Why everything runs on your phone

Vì sao mọi thứ chạy trên điện thoại

Most consumer applications assume a server somewhere in the middle: you sign in, upload telemetry, run machine learning in a data center, and synchronize state through REST endpoints. That architecture works well for social feeds and collaborative documents. It is a poor fit for parking dead reckoning, forty-eight kilohertz audio synthesis, and calibrated noise measurement — three problems uranashel tackles daily across Wheria, Estua, and Sonarish. The phone in your pocket is not a thin client displaying someone else's computation; for our sensor apps, it is the computer.

When we say on-device-first, we mean the full pipeline executes locally: sample sensors at hardware rates, fuse estimates in real time, render the interface, and persist history inside the app sandbox. Phyzix follows the same rule — lab sessions and CSV exports never leave the device unless you explicitly share them. Stashio is the deliberate exception: optional cloud sync when you want your bookmarks on a second phone, but capture, indexing, and search still function in airplane mode. The architectural choice is not ideology for its own sake; it follows from the physics of latency, the economics of privacy, and the environments our users actually stand in.

Latency budgets that cloud cannot meet

Consider Wheria updating your walked path after each detected step. At a normal walking pace, footfalls arrive roughly every half second to seven tenths of a second apart. The inertial measurement unit samples accelerometer and gyroscope data at fifty to two hundred hertz, meaning the fusion filter must ingest new measurements, propagate uncertainty, and redraw the path within milliseconds — not after an eighty-millisecond round trip to a Singapore data center. Compass heading at fifty hertz allows only twenty milliseconds between updates; Wi-Fi round-trip time alone consumes that budget before any server-side Kalman filter runs.

Estua's audio engine operates under even stricter deadlines. The callback fires every five hundred twelve samples at forty-eight kilohertz, which equals approximately ten point seven milliseconds per buffer. Miss that deadline and the output buffer contains a discontinuity the human ear hears as a click — catastrophic at two in the morning when someone is trying to sleep. There is no practical path to POST pulse-code-modulated audio to a remote server and receive synthesized noise back in time. Sonarish faces a related constraint: fast Fourier transform windows of two thousand forty-eight to four thousand ninety-six samples at forty-eight kilohertz represent forty-three to eighty-five milliseconds of captured sound, and a real-time spectrogram requires the transform on the same device that owns the microphone hardware abstraction layer.

Privacy as a consequence of design

We describe ourselves as privacy-conscious not because marketing demanded the label, but because we never built the server-side infrastructure that would violate it. Wheria stores parking coordinates, walked path polylines, floor hints, and optional photos entirely inside the app sandbox — no account required, no upload queue. Sonarish keeps noise sessions, machine baselines, and exported spectrogram images local by default. Estua remembers only your scene preference and random seed; the audio stream itself is never recorded unless you explicitly export it. We do not embed third-party analytics SDKs in these applications, and crash reports flow through Apple and Google's standard channels only. There is no model training on our servers because there are no servers collecting accelerometer traces.

Offline is the normal case, not an edge case

Parking garages frequently offer zero usable LTE signal. Factory noise surveys happen inside shielded halls where cellular radios struggle. Sleep audio must work in airplane mode on long flights. Treating connectivity as optional rather than mandatory means the apps function in the places where users need them most — underground, inside metal structures, and at three AM when the household Wi-Fi is off. This is why ktuyen's test matrix includes explicit offline garage walks before every release: if indoor navigation requires a network handshake, it fails the moment you descend a ramp.

What we consciously give up

On-device-first has costs we acknowledge openly. Cross-device sync for Wheria parking pins — sharing a garage walk from iPhone to Pixel without manual export — remains unbuilt because we have not prioritized the encrypted sync layer. Community heatmaps of parking spots and server-side models that improve with everyone's data are features we could ship with cloud infrastructure, but they contradict the latency and privacy properties that make the sensor apps trustworthy. We accept slower feature velocity in exchange for millisecond feedback, offline reliability, and data that never leaves your phone unless you choose to export it. For a four-minute walk back to your car, that trade is correct. To understand how Wheria uses those local computations underground, continue with indoor navigation when GPS dies; for the audio thread constraints Estua shares with Sonarish, see life on the audio thread.

Đa số ứng dụng consumer giả định có server ở giữa: đăng nhập, upload telemetry, chạy machine learning ở data center, đồng bộ trạng thái qua REST. Kiến trúc đó phù hợp feed xã hội và tài liệu cộng tác. Nó kém phù hợp với dead reckoning tìm xe đỗ, tổng hợp audio 48 kHz và đo ồn đã hiệu chuẩn — ba bài toán uranashel giải hàng ngày qua Wheria, Estua và Sonarish. Điện thoại trong túi không phải thin client hiển thị tính toán của người khác; với app cảm biến, nó chính là máy tính.

Khi nói on-device-first, team có nghĩa toàn bộ pipeline chạy cục bộ: lấy mẫu cảm biến ở tốc độ phần cứng, fusion ước lượng real-time, render giao diện, lưu lịch sử trong sandbox app. Phyzix theo cùng quy tắc — session lab và export CSV không rời máy trừ khi bạn chủ động chia sẻ. Stashio là ngoại lệ có chủ đích: sync cloud tùy chọn khi muốn bookmark trên máy thứ hai, nhưng chụp, index và tìm kiếm vẫn hoạt động ở chế độ máy bay. Lựa chọn kiến trúc không phải lý tưởng vì lý tưởng; nó đi theo vật lý độ trễ, kinh tế privacy và môi trường user thực sự đứng trong đó.

Ngân sách độ trễ cloud không đáp ứng

Xét Wheria cập nhật đường đi sau mỗi bước phát hiện được. Ở nhịp đi bộ bình thường, bước chân cách nhau khoảng nửa đến bảy phần mười giây. Bộ đo quán tính lấy mẫu gia tốc và con quay ở 50–200 Hz, nghĩa là bộ lọc fusion phải hấp thụ đo mới, lan truyền độ không chắc chắn và vẽ lại đường đi trong vài millisecond — không phải sau round-trip 80 ms tới data center Singapore. Heading la bàn ở 50 Hz chỉ cho 20 ms giữa các cập nhật; riêng RTT Wi-Fi đã ăn hết ngân sách trước khi Kalman phía server chạy.

Engine audio Estua chịu deadline còn chặt hơn. Callback mỗi 512 sample ở 48 kHz, tương đương khoảng 10,7 ms mỗi buffer. Trễ deadline thì buffer output có discontinuity mà tai nghe thành click — thảm họa lúc hai giờ sáng khi ai đó đang cố ngủ. Không có con đường thực tế POST PCM lên server xa và nhận noise tổng hợp kịp thời. Sonarish gặp ràng buộc tương tự: cửa sổ FFT 2048–4096 sample ở 48 kHz là 43–85 ms âm thanh thu được, và spectrogram real-time cần transform trên cùng thiết bị sở hữu HAL microphone.

Privacy là hệ quả của thiết kế

Team mô tả mình quan tâm privacy không vì marketing cần nhãn, mà vì chưa xây hạ tầng server có thể vi phạm nó. Wheria lưu tọa độ đỗ, polyline đường đi, gợi ý tầng và ảnh tùy chọn hoàn toàn trong sandbox — không cần tài khoản, không hàng đợi upload. Sonarish giữ session ồn, baseline máy và ảnh phổ export local theo mặc định. Estua chỉ nhớ scene và seed; luồng audio không bao giờ ghi trừ khi bạn export. Team không nhúng SDK analytics bên thứ ba, crash report đi qua kênh chuẩn Apple/Google. Không train model trên server vì không có server thu trace gia tốc.

Offline là trường hợp bình thường

Hầm xe thường LTE bằng không. Khảo sát ồn xưởng diễn ra trong hộp kínen cản sóng. Audio ngủ phải chạy airplane mode trên chuyến bay dài. Coi kết nối là tùy chọn thay vì bắt buộc nghĩa là app hoạt động ở nơi user cần nhất — dưới hầm, trong kết cấu kim loại, lúc ba giờ sáng khi Wi-Fi nhà tắt. Đó là lý do ma trận test ktuyen có walk hầm offline trước mỗi release: nếu indoor navigation cần bắt tay server, nó fail ngay khi xuống ramp.

Thứ team chủ động hy sinh

On-device-first có giá team thừa nhận rõ. Sync chéo thiết bị cho pin đỗ Wheria — chia walk hầm từ iPhone sang Pixel không export thủ công — chưa xây vì chưa ưu tiên lớp sync mã hóa. Heatmap cộng đồng chỗ đỗ và model server học từ data mọi người là feature có thể ship với cloud, nhưng mâu thuẫn độ trễ và privacy khiến app cảm biến đáng tin. Team chấp nhận feature chậm hơn để đổi lấy phản hồi millisecond, offline ổn và data không rời máy trừ khi bạn export. Với bài đi bộ bốn phút về xe, trade đó đúng. Để hiểu Wheria dùng tính toán local dưới hầm thế nào, đọc dẫn đường trong nhà khi GPS chết; về ràng buộc audio thread Estua chia với Sonarish, xem sống trên audio thread.