jegly/Box: an offline, on-device AI suite for Android
The most advanced, fully offline client-side AI suite on Android today.
At a glance
- What is it?
- Box is a Kotlin fork of Google AI Edge Gallery that runs LLMs, diffusion, speech and RAG on Android 14+ without a network connection. This article covers what it adds, how to install it, and where it breaks down.
- Who is it for?
- Adopt Box if you have an Android 14+ device with a supported NPU or TPU, you want GGUF models running locally, and you accept that the README does not document rollback, storage budgets or per-model hardware requirements. Skip it if your hardware is older, if you need a stable API contract rather than a moving release stream, or if you cannot sideload APKs.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 8 days ago.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What jegly/Box is, and who it is actually for
Box is a fork of Google AI Edge Gallery, the reference Android app Google publishes for running LiteRT models on phones. The fork keeps the upstream build number in its badge (UpstreamVersion 1.0.15) but tracks its own releases through GitHub tags, and the README notes that as of v2.0.0 the in-app "App version" matches the Box release version rather than the upstream Gallery number.
What that fork buys you is breadth. Where Gallery is a demonstration app for LiteRT, Box layers on a second inference engine (llama.cpp for GGUF), plus stable-diffusion.cpp for image generation, whisper.cpp and SenseVoice for speech-to-text, Supertonic for on-device TTS, SQLCipher for encrypted storage, and an MCP server integration. The topics list on the repository includes rag, visionai, music-generation and mcp-server, and the README badges confirm each of those areas.
The audience is narrower than the feature list suggests. Android 14+ is a hard floor. The NPU acceleration paths named in the badges are Snapdragon 8 Gen 2, 3 and Elite, Google Tensor G5 (Pixel 10) and G6 (Pixel 11), and MediaTek NPU. If you are on a mid-range 2022 phone, you can still install Box, but you will be running the CPU paths, and the README does not publish any performance figures for either case. That is a real gap: you cannot size your expectations from the documentation alone.
Two inference engines behind one app
The architecture is a hybrid. LiteRT handles the Google-native path, including Gemini Nano through ML Kit and NPU or TPU delegation on supported silicon. llama.cpp handles GGUF weights, and the README advertises Vulkan-based GPU offload for those GGUF models. stable-diffusion.cpp sits alongside for diffusion, also consuming GGUF.
That split is the interesting design decision. LiteRT gives you vendor-optimised execution and access to Gemini Nano, but it constrains you to models Google has packaged for the runtime. llama.cpp gives you the enormous GGUF ecosystem and community quantisations, at the cost of a second runtime, a second memory-management story, and a second set of failure modes. Box does not abstract the two behind a single model format; the README presents them as parallel capabilities.
Model admission appears to be gated. The repository carries model_allowlist.json at the top level and a model_allowlists/ directory. The README does not explain the schema or the policy behind it, so what a reader can confirm is only that an allowlist exists and that it is checked into the repository. Whether that list is enforced at load time, or is advisory metadata for the UI, is not stated. Treat it as a starting point for inspection rather than a documented contract.
On the storage side, SQLCipher with AES-256 is used, and the badges list a biometric lock. The README describes the app as "Hard Offline" on the network dimension, which is a stronger claim than "works without internet": it implies the network permission is not used for model traffic at all.
Installing Box from the release APKs
Box is distributed as APKs through GitHub releases, not through Google Play or F-Droid. The README points at the latest release and splits the download into two variants: Main for stock Android, and custom-rom-support for GrapheneOS, LineageOS and CalyxOS, which ship without Google services. Picking the wrong one is the first thing that will go wrong for a new user.
The README also documents an Obtainium route, which is the one to prefer if you want updates to arrive automatically. You paste the repository URL into Obtainium and then filter the release assets by regex so the right variant is selected.
# Repository URL to paste into Obtainium:
https://github.com/jegly/Box
# APK filter regex, Main variant:
Main
# APK filter regex, custom ROM variant:
custom-rom-supportAfter adding the repo, Obtainium resolves the latest release and installs it; the README states that future updates are detected automatically. Version 3.4.5 is the release listed at the top of the material, published on 2026-09-03, with v3.3.5 the day before and v3.3.4 on 2026-08-23. That cadence matters if you care about stability: three releases in under two weeks is a fast-moving target.
There is also an in-app updater under Settings, and the README points to Settings then Check for updates as the way to see whether a newer Box release exists. If you sideloaded manually rather than through Obtainium, that is your update path.
Where Box is the wrong tool
The clearest limitation is hardware. The accelerated paths are enumerated by chip family, and the README does not describe a fallback policy or minimum RAM. A device outside Snapdragon 8 Gen 2/3/Elite, Tensor G5/G6 or MediaTek NPU is not documented as unsupported, but it is also not documented as tested. Running a 7B GGUF model on CPU inside an Android app is a memory-pressure problem before it is a speed problem, and nothing in the README tells you what happens when the allocation fails.
Second, the release stream is aggressive. Three releases inside twelve days implies that fixes and regressions both arrive quickly. If you are building anything on top of Box, or recommending it to non-technical users, that is friction the README does not acknowledge.
Third, the licence situation is unresolved at the metadata level. The README badge says Apache 2.0 and a LICENSE file exists at the repository root, but the repository metadata reports the licence as NOASSERTION. Those two statements disagree, and the README does not reconcile them.
Finally, the documentation has real holes. There is no rollback procedure documented, no storage budget guidance for downloaded GGUF files, and no per-model hardware requirements. For a suite that asks you to pull multi-gigabyte weights onto a phone, the absence of a storage section is the gap most likely to bite.
How Box differs from Google AI Edge Gallery and PocketPal
The obvious alternative is the upstream project Box forked from: Google AI Edge Gallery. Gallery is a first-party demonstration of LiteRT, maintained by Google, with a narrower feature set and a build number that Box's badge still references at 1.0.15. If all you want is to try a LiteRT model on a Pixel with minimal setup, Gallery is the smaller surface area and the more predictable update path. Box exists for people who found that too narrow.
The other comparison worth making is against PocketPal, which appears in the related searches for this project. PocketPal is a llama.cpp-based Android client: one engine, one model format, focused on chat. Box's difference is the second engine plus the non-text modalities. Diffusion, speech-to-text, TTS, music generation and MCP servers are all outside what a single-engine chat client covers. The trade is complexity: Box ships more moving parts, and each one is another thing that can fail on a given device.
If your actual requirement is a self-hosted server you reach over the network, none of these are the right shape. Box is explicitly offline-first, and the README's "Hard Offline" framing means the network is not the transport for inference. That is the point of the project, but it also means you cannot offload a model too large for the phone.
Maintenance, updates and licence
The repository is not archived, and the last push was on 2026-09-03, which is recent relative to the release history. Releases v3.4.5, v3.3.5 and v3.3.4 all landed within the preceding two weeks of that push. On the evidence available, this is an actively released project, and the release notes are the place to check for behaviour changes between versions.
Upgrade cost depends on how you installed it. With Obtainium, the README states that future updates are detected automatically, so the cost is a periodic notification and whatever disruption a new APK brings. With manual sideloading, you are responsible for checking Settings then Check for updates, or the releases page. Because the app version now tracks the Box release tag rather than the upstream Gallery number, version comparisons in the UI should be meaningful after v2.0.0.
On licensing: the README badge points at Apache 2.0 and the repository contains a LICENSE file, while the repository metadata reports NOASSERTION. This article is not legal advice. What a prospective adopter should do is open the LICENSE file directly and read it, rather than relying on either the badge or the metadata field. The fork also carries a .gitmodules file, which means some components are pulled in as submodules; their licences are separate and the README does not enumerate them.
Editorial conclusion
Adopt Box if you have an Android 14+ device with a supported NPU or TPU, you want GGUF models running locally, and you accept that the README does not document rollback, storage budgets or per-model hardware requirements. Skip it if your hardware is older, if you need a stable API contract rather than a moving release stream, or if you cannot sideload APKs. Before committing, verify three things: that your device is on the supported list (Snapdragon 8 Gen 2/3/Elite, Tensor G5 or G6, or MediaTek NPU), that you can install the correct APK variant for your ROM, and that the model_allowlist.json file in the repository actually lists the model you intend to load. The licence file is present but the repository metadata reports NOASSERTION, so read LICENSE before any redistribution.
Frequently asked questions
What are some alternatives to Google AI Edge Gallery?
jegly/Box is itself a fork of Google AI Edge Gallery, and it adds a second inference engine (llama.cpp for GGUF) alongside LiteRT, plus diffusion, speech-to-text, TTS, music generation and MCP server support. PocketPal is a narrower alternative that focuses on llama.cpp chat on Android.
What Android version does jegly/Box require?
The README badge states Android 14 or later. The accelerated paths named in the badges cover Snapdragon 8 Gen 2, 3 and Elite, Google Tensor G5 and G6, and MediaTek NPU, but the README does not document a minimum RAM figure or a CPU fallback policy.
How do I install jegly/Box on a custom ROM?
Download the custom-rom-support APK from the latest release rather than the Main variant. In Obtainium, set the APK filter regex to custom-rom-support. The README names GrapheneOS, LineageOS and CalyxOS as the target ROMs for that variant.
Does jegly/Box send anything over the network?
The README describes the app as Hard Offline and the suite is positioned as fully offline and client-side. What the README does not document is the exact network permission set or any telemetry behaviour, so that is worth verifying yourself before relying on it.
What licence does jegly/Box use?
The README badge says Apache 2.0 and a LICENSE file exists at the repository root, but the repository metadata reports the licence as NOASSERTION. Because those disagree, read the LICENSE file directly before redistributing anything.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/jegly-box)