Tower approval first
Every new passenger asks before joining.
Local-first connection
One phone becomes the Tower. Nearby passengers request entry, the Tower approves them, and everyone can connect across the local network—even when the outside world is offline.
Adult: Android, iPhone and iPad · Family ages 13–17: Android
Every new passenger asks before joining.
Call media uses peer-to-peer transport where possible; signalling stays on the Tower.
A deliberate scan keeps young travellers in the right space.
The cabin keeps working when the cloud disappears.
How a cabin begins
CabinMesh treats admission as a human decision, not a discovery shortcut. The person hosting stays in control of who enters.
One adult device opens a cabin on a temporary nearby local network.
A new installation waits until the Tower explicitly accepts or rejects it.
Approved adults can chat, play and share locally; call media connects directly where possible.
Two deliberately different editions
For adults
Create or join an approved nearby cabin for conversation, entertainment and direct voice.
Adult organized
A nearby adult assigns each roster name and opens the door with a short-lived, single-use invitation.
The Family invitation is a technical enrollment control. It is not a substitute for legal parental consent where local law requires it.
Optional offline assistant
CabinMesh Adult for Android can download a verified on-device model while internet is available. The app checks the exact byte count and SHA-256 fingerprint before it lets native code open the file.
2.41 GiB · text, image and audio input · designed for capable phones with at least 8 GB memory.
Content-addressed and resumable3.41 GiB · a larger local model for high-memory devices · never used for cloud inference.
Exact length + SHA-256 requirediOS uses the model managed by the operating system. It does not download or send prompts to the Android model service.
OS-owned offline providerFamily has no generative AI or model download. Model hosting changes delivery only: inference, prompts, attachments, responses and history stay on the user's device.
View the versioned Android model manifestPrivacy model
Core cabin activity does not need a CabinMesh account or central message server. Nearby devices communicate across a temporary local network they create, join or already share.
Read the FlightNet policiesAdmission, session activity, games and direct sharing happen between nearby devices.
A report is saved locally first. Delivery needs internet and an available HTTPS intake; optional evidence is included only after explicit opt-in.
Some local signalling and file paths use the nearby LAN without end-to-end content encryption. We do not hide that.
Project status
The apps and their store channels are verified separately. This site will publish a download or beta link only after that exact channel is confirmed usable—not merely created in a store console.
Simulator and engine checks do not replace physical-device, real-LAN, live-call or store validation. The latest recorded iOS checks include source changes made after submitted build 1.0.1 (5).
Open the setup and readiness guideQuestions, answered plainly
Yes for the nearby cabin itself. Optional safety reports and software or model downloads require an internet connection.
No. A new Adult installation waits for the Tower. Family has no public discovery and enrolls only from an adult-issued QR.
The local cabin is no longer available. The Family listener runs only while the adult keeps its organizer surface open.
No. Family is a closed, games-only product without chat, files, calls, ads, purchases or generative AI.
Android and iOS distribution are being verified separately. Links will appear here only after the corresponding channel is ready.
The freshly rerun iOS scope contains 137 distinct tests across the app, Safety, Calls and UI suites. The complete documented iOS inventory contains 271 distinct methods; repeating the UI suite on both iPhone and iPad produces 282 recorded executions. Physical-device permissions, a real multi-device LAN, live calls and store approval remain separate checks.
No. Reports are saved locally first and remain queued until an available HTTPS intake accepts them. The production intake is not live yet while its backup and operator controls are completed.