The manifest gives this keyboard no internet permission
Souchastnik is an Android input method, so it can see what a user types. Its clearest design choice is in AndroidManifest.xml: there is no android.permission.INTERNET, and the app removes an AndroidX-added receiver permission during manifest merging. The README tells users to inspect the built APK with aapt. This is stronger evidence than a privacy-policy promise, though buyers should still verify the exact APK they install.
The source also skips password, visible-password, web-password, PIN, and card-number input types. It reads up to 400 characters before the cursor for analysis and runs the model in a separate process, allowing the keyboard to remain available if Android kills the engine for memory pressure. These controls reduce exposure inside the app. They do not prove that every device build matches the source.
A 0.8B local model answers a narrow Russian-language question
The app pairs a quantized Qwen3.5-0.8B model with llama.cpp. A local trigger dictionary first narrows the possible legal articles, then the model decides whether the typed phrase appears to match one. Separate dictionaries append mandated labels for named entities and services. The product is therefore specific to Russian text and Russian legal references, even though the keyboard declares both Russian and English input subtypes.
The README says Android 9 or newer, arm64, and 4 GB of RAM are required. It reports 4 to 6 seconds per phrase on its tested phone and 15 to 20 seconds on older cores without dot-product instructions. Those are project claims, not our measurements. We did not reach an APK or run inference, so we cannot confirm latency, classification quality, memory use, or the claim that password suppression works in the published release.
What happened when we ran it
Our fresh Debian sandbox installed commit df86f6c in 75 seconds using the JVM 21 image. It had 3 CPUs, 10 GB of RAM, no secrets, and no elevated privileges. The repository contained 47 files, about 2,780 source lines, and occupied 0.2 MB. Installation succeeded, but the next two steps did not.
The build exited with status 1 after 13 seconds. Gradle reported that the Android SDK location was missing and told us to set ANDROID_HOME or add sdk.dir to local.properties. The test command failed at the same configuration stage with exit 1 after 13 seconds. Its log gave the same SDK error, so it did not establish whether any application behavior passes.
A release build needs assets that the public checkout omits
The Gradle file targets SDK 35, uses Java 17, builds only arm64 native code, and expects CMake 3.22.1. None of that is introduced in the public README as a source-build checklist. Our log also printed the project's own warning that a missing keystore.properties causes release output to use a debug key, which must not be published.
Model weights are deliberately excluded from Git. The maintainer guide under jniLibs explains where to place the renamed GGUF file and how to fetch a public base model, while the README says the legal trigger dictionary is available only by request. With 0 CI workflow files, no Dockerfile, and no tests directory in our scan, a contributor must assemble the Android SDK, native toolchain, model, trigger data, and signing material before reproducing the intended release.
Open reports challenge both classification and device fit
Issues 22 and 23, opened September 16, show cases that reporters say the app did not flag as extremist content or searches for such material. The reports consist mainly of screenshots and have no maintainer diagnosis, so they do not establish a cause. They do establish that users have observed missed classifications, which is enough reason to reject the output as legal advice. The README makes the same disclaimer.
Device reports point to ordinary keyboard risk as well. Issue 20 says the package appeared incompatible or damaged on a Realme 10 Pro+, while issue 21 shows the keyboard extending beyond its frame. Both were open with no comments when checked on October 1. Issue 5 asks for NPU support and has an open pull request attached to that work, but discussion also records differing results across test builds.
v1.0 has attention, but only a short operating record
GitHub showed 714 stars and 15 combined issues and pull requests on October 1, 2026. The repository was created August 31, pushed September 7, and its latest release is v1.0 from September 3. Issue activity continued after the last source push, including compatibility and missed-detection reports. That combination looks like an early project receiving real user feedback, not an abandoned repository.
Souchastnik makes one admirable trade: the local model increases the APK and device burden so typed text does not need a network service. The privacy mechanism is inspectable. The legal classification is much harder to trust, especially when the matching dictionary is unavailable in Git and users report misses. Treat it as provocative software for informed testing. For daily typing, a mature offline keyboard is the safer choice; for legal questions, use a qualified human.

