Mango

dev.disobey.mango
by aljaz aljaz@nostr.si

Mango - Confidential AI app

No provider lock-in. No subscriptions. Own your data. Bring your own key. Protect your chats. And delete them if forced to unlock the app. No tracking, no analytics. PPQ can now be set up automatically inside Mango (no account on ppq.ai needed first), funded via any external Lightning wallet by scanning a QR, and backed up to an encrypted device backup (.mppq) with a password. PPQ holds the balance (prepaid USD credit); Mango never touches funds. Duress wipe preserves PPQ credentials. BYOK and custom providers remain supported. The app that serves you.

First release: Apr 16, 2026, 4 total releases.

Most recent release: Sep 24, 2026.

Website Repo

Appears in 2 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Sep 24, 2026 0.3.1
    Bug fix release **Full Changelog**: https://github.com/aljazceru/mango/compare/v0.3.0...v0.3.1
  • Sep 23, 2026 0.3.0
    ### New features - Added optional on-device LLM inference on Android and iOS, including local model download and management. - Added hybrid inference routing, with local-only, remote-only, rules-based, and smart-routing modes. - Added the Venice privacy provider with encrypted transport and client-side TEE attestation. - Added Redpill provider support with TEE-attestation verification and per-enclave freshness details. - Added ContextVM remote tool discovery and invocation via Nostr relays. - Added tool-discovery screens on Android and desktop, including search, usage counts, details, and remote-provenance badges. - Expanded directory RAG ingestion to support DOCX, EPUB, HTML, and RTF files, with a 20 MiB per-file limit.
    More…
    ### Bug fixes and security improvements - Fixed NVIDIA NRAS v3 attestation compatibility, including request/response formats, ES384 JWT verification, and per-enclave nonces. - Fixed Redpill attestation URLs that could contain a duplicate /v1 path segment. - Improved local-model eligibility on 8 GB devices by using available RAM rather than an overly restrictive model-size cap. - Fixed iOS local-model prompts to use each GGUF model’s embedded chat template. - Fixed Android “Delete All Data” on debug and beta package variants. - Prevented cleanup of user-owned image files; only app-managed temporary attachments are removed. - Blocked IPv4-mapped IPv6 addresses in URL-fetch protections. - Excluded Android app data from cloud backup and device-transfer backups. - Fixed camera-capture cleanup when image attachment is cancelled. - Corrected lock-timeout behavior for the “Never” setting after background/resume. - Added Android release-signing safeguards and CI packaging for local-inference libraries. - Closed nine RustSec advisories and removed an unused dependency. - Fixed Nix development-shell dependencies and Android SDK-path leakage into local.properties. **Full Changelog**: https://github.com/aljazceru/mango/compare/v2.0...v0.3.0
  • Apr 24, 2026 0.2.2
    ### New Features #### Multimodal Image Support - Attach images to conversations via camera or gallery on iOS and Android, or file picker on desktop - Images are stored encrypted and rendered as thumbnails in chat history - Vision capability check gates image attachment to compatible models #### Directory RAG Sources - Index local folders as knowledge sources for RAG across all platforms - Desktop: file-system watcher + 5-minute ticker for automatic re-sync - iOS: bookmark-based directory picker with foreground-resume sync
    More…
    - Android: SAF (Storage Access Framework) directory picker with background sync worker - Directory sources folded into the existing RAG screen (no separate UI section) #### Fork Conversation - Fork any chat into a new independent conversation from a selected message - Available via long-press context menu on Android and the chat menu on desktop #### Export Chat to Markdown - Export any conversation as a Markdown file from the chat menu (desktop) #### Rename Conversation - Tap the chat title in the header to rename it inline on all platforms #### Lock Timeout: Never - Selecting "Never" for the lock timeout now skips the PIN prompt on cold launch - Displays a threat-model warning when "Never" is selected ### Bug Fixes - Restored UI state mirror in CoreUpdated handler (regression from a7c204b) - Guarded NewConversation against locked-DB panic on desktop - Fixed copy action not working in chat - Fixed multipart user messages not propagating to Tinfoil/PPQ transports - Fixed image-bearing message turns being routed incorrectly through the tools branch - Fixed [Image:] placeholder leaking into multipart text content - Fixed navigation: push previous screen onto stack for Chat entry + Android BackHandler - Fixed migration ordering: MIGRATION_V17 now correctly precedes MIGRATION_V18 - Fixed iOS glob matcher using prefix match instead of exact/suffix for literal patterns - Pre-fetch directory files, verify embed length, and accumulate errors (HI-02/HI-04/ME-05) - Cap per-file RAG ingestion at 32 MiB before reading into memory - Bookmark rehydration on Android cold launch (SAF regression)
  • Apr 16, 2026 0.1.0