For agents, on top of README.md, which they read first.

Notes for agents

  • The user of this product is a young child. Every conversation is logged and visible to the parents; that is a requirement, not an option to trade away. Nothing reaches the child without passing the guard. A failure of the model, the guardrail or the network ends in a safe spoken fallback, never in silence or raw error text.
  • Never log content. Nothing the child or Whiskers said, no memory facts, no summaries, and not the child's name. Log lengths, counts, ids, durations and whether a profile is set.
  • The child is a profile, never a literal. Name and age live in HouseholdConfig::child (whiskers-core/src/profile.rs) and reach prompts and the guard only through Audience. Do not write a name, an age or a pronoun for the child into code, tests, fixtures, docs or comments; test fixtures use Ada, age 6. With no profile the guard assumes the youngest supported age (Age::YOUNGEST): a missing profile must never be the loose case.
  • Nothing identifying goes in tracked files. No family details, hostnames, IPs, device serials, user names, personal paths or secret names: they are build properties and environment variables. tools/check-private.sh enforces a deny-list kept in the gitignored .private-terms; run it before committing. Operator-private notes belong outside this repository.
  • No non-native user interface. Rust core, Kotlin shell with Jetpack Compose. Logic belongs in the core; the shell draws and listens.
  • Jev decides whether a message is allowed; a model writes the parents' summary. Shared Jev client code lives in third-party/jevcrates (a submodule); do not write a second client here.
  • Measure on the device before designing around it. Speech recognition, the child profile and the Fire OS version differ per device. Do not assume a Google service exists on Fire OS.
  • Pushing is the owner's call, per push.