands-free answers use a temporary local conversation, without your personal memories, documents, notes or action tools. Ambient audio is neither saved nor sent online. Turning wake detection off stops its capture; manual Talk and Notes remain available. This setting is software control, not a physical microphone disconnect. A fault is shown as unavailable, rather than Ready. Use Test phrase for detection-only feedback.

Hardware

ComputeRaspberry Pi 5, 8 GB RAM, quad-core Cortex-A76
Display10.1″ 1920×1200 IPS, 5-point touch (HDMI panel)
AudioBuilt-in speaker (the assistant talks)
MicrophoneUSB microphone (included) — manual recording plus optional local “Hello Phantom” detection (off by default)
KeyboardMini wireless keyboard with thumb touchpad (included; Alt+M = talk shortcut; Tab moves focus)
Power27 W USB-C PD supply, included
CoolingActive fan, thermally governed by the Pi 5 firmware trip points — quiet at idle, ramps under load
Storage256 GB microSD; the filesystem expands to the full card on first boot (NVMe is an upgrade path, not the shipped configuration)
NetworkGigabit Ethernet + Wi-Fi (2.4/5 GHz)
Battery / RTCNo device battery, UPS, or RTC coin cell is installed. Time comes from NTP; after an offline cold power loss, wall-clock time may be unknown until network time returns.

Software stack

OSDebian 13 (trixie), stock kernel, systemd
InferenceOllama / llama.cpp, bound to 127.0.0.1 only, run with --offline
Chat modelphntm-one:chat — Gemma 3 4.3B, Q4_K_M, 8K context configured
Fallback modelllama3.2-phntm-one:fallback — Llama 3.2 3B, Q4_K_M (RAM-pressure fallback, chosen by a boot-time RAM ledger)
Embeddingsnomic-embed-text (local memory/RAG recall)
Speech-to-textwhisper.cpp (base.en q5_1), on-device, runs per-utterance and exits; the separate optional wake detector captures continuously when enabled (off by default)
Voice outPiper TTS (en_GB-northern_english_male-medium), on-device
AppPython/FastAPI (uvicorn) on port 8800
FaceFirefox ESR (kiosk window, user unit phntm-one-face) in a minimal desktop session showing http://127.0.0.1:8800/screen — Settings → Exit to desktop; double-tap PHNTM One to come back
AppsSettings → Apps (or the Apps tile on the desktop): Files, Text Editor, LibreOffice, Browser and Terminal open in their own window, as your own account, in front of the assistant. The desktop panel also carries a small network item: which link is up (Ethernet, Wi-Fi, both) and how far it goes — green only when the internet was confirmed by traffic this device already makes (the clock sync), pale when there is a way out nobody has verified, amber for local-only or a sign-in page, grey when offline. A sample document to try the vault on ships in Documents/Try PHNTM-One.

Where things live

Services

unitrole
phntm-oneAssistant API — brain, memory, RAG, web UI (port 8800)
phntm-one-loopsHealth monitor and the caretaker: the self-maintenance below, plus briefings
phntm-one-warmLoads models into RAM at boot (one-shot)
phntm-one-selftestBoot proof, six checks: ledger, brain (a real generate and a real embed), disk, thermal, services, speaker — audio is skipped when voice is off or quiet hours apply. A permitted skip is not proof of speaker hardware; setup uses a chime
phntm-one-face (user unit)The touchscreen face
phntm-one-updateApplies a staged update — self-test gated, auto-rollback

Restart the assistant services: sudo /usr/bin/systemctl restart phntm-one.service phntm-one-loops.service phntm-one-telegram.service. Restart the touchscreen separately from the device user’s session: systemctl --user restart phntm-one-face.

Network posture

Open ports — this is the complete list (ss -tulpn will agree):

Trust model: anything from the LAN arrives over HTTPS on 8843 and needs a paired phone's credential — that includes memories, notes and documents (they are yours, from your paired phone). Control routes (power off, factory reset, restart, account, network changes, the mailbox) are device-screen only and can't be reached from the network at all; a DNS-rebinding guard rejects requests addressed by any hostname but the unit's own. Nothing answers from the internet — no port forwarding, no relay, no cloud endpoint.

At the screen, everyday use needs nothing — but the actions that hand the device to someone else need your device password: Exit to desktop, Terminal and Files, showing the pairing code, linking Telegram, changing where backups go, turning on Boosted or Autonomous, restoring a backup, Take Everything, LibreOffice (its macros can run programs), changing the Telegram bot or connecting a calendar, clearing history, unpairing a phone, forgetting a Wi-Fi network, and a factory reset (which also accepts the one-time recovery code shown when you set up the device — keep it; you can make a new one from Settings with your password). Optional screen lock (Settings → Screen lock…, off unless you turn it on): after the idle time you choose, the screen asks for your password. The certificate the phone app uses is the device's own: its authority is restricted to this device's name, so installing it on your phone trusts this device and nothing else.

Encryption at rest

On a device provisioned for it, everything that holds your data or credentials is encrypted on the drive by the Linux kernel (ext4 encryption, AES-256): the app's data and settings (memories, conversations, documents, the search index, logs, API keys), local backups, the screen browser's profile and cache, your own home folder, the saved Wi-Fi passwords and the system journal. The key lives in the Raspberry Pi's one-time-programmable memory, so the device still starts by itself after a power cut. What this protects: a drive or card taken out of the device, thrown away, or copied — it is ciphertext. What it does not protect: a thief who takes the whole device (another operating system started on the same board can read the key), or anyone who is already root on the running device. Temporary files live in memory, and swap is memory-only (zram, with Raspberry Pi OS's copy-to-disk write-back turned off). A unit that ran before it was encrypted may still hold older fragments in the flash's free blocks: they are trimmed when a store is encrypted, but flash does not guarantee erasure — a full reset and re-flash is the clean start. Check it yourself: sudo phntm-at-rest status, and the Privacy Proof reports it.

The two-brain design

Updates

Shipped units have no update channel — there's no repo remote, no phone-home, nothing polls, and no automatic OS updates (the Debian update timers are off on purpose). Updates are owner-initiated: a documented local procedure applies a release you provide (the supported path checks its signature and every file's hash first), runs the boot self-test, and rolls itself back automatically if the self-test fails. Your unit will not change behavior underneath you.

Shared chat capacity

Overlapping model chats share the local runner and can take longer. Two model requests may be admitted; an additional request receives a busy response. Wait for an answer to finish, then retry. Deterministic answers that do not need a model bypass this limit. Current response measurements are shown on Home; older benchmarks are not a timing promise.

Memory semantics

Open loops (Follow-Through)

Beyond remembering facts, the device keeps track of what you still have open — a task you haven't finished, something you're waiting on, a decision that's blocked. The HOME screen's OPEN LOOPS card shows them, and you can tap any one to mark it done or drop it.

Factory reset

Settings → Factory reset — wipes memories, conversations, pairing, settings, API keys; the wizard owns the next boot. Documented in the on-device README.

Reset deletes the managed app state and its databases and index. Use the full reset when transferring the whole device, including the owner’s computer account. Separately exported files, detached backup media and copies on other devices are not erased by resetting this one. On a device without encryption at rest it is not a forensic secure-erase of the flash — a lab with the raw card could recover fragments from unallocated blocks, as with any SD card. With encryption at rest, the full reset (device and computer) also destroys the encryption's per-install secret: whatever the flash still holds of the ENCRYPTED stores is ciphertext no key opens any more (fragments from before the unit was first encrypted are not covered — see Encryption at rest). Passing an unencrypted unit on and that matters? Re-flash a fresh card from the Golden Master image or destroy the old card.

Known Limitations

Found something not on this list? [email protected]

we'd rather you hear these from us than discover them and wonder what else we didn't say

Speed — the big one

Supported questions about device status, privacy and time can be answered directly from device readings without model inference. Open-ended replies use the selected model and vary with prompt length, retrieval, other work and whether the model must reload. A short local answer can take tens of seconds; a long or cold-model turn can take longer than a minute. Earlier benchmark results are historical measurements, not a current speed guarantee. The Home performance card shows recorded timings where available, and this unit’s burn-in certificate reports measurements taken for that unit. Optional cloud answers require internet access and send context to the configured provider.

Model capability

Gemma 3 4B (Q4_K_M) is genuinely useful — conversation, questions over your own memories, summaries, drafts — but it is a small model. It will occasionally be confidently wrong, shallow on deep technical questions, and it can't compete with frontier models on hard reasoning. We say which brain answered every time so you always know what you're getting.

Memory timing

Only an explicit “remember that …” is written immediately. Other facts are filed by a background pass about five minutes after the conversation goes idle; a power cut inside that window can lose a fact that was never asked for explicitly. Completed conversation turns are stored locally according to the retention setting; interrupted turns may be incomplete.

Real-time clock

The RTC header has no battery fitted. Time comes from your network (NTP); with no internet the restored clock may be old or unverified. Reminders can be mistimed until a time source is reachable, and creating one is refused when the clock has no believable time.

Memory ceiling

8 GB total. The RAM ledger budgets the chat model and embedding model against available memory, reserving headroom for the UI and context. Residency is not permanent; idle models may be released and reloaded on demand. if RAM pressure forces it, the device drops to the 3B fallback model and says so. Big models don't fit — that's the honest reason a beefier SKU is on the roadmap.

Context window

Configured to 8K tokens for RAM headroom (the architecture supports far more; the RAM doesn't). Very long conversations eventually roll context; memory (RAG) is the long-term store, not the context window.

Boot and readiness

The face shows startup state while the device checks readiness. Boot time and model loading depend on storage, memory pressure and the installed build. Older development-unit timing does not establish this unit’s current performance. Check the burn-in certificate for recorded results. Models can be released while idle, so the first answer after a quiet spell may need a reload.

Fan

The Pi fan is thermally governed and can ramp under sustained inference. Temperature depends on enclosure cooling, room temperature and workload. Home shows measured temperature and Device shows available health readings; inspect current throttling state rather than assuming older open-bench temperatures apply to an enclosed unit.

Vision

Library → Documents and PHNTM Drop accept JPEG/PNG photos and scanned PDFs for local OCR. You can ask about recognized text with document citations. OCR can miss handwriting, poor scans or unsupported text. Compare cited excerpts with the original file. There is no full recognized-text preview; a citation or answer is not proof that every page was read correctly. General visual scene understanding and direct image conversation are not provided by this OCR path.

Network features

What "autonomous" means here (and doesn't)

Two separate things share the word. The device always maintains itself (the section below says exactly what that covers), and that self-maintenance never browses the internet on its own and never touches your accounts. Separately, Autonomous mode is an optional brain mode you turn on: there, and only there, the device can act on the accounts you connect (Telegram, email, Google Calendar) — always from a message you sent (or, for the calendar card on the screen, a Refresh you tap), and every send or calendar change is confirmed by you before it happens. It does not run open-ended agent tasks or browse the web on its own.

How it fixes itself

A supervisor checks the device every 90 seconds — services, the model server, memory, disk, temperature, the network, the screen, its own configuration files and the indexes it builds from your memories and conversations (the deeper index and configuration comparisons less often) — and keeps a record of what it saw. When a check confirms a fault, one of a fixed set of repairs may run. There are fifteen repairs aimed at a fault, listed below. Beyond them the device only does housekeeping on its own: trimming its logs and caches when the disk runs low, and cleaning up after its own rehearsals and test workspaces — none of which touches your data. Each repair is limited (for example no more than three restarts of one service in half an hour, and no more than two rollbacks a day on any one thing, with no automatic retry on it for six hours after a rollback), each one is written down with the reason it was chosen, and the seven that touch files or indexes run inside a transaction that is verified and undone if it did not work. The device keeps score of how well each repair has worked on this unit and, where it has a choice, prefers what has worked here; a repair aimed at a symptom is withheld when the evidence says the cause is elsewhere. It also rehearses: once it has first proved its own safe window, on quiet days it introduces a small, disposable fault into something built to be broken and watches the real repair path handle it. What it does not do: it does not change its own code, does not install updates by itself, and does not touch your messages, notes or reminders while repairing anything.

repairwhat it fixesreversible?limit
Restart the assistantthe chat service stopped answeringno (a restart)3 per 30 min
Restart the model serverthe local model server stopped answering, or grew past its baselineno3 per 30 min
Restart the Telegram bridgethe remote control plane went downno3 per 30 min
Re-warm the modelsa model dropped out of memoryn/a (a reload)load capacity
Relieve memory pressurememory critically low for two checks in a rowno3 per 30 min
Restart the facethe screen stopped paintingno3 per 30 min
Re-run the boot self-testthe start-up check had not passedn/a (a check)3 per 30 min
Rejoin Wi-Fithe device is off a network it knowsno (changes no credential)3 per 30 min
Restore a configuration filea shipped session file drifted from its known copyyes — verified, undone if wrong3 per 6 h, 2 rollbacks/day
Regenerate the public-facts filethe non-secret facts file drifted from its generatoryes3 per 6 h, 2 rollbacks/day
Reconcile the memory indexthe search index disagrees with what it remembered, entry by entryyes3 per 6 h, 2 rollbacks/day
Rebuild the memory indexthe search index is too far gone to reconcileyes1 per day (counts against the 3 per 6 h), 2 rollbacks/day
Reconcile the conversation indexthe conversation index disagrees with your kept messagesyes3 per 6 h, 2 rollbacks/day
Rebuild the conversation indexthe conversation index is too far gone to reconcileyes1 per day (counts against the 3 per 6 h), 2 rollbacks/day
Rebuild replayed historythe device's own derived history diverged from its shipped recordyes3 per 6 h, 2 rollbacks/day

Beyond these, the device observes and reports. It can tell when a fault is the cause and when it is a consequence, or say honestly that it cannot tell; it can propose what evidence would settle a question it cannot answer; and it can build and test a small change, handed to it, in a sealed workspace on the device that cannot reach the running assistant, your data or the network. None of that changes the device: a change reaches it only as an update you install yourself, and the supported release path checks the signature and every file's hash before anything is touched, then rolls back if the self-test fails.

This is a hand-built early unit

This is hand-built early hardware. When available, this unit’s qualification certificate (on your own device) records its qualification results. Development results do not replace qualification of the unit in front of you.

Privacy Verification

the central claim, provable with standard tools — no PHNTM cooperation required

1 · See every open port

ss -tulpn

Expected: sshd (22), the app (8843 HTTPS for phones, 8800 for the screen), mDNS (5353/udp), and Ollama/llama.cpp bound to 127.0.0.1 only. Nothing else listens for you. nmap from another machine should agree: 22, 8800 and 8843, LAN-only; a UDP scan also shows 5353 and the OS's own time-sync and DHCPv6 client sockets (systemd-timesyncd, NetworkManager).

2 · Watch the wire while you talk to it

tcpdump ships on the unit. Over SSH:

sudo tcpdump -i any -nn 'not (net 192.168.0.0/16 or net 10.0.0.0/8 or net 172.16.0.0/12 or net 127.0.0.0/8 or net 224.0.0.0/4 or net fe80::/10 or net fc00::/7 or net ff00::/8 or host 255.255.255.255)'

Then have a conversation on the touchscreen, create memories, recall them. Expected, on a unit in Private mode with no cloud or messaging connected: no conversation content sent to an external service by the assistant. This is not a promise of packet silence. If you have connected Telegram, you will instead see a steady TLS connection to api.telegram.org — the device polls it to receive your messages, in every mode; and in Boosted/Autonomous you will see traffic when the cloud brain answers or a confirmed action runs. The egress ledger records supported app-level sends, not every packet from every process. You may also see traffic at the OS level (documented, not hidden):

None of these carry conversation content, and none go to any PHNTM server — there is no PHNTM server.

3 · The kill test

Unplug your router's WAN (or the router entirely). Then:

4 · Inspect the processes doing the work

ps aux | grep -E 'ollama|llama|uvicorn'

Note --offline on the llama.cpp worker and the 127.0.0.1 bindings; sudo nft list ruleset shows the rule that drops every non-loopback packet from the ollama user. The model files are on disk at /usr/share/ollama/.ollama/models — hash them (the directory is owned by the ollama service account, so read it with sudo); they are the standard published weights.

5 · Boosted and Autonomous are the documented exceptions

If you configure your API key and select Boosted or Autonomous mode, cloud-model answers sends your question, the memories and document excerpts pulled in as context, your name and language, and the recent turns to your model provider, billed to you, labeled in the UI per-answer. tcpdump during a Boosted answer shows TLS to your provider. In Autonomous mode, the actions you confirm (and the calendar reads you ask for from the screen) also reach the accounts you connected — your email provider (SMTP/IMAP) and www.googleapis.com for your calendar. Separately, if you connect Telegram the device keeps a continuous connection to api.telegram.org to receive your messages, in every mode. These integrations are off by default. The on-device egress ledger records supported application events, including preparation and attempted sends; it is not a complete network history and does not record every continuous polling request. Switching back to Private stops cloud-model requests. Disconnect other configured integrations separately; operating-system network traffic can continue. Deleting a configured key removes it from active settings; copies outside those settings must be managed separately.

6 · What happens if PHNTM (the company) disappears

Local chat, memory, documents and voice keep working without PHNTM servers. Your local owner account and locally stored data stay on the device; there is no PHNTM cloud account or license-server dependency. Optional third-party integrations still depend on their providers. Future updates or support could become unavailable. This manual is stored on the device.

Licenses & Notices

Built with Llama. Llama 3.2 is licensed under the Llama 3.2 Community License, Copyright © Meta Platforms, Inc. All Rights Reserved. The fallback chat model on this device (llama3.2-phntm-one:fallback) is built from Llama 3.2 3B.

Gemma is provided under and subject to the Gemma Terms of Use found at ai.google.dev/gemma/terms; the primary chat model (phntm-one:chat) is built from Gemma 3 4B, and use is subject to the Gemma Prohibited Use Policy at ai.google.dev/gemma/prohibited_use_policy.

The following texts are served by this device (no internet needed):

Piper TTS 1.4.2 is GPL-3.0-or-later; whisper.cpp is MIT-licensed; Firefox ESR is MPL-2.0; Debian packages carry their own terms in /usr/share/doc/*/copyright on the device.

AI Cam · USB camera preview

Attach a USB webcam to PHNTM One, open AI Cam on its touchscreen and tap Connect camera. The face shows a small live preview from the connected webcam. Disconnect releases the camera; leaving AI Cam, resting or locking the face also turns it off. Reconnect explicitly to resume.

This first version is preview only. It does not record audio, save photos, send camera images to the assistant or detect whether you are at your desk. A missing, unplugged or busy camera is reported on screen. Camera compatibility depends on browser and Linux support.