Local-only app: remove network, uploads, providers, backend, desktop

Phone is now a pure on-device recorder: no accounts, no servers, no
background uploads (INTERNET permission gone). File sync is the user's
own tooling; the library adopts externally added files.

Android:
- Delete provider package (Nextcloud, custom SHONAR, sync-folder,
  registry, auth, TOFU/TLS), sync stack (SyncWorker/Drain/Slots,
  MigrationRunner), provider/storage/folder UI, AI-via-server details.
- Home shows a fixed 'on this phone' library; details keep playback,
  rename, file info. Settings lose Network/provider/HTTP-logging.
- Library root is the stored folder or Music/Recordings; import is
  double-scan proof (mutex + unique filePath index, migration v3->v4
  dedupes by path) with regression tests.
- Drop okhttp/work/security-crypto/media deps; delete their tests.

Repo: backend/, desktop/, worker/, deploy/, shared/, server scripts
and docs removed; README rewritten; CI keeps the android job only.
This commit is contained in:
avi 2026-09-14 11:56:20 -05:00
commit 8c510f4ab9
154 changed files with 196 additions and 23570 deletions

117
README.md
View file

@ -1,46 +1,26 @@
# S.H.O.N.A.R.
**S.H.O.N.A.R. — Self-hosted Oral Notes and Audio Recorder**
**S.H.O.N.A.R. — Self-hosted Oral Notes and Audio Recorder (local-only)**
An open-source, self-hosted alternative to cloud voice-note AI devices and
services. Record conversations on your Android phone, sync them to a server
**you** control, transcribe and summarize them with AI providers **you**
choose, and keep full ownership of your audio, transcripts, and accounts.
Record conversations on your Android phone and keep them in a folder you
control. No accounts, no servers, no uploads, no telemetry — the app has
no network permission at all. If you want your recordings on other
machines, sync the folder yourself (Syncthing, USB, …); the app adopts
files added from outside into its library automatically.
- No telemetry. No third-party analytics. No hidden external AI calls.
- Runs fully locally by default (local transcription + local LLM supported).
- Works with **no AI configured at all**: recording, sync, playback, download,
and manual transcripts still work.
- Apache-2.0 licensed. All code in this repository is original.
- Record with one tap (app, notification, or home-screen widget), pause /
resume, save with rename, play back with seek + speed.
- Library lives in a folder on the phone (`Music/Recordings` by default);
rename and delete move together with the audio file.
- Apache-2.0 licensed.
## Repository layout
```
android/ Android app (Kotlin, Jetpack Compose, Material 3)
backend/ FastAPI + PostgreSQL API server
worker/ Background worker entrypoint (same image as backend)
shared/ OpenAPI spec shared with the Android client
deploy/ Docker Compose, reverse proxy, backup/restore
docs/ Architecture, API, security, self-hosting guides
scripts/ Dev / CI helper scripts
docs/ Recording-consent notice
```
## Quick start (Docker)
```bash
cp .env.example .env
# EDIT .env — at minimum set SHONAR_SECRET_KEY (any 32+ random chars):
# python3 -c "import secrets; print(secrets.token_urlsafe(48))"
docker compose up -d --build
```
Then open `http://localhost:8000/docs` for the interactive API docs and
point the Android app at your server URL. (ReDoc at `/redoc`, raw schema at
`/openapi.json`.)
The default compose stack is: API + worker + PostgreSQL + Redis, with audio
stored on the local filesystem. No paid cloud service is required.
## Quick start (Android)
Requirements: JDK 17, Android SDK (platform 35). See
@ -52,85 +32,12 @@ cd android
adb install app/build/outputs/apk/debug/app-debug.apk
```
## Feature status
S.H.O.N.A.R. is developed in milestones; each merged milestone is tested and
buildable. See [docs/ROADMAP.md](docs/ROADMAP.md) for the maintained matrix.
**Current state:**
- Backend: M0–M2 complete — health, full auth (register, login, rotating
refresh tokens with reuse detection, logout, delete-account), rate
limiting, chunked resumable uploads, recordings CRUD, storage
abstraction, Postgres FTS schema, Docker dev stack.
- Android: app shell with a generic data-driven **Custom Settings** system
(8 value types, add/edit/delete/reset/search/export/import).
- **Product direction:** the server layer is provider-based, with
**Nextcloud as the default** provider and options for Start9, Umbrel, a
custom SHONAR server, or local-only storage. See
[docs/server-providers.md](docs/server-providers.md) for the interface,
data model, auth flow, and phased plan.
- Home Assistant is **not** part of the initial product. Prior work is
preserved but disabled under [`deferred/home-assistant/`](deferred/home-assistant/README.md)
and on branch `deferred/home-assistant`.
- Provider sync and AI pipeline remain TODO; local recording, playback, and
library storage are implemented in the Android app. The custom SHONAR
server provider (login, token persistence + auto-refresh, chunked
upload/download) is implemented with provider-selection login UI;
on-device verification pending, WorkManager sync driver still TODO.
## AI providers
All AI is optional and provider-independent, configured only through
environment variables (never hard-coded keys):
| Variable | Values | Default |
|---|---|---|
| `SHONAR_TRANSCRIPTION_PROVIDER` | `none`, `whisper_http`, `faster_whisper` | `none` |
| `SHONAR_TRANSCRIPTION_MODEL` | model name (e.g. `base`, `small`) | `base` |
| `SHONAR_TRANSCRIPTION_BASE_URL` | whisper-compatible HTTP server URL | — |
| `SHONAR_LLM_PROVIDER` | `none`, `openai_compat`, `ollama` | `none` |
| `SHONAR_LLM_MODEL` / `SHONAR_LLM_BASE_URL` / `SHONAR_LLM_API_KEY` | model/endpoint/credentials | — |
| `SHONAR_STORAGE_BACKEND` | `local`, `s3` | `local` |
| `SHONAR_STORAGE_PATH` | filesystem storage root | `./data/storage` |
| `SHONAR_DATABASE_URL` | SQLAlchemy async URL | postgres in compose |
When any external (non-local) provider is enabled, `/api/v1/system/status`
reports `external_ai_in_use: true` and the Android app shows it in Settings —
you always know if your audio or text leaves your machine.
## Documentation
- [docs/self-hosting.md](docs/self-hosting.md) — deployment, HTTPS, backups
- [docs/api.md](docs/api.md) — API overview (OpenAPI at `/openapi.json`)
- [docs/security.md](docs/security.md) — security model and honest limits
- [docs/architecture.md](docs/architecture.md) — system design
- [docs/recording-consent.md](docs/recording-consent.md) — legal notice
## Development
```bash
# backend
cd backend && uv venv .venv && uv pip install -e ".[dev]"
docker compose -f deploy/docker-compose.dev.yml up -d
.venv/bin/alembic upgrade head
.venv/bin/uvicorn shonar.main:app --reload
.venv/bin/pytest # tests
.venv/bin/ruff check . # lint
# android
cd android && ./gradlew test
```
## Contributing
See [CONTRIBUTING.md](CONTRIBUTING.md) and
[CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md).
## License
Apache-2.0 — see [LICENSE](LICENSE).
## Legal notice
**You are responsible for complying with recording-consent laws in your