Exact selection or paragraph window
TECHNICAL PROOF
Read the claim.
Then inspect the build.
The strongest privacy claim is not a sentence on this site. It is the missing Android permission in the release package, combined with a local runtime and a model that never needs a network path.
PROOF 02 / REQUEST PATH
Every rewrite stays inside the app process.
The keyboard captures your exact selection or a bounded paragraph window, asks the local model, validates the response, renders a diff, and waits for a human action.
URLs, numbers, email, negation checks
llama.cpp CPU runtime + verified GGUF
Reject unsafe or malformed changes
Insertions and deletions, no silent replace
Keep original or Accept edit
PROOF 03 / CURRENT EVIDENCE
A versioned model, package, and measurement.
The app UI, installed model, and next model are tracked separately. Metrics remain attached to the exact package and device that produced them.
PROOF 04 / QUALITY BOUNDARIES
The diff exists because small models drift.
The installed v3 model passed six of eight hard release gates and shipped under a documented exception. So every edit shows its work and waits for you—that is not a disclaimer, it is the interface.
Checks around the model
- URLs and protected spans are checked.
- Number and negation changes are validated.
- Invalid output keeps the original.
- The user accepts every edit.
- Undo is armed immediately after acceptance.
Limits still under review
- Meaning corruption missed the installed model's gate.
- Spanish identity behavior also missed its release gate.
- Mixed-language Professional rewriting is a known weak area.
- Short ambiguous sentences are difficult for a 350M model.
- Battery-per-rewrite and sustained thermal tests remain open.
- The replacement model is still in evaluation.
KEEP THE CLOUD OUT OF THE CONVERSATION
Your keyboard sees enough.
It doesn't need a network.
Write, revise, and decide on your phone.