Lotti Private Logbook
A local-first logbook where personal AI assistants suggest next steps while you retain approval over every material change.
The evidence describes a structural separation between agent opinions and user facts, with confirmation required for task, checklist, status, and date changes except initial title and language on empty fields. Outbound flows are explicitly limited to configured encrypted sync and configured inference, with model and usage records. End-to-end encryption, device verification, and a security scope covering keys, certificates, payloads, and integration leakage are documented. Deductions apply because local databases lack application-level encryption at rest, sync metadata remains observable, provider retention and training behavior cannot be verified by the app, and dependency-security evidence is limited to read-only workflow permissions, pinned action versions, and a reporting process rather than audits or vulnerability scanning. Agent templates can be rolled back and agent memory rebuilt, but user-data recovery depends on peer replication and ordinary backups, with no server recovery. Attribution and maintainer channels are visible, although publisher identity is not independently verified.
The README is broadly consistent about core boundaries, failure modes, and privacy limitations, while the API tests cover health, invalid input, provider failures, unexpected failures, and streaming response structure. Deductions apply because live provider tests are skipped without GEMINI_API_KEY and the supplied evidence does not cover offline operation, timeouts, retries, or failures across the advertised provider set. The archived Android workflow uses obsolete Java, Node, and action versions and retains historical MeinsApp and master-branch structure, adding legacy inconsistency. Error responses use meaningful status codes and sanitized messages, but no evidence shows recovery guidance in the end-user interface.
The material identifies concrete scenarios spanning tasks, journals, voice capture, time tracking, health data, and category-specific AI routing. It documents five operating-system families, local inference, numerous cloud providers, and custom OpenAI-compatible endpoints. Boundaries are unusually explicit: AI can be disabled, image generation has no local path, experimental features are off by default, server-side recovery is absent, and provider conduct cannot be verified. Trigger precision is deducted because automatic wake behavior is only summarized; the supplied files do not establish detailed trigger rules, suppression conditions, or false-trigger controls.
The README has strong organization across installation, features, architecture, privacy, development status, pricing, and documentation. It gives platform-specific acquisition routes, source-build commands, and further documentation pointers, and a complete GPL-3.0 license is present. Limitations are documented particularly well, including unencrypted local storage, observable metadata, nonautomatic history transfer, mobile data-access friction, and rough experimental features. Deductions apply because the supplied evidence has no substantive FAQ or end-to-end usage examples and no formal version or changelog material. Naming is mostly stable, but archived MeinsApp paths and the master branch expose legacy structure. Security reporting and support ownership are clear and the single-maintainer constraint is disclosed, but there is no formal response SLA, maintenance commitment, or release governance.
Agent output is presented as reports, summaries, and individually reviewable proposals tied directly to task workflows, making it readily actionable. Separating intent from recorded reality, persistent assistants, review-driven agent evolution, and category-level routing show material incremental value over a basic logbook or task list. Deductions apply because effectiveness is supported chiefly by project claims and the author's personal usage account rather than independent outcome evidence. Cloud inference, self-hosted Matrix, local hardware consumption, and possible platform purchases add costs, while impact accounting remains incomplete for most providers.
Architecture, data flows, exceptions, and limitations are expressed as concrete claims that could be inspected, and API tests corroborate a limited set of endpoint structures and error mappings. The documentation carefully distinguishes application guarantees, third-party claims, the author's daily-use validation, and speculative compatibility, earning full credit for fact-inference separation. Deductions apply because the evidence is dominated by README assertions and omits the core implementation of database write barriers, encrypted sync, telemetry absence, and inference request logging. The workflows and API tests corroborate only peripheral or limited subsystems rather than the principal security and product claims.
- Local SQLite databases are not encrypted at rest by Lotti; compromise of a device or OS account may expose sensitive records.
- A Matrix homeserver can still observe synchronization timing and approximate volume; end-to-end encryption does not conceal that metadata.
- A newly paired device does not automatically receive existing settings and history; these must be sent manually, and sync is not a substitute for a consistent backup.
- Data sent to an AI provider remains subject to that provider's retention, training, and jurisdiction terms, which Lotti cannot verify in operation.
- The supplied files do not expose full implementation evidence for encryption, the approval write barrier, the no-telemetry claim, or current dependency vulnerability status.
- The archived Android pipeline contains obsolete tooling and steps that write credentials to disk; no leakage is shown, but it should be reviewed and modernized before reuse.
What does this agent do, and when should you use it?
Lotti combines journaling, task management, and time tracking in Flutter applications for macOS, Linux, Windows, iOS, and Android. It stores planned tasks separately from records of what actually happened, alongside notes, audio, images, habits, measurements, and health data in local SQLite storage. Persistent task agents read this context, summarize it, and propose checklist, status, or scheduling changes, but users must approve those changes except for the initial title or language of an otherwise empty task. Personal records live in a user database, while agent memories, reasoning traces, wake history, and suggestions occupy a separate agentic database that can be pruned or rebuilt. Device sync is end-to-end encrypted over Matrix using Synapse and Vodozemac, while inference is optional and can be routed by category to Ollama, OpenAI, Anthropic, Mistral, Google, Alibaba, Nebius, OpenRouter, Melious, or another OpenAI-compatible endpoint.
Users capture tasks, checklists, planned blocks, time records, journal entries, images, measurements, surveys, habits, and audio through the Flutter app. Whisper or Voxtral can transcribe audio on-device, while configured cloud providers may also process audio; a voice note can be turned into a task with a checklist. Task agents read a task and its attached context, maintain persistent state and memories, wake when configured, and produce reports plus proposed edits. Those proposals remain in the agentic database until approval moves them through a controlled path into the user database; only an empty task's first title and missing language may be set automatically. Inference routing separates providers, models, and inference profiles, allowing each category to use a different local or hosted model. Usage & Impact records cloud requests, models, and token counts, adding cost, energy, and CO₂e only when a provider supplies them. Matrix sync encrypts both databases, uses vector clocks for conflict resolution, and requires QR pairing, check-code comparison, and emoji verification before a new device can decrypt records.
- A freelancer whose plans routinely change can keep intended tasks and planned blocks separate from actual time, focus ratings, and supporting notes.
- A mobile user who captures rambling voice notes can transcribe them locally with Whisper or Voxtral and turn them into structured tasks with checklists.
- A privacy-conscious journaler can retain SQLite records and attachments on personal devices while synchronizing ciphertext through a self-operated or trusted Synapse server.
- Someone who wants AI assistance without autonomous edits can review, confirm, or dismiss every proposed checklist, status, and date change.
- A user with mixed sensitivity levels can route private categories to Ollama while sending ordinary task management or open-source work to a chosen cloud model.
- A person tracking work and well-being can review time by category alongside habits, measurements, and health information imported from Apple Health or other sources.
What are this agent's strengths and limitations?
- It preserves intent and observed reality as separate records instead of rewriting the historical record when plans change.
- The physical split between the user and agentic databases constrains agent writes, with material edits passing through explicit human approval.
- Local SQLite, filesystem attachments, no telemetry, and end-to-end encrypted sync give users direct possession of their records and control over the relay.
- Inference is optional and can be routed per category across Ollama, several cloud providers, or a custom OpenAI-compatible endpoint.
- Tasks, voice capture, journaling, time, habits, measurements, and health data share one cross-platform workspace.
- Usage & Impact identifies every cloud model request and token count, with cost, energy, and CO₂e shown where the provider reports them.
- Synchronization requires a Synapse homeserver operated by the user or a trusted party; no hosted sync service is included.
- The on-device SQLite files are not separately encrypted by Lotti, so a compromised device or OS account can expose local records.
- Pairing a device does not automatically transfer historical data or settings; the existing device must send both explicitly.
- Windows users must build from source, while TestFlight and some mobile-store distribution remain invitation-only.
- The design-system migration and agent layer are still evolving, and projects, events, dashboards, embedding search, and Daily OS ship behind experimental flags.
- There is no local image-generation path, and impact metrics beyond tokens are currently available only when Melious returns them.
- Ordinary code pull requests are not accepted; upstream contributions are limited mainly to issues and qualifying translations.
How do you install or deploy this agent?
On Linux, install com.matthiasn.lotti from Flathub, which is the recommended route, or download a tar.gz from GitHub Releases. macOS users can download a signed and notarized DMG from Releases, and Android users can install the release APK. TestFlight for iOS, iPadOS, and macOS and Play Store internal testing for Android are invitation-only; Windows currently requires a source build. To build from source, install Flutter through FVM, then run make deps, make analyze, make test, and fvm flutter run -d <device> from the repository; Linux also needs the audio-codec and emoji-font packages identified in docs/DEVELOPMENT.md. Local use requires no AI credentials. Inference requires either a configured local Ollama endpoint or an API key for the selected provider; custom OpenAI-compatible base URLs are supported. Encrypted multi-device sync requires a Synapse homeserver operated by you or someone you trust, with the included tools/matrix_provisioner CLI used to create the first account, encrypted room, and single-use pairing bundle.
How do you use this agent?
Start by creating categories and recording tasks, journal entries, audio, or time in the app; task management, journaling, and time tracking work without an inference provider. To enable assistants, configure a provider, its models, and an inference profile, then assign that route to the relevant categories. Attach a Task agent to a task to receive a persistent report and proposed changes, then confirm or dismiss each proposal in the UI or use Confirm all. Provision the first synchronized device with tools/matrix_provisioner. Pair later devices from an existing device by scanning the QR code, comparing the independently derived check code, and completing emoji verification. Pairing starts live synchronization but does not automatically copy the back catalogue or settings, so use Send settings and Send message history from an existing device. For a separate desktop backup, make a consistent SQLite copy with VACUUM INTO while Lotti is running and copy the attachments directory as well.