PRIVATE · UNCENSORED · 100% LOCAL

Your own AI.
No cloud. No login. No limits.

Characters, roleplay, branching stories, and a private assistant — powered by AI models that run on your own GPU, not the cloud. One download sizes itself to your hardware, then works fully offline: no setup, no account, nothing phoning home.

Windows, ready to go  ·  macOS & Linux are experimental — built but not yet tested on real hardware. Why?
No account. No cloud.No telemetry. Crash reports only if you opt in.Open source. MIT.
Aphelion llama3.1-8b · 11 / 12 GB — ▢ ✕
Seraphina · 17 messages
SERAPHINA
She lowers her bow, shoulders easing. “You came back. I wasn't sure you would.” A wry, knowing smile.
YOU
I said I'd find the trail. Lead the way.
Write a message…
LIVE 100% OFFLINE · YOUR GPU · TOTAL PRIVACY Your data never leaves your machine 🔒
Already on v0.1.2 or earlier? That build can't check for updates on its own — download the latest manually this once. From v0.1.3 on, Settings → Updates does it for you.
SEE IT IN ACTION

The full tour.

A ~35-minute deep dive through the whole app — first-run setup, building characters, the emotion-reactive live portraits, the routed expert assistant, and the privacy model that keeps it all on your machine.

WHAT YOU GET

A whole AI workspace — in one window.

Not a chat box bolted onto a server. Aphelion is one app where characters, stories, dialogue trees, and an expert assistant live side by side — all powered by models running on your own machine. Whether you're drafting a novel without a chaperone, querying a folder of your own research, or just want a capable AI that answers to no one — it's all one window.

LOCAL

Stays on your machine

Every prompt, model, and conversation runs and lives on your PC. Your data never leaves it — online or off.

ONE APP

One app, zero setup

Install one program and start talking — no command line, no separate tools to download and wire together.

AUTO-FIT

Fits your hardware

Aphelion reads your GPU and VRAM and loads the best model that runs fast — no config files, no guesswork.

WORKSPACE

More than a chat box

Characters and group chats, long-form stories, branching dialogue trees, and expert assistants — all in one place.

PRIVATE

Private by default

No account. No telemetry. No phone-home. The lock icon means exactly what it says.

OPEN

Open and yours

Free and MIT-licensed. Read the source, change it, build on it. Nothing hidden.

MODELS

It picks the right brain for your machine.

On first run, Aphelion checks your graphics card and downloads a model sized to fit — so it runs fast instead of crawling. Bigger card, bigger and smarter model. Switch any time, or bring your own.

~6 GB VRAM

Light & fast

A compact model like Gemma 3 4B. Runs on modest GPUs — even CPU in a pinch.

~2.3 GB download
~12 GB VRAM

Balanced

A strong all-rounder like Gemma 3 12B for mid-range cards.

~7 GB download
20 GB+ VRAM

Most capable

Flagship models — Gemma 3 27B or SuperGemma4 26B — for high-VRAM GPUs.

~15 GB download

Not sure how much VRAM you have? You don't need to know. VRAM is just your graphics card's memory (more of it = a bigger, smarter model) — and Aphelion checks yours on first run and picks one that fits. The numbers above are only if you're curious.

Uncensored models are available behind an opt-in warning, and you can point Aphelion at your own GGUF file. Whatever you pick, it runs entirely on your machine.

IS IT SAFE?

It's a model, not an agent.

Some "AI" tools are autonomous agents — deliberately given permission to run commands, browse the web, and change files on your computer (think AutoGPT, OpenClaw, and computer-use bots). That power is also the risk. Aphelion is the opposite: the model only ever speaks text — it has no autonomy and no reach into your system.

WHAT IT DOES
  • Reads your prompt and writes text back — that's the core job
  • Runs a model on your GPU, on your machine
  • Saves the chats and characters you make, on your own disk
  • Reads files only from folders you explicitly grant, as reference
  • Saves the documents you ask it to create, where you choose
WHAT IT CANNOT DO
  • Run programs, scripts, or shell commands
  • Reach the internet, your accounts, or other apps
  • Click, type, or control anything on your computer
  • Touch any file you haven't handed it — it never goes looking on its own

The model itself never touches your disk — when you grant a folder, the app reads the files and feeds the model plain text. It can write a villain's monologue; it can't go rummaging through your hard drive on its own.

FAQ

Questions, answered.

Is it really free?

Yes — completely. MIT open source, no account, no trial, no upsell.

Does it send my conversations anywhere?

No, never. The AI runs on your own computer. Disconnect from the internet and it keeps working.

What about telemetry and crash reports?

There is no telemetry by default — nothing is collected, nothing is sent. If you want to help squash bugs, Settings → Crash reports is an opt-in switch (off until you flip it): when the app hits an unexpected error, an anonymous report goes to sentry.io containing the error, stack trace, app version, and OS — never your chats, characters, prompts, or files. The reporting code isn't even loaded until you opt in, and you can turn it off any time. All told, Aphelion touches the internet only when you tell it to: downloading a model, checking for updates, or crash reports if you opted in.

Is this an "AI agent"? Can it do things to my computer?

No. The model only generates text — it has no autonomy. The app reads files only from folders you explicitly point it at, and saves documents you ask it to create; it never runs commands, browses the web, or goes through your files on its own. Unlike autonomous agents, it has no free rein over your system. See "It's a model, not an agent" above.

What's a "model"?

The AI's "brain" — a file the app downloads once. Setup picks a good one for your hardware; you can change it in Settings.

Windows says it "protected my PC" — is that bad?

No — it just means the app isn't code-signed yet, and that certificate is a recurring monthly cost, so while Aphelion is free I haven't bought one. Click More info → Run anyway (the source is all public). If enough folks chip in, I can sign it and the warning goes away.

What platforms and hardware do I need?

Windows 10/11, macOS (Apple Silicon), or Linux (x64). A graphics card (GPU) is recommended — more VRAM means a bigger, smarter model — but setup fits a model to whatever you have. macOS and Linux builds are brand-new (beta) and less battle-tested than Windows — please report anything odd.

Can I use uncensored models?

Yes — behind an opt-in warning. Whatever the AI writes is generated by the model you choose, not by Aphelion. Use at your own discretion.

How do I uninstall it?

Settings → Apps → Aphelion → Uninstall. It even asks whether to also delete the downloaded model and your chats, so you can reclaim the disk space.

UPDATES

What's new.

Already on v0.1.2 or earlier? Those builds don't have the in-app update check — it ships with v0.1.3, so they can't see this release on their own. You'll need to update manually this once: download the latest below (or from the releases page) and run the installer. From v0.1.3 on, Settings → Updates will check for you.

v0.1.49 LATEST

  • Opt-in crash reports. A new switch in Settings (off by default) can send anonymous crash reports when something breaks — the error, stack trace, app version, and OS. Never your chats, characters, prompts, or files: no breadcrumbs, no session replay, no tracing, and the reporting code isn't even loaded into the app until you opt in. Flip it on if you want field bugs to actually get fixed; flip it off any time. The site's privacy copy is updated to say exactly this.

v0.1.48

  • Resizable chat panel. The right panel's handle is now a splitter — drag it to widen the panel and read long scene fields in full (the width sticks); a plain click still tucks it away.
  • Readable delete buttons. Destructive buttons now use a deep red with white text, readable on every theme — including the red-accent presets where they used to blend in.
  • Expert names behave. Long expert names ellipsize cleanly in the picker and the manage list instead of overflowing their boxes (hover shows the full name).

v0.1.47

  • The portrait engine: multi-axis expression matching. Portraits are now matched on three expression axes — pleasure, energy, dominance (the research-standard PAD model) — on top of tags, so an intense moment stops landing on the angry portrait: same energy, same command, but anger needs low pleasure. Analyze rates every image's face on the axes; the scene tracker rates the moment; the picker matches them first, then outfit and setting, with pose dead last.
  • Train it yourself: the WHY tab. A little tab on the live portrait slides out the inspector — see exactly which tags drove the pick, 👍/👎 the choice (a 👎 cools those tags off and immediately tries the next-ranked portrait), click any tag to demote it, add your own tags, and cycle through the ranked alternates. Your feedback re-weights the evidence the model sees; the model keeps doing the judging.
  • Advanced art prompts. Next to the basic 8-emotion prompt set there's now an ✨ Advanced mode: the model reads the whole character card and writes a 12-16 look expression range in that character's voice — a guarded character gets "guarded amusement, one brow raised," not a generic smile — each annotated with its axis targets.
  • Quality of life: checking for updates is now a bright hero card at the top of Settings, and docked side panels leave a glowing pull-tab so they're easy to find and reopen.

v0.1.46

  • Dockable panels — let the story fill the screen. Both side panels now collapse away: click the slim handle on either edge and the sidebar or the chat panel folds shut, leaving the portrait and the conversation to dominate. Click again to bring it back; the app remembers your choice.
  • A much tidier chat panel. The right panel is now grouped into foldable sections — Cast, Sources, Style, Portrait, Scene — and all the explainer paragraphs moved behind little ⓘ buttons, so the panel is scannable instead of a wall of text. The sidebar footer also slimmed down to a compact icon row.

v0.1.45

  • Portrait picking, in the right order. The smart-portrait picker now weighs its criteria strictly ranked: emotion first, then outfit, then details — with pose dead last, so a matching pose can never drag in the wrong outfit. And the outfit has to make sense for the setting: no intimate wear at a public dinner unless the story has explicitly earned it (the venue calls for it, or it was deliberately agreed to in the story).

v0.1.44

  • Character stats: feelings that must be earned. Every chat now carries ten live levers for the character — arousal, affection, trust, anger, fear, joy, sadness, confidence, openness, energy — updated each reply and fed back into the prompt (“arousal 65% · anger 10% · …”). Moods shift gradually with cause instead of teleporting, intimacy has to be built, and a guarded character hides warmth instead of not having it. Visible as sliders in the chat dials — drag to steer.
  • Earned actions (anti-puppeting). A new per-chat toggle: when on, your messages can't act for the character — writing “she takes off her clothes” is treated as a wish, not an event. The character responds as themselves: comply, resist, deflect, or call it out, based on who they are and what the moment has actually earned. Off by default (director mode still works).

v0.1.43

  • Scene memory: the app now carries the scene, deliberately. After each reply, a small model call updates a structured record of the character's current state — outfit, hair, mood, pose, props, location — changing only what the story changed. It's injected into every turn (so she stays in the red dress), it's what the live portrait matches against (exact colors, not vibes), and it's visible and editable live in the chat dials. Toggle per chat; on by default.
  • Sharper portrait tags. “Analyze” now demands the exact color of every clothing item, the hair, and props — fixing black-vs-purple misses — and the whole index is now viewable and editable in the character editor, so a wrong tag is a two-second fix.

v0.1.42

  • Portraits move out of the save file. Older installs kept portrait images inside the app's small (~5 MB) save, which is what could fill it up. On first launch this build quietly moves them into proper files on disk — new uploads have worked this way since v0.1.37 — freeing the save for what it's for: your characters and chats. Deleting a character (or swapping out its images) now also cleans up its portrait files.

v0.1.41

  • Smart portraits: point at a folder, hit Analyze, done. Drop every portrait of a character — outfits, poses, expressions — into one folder and click Analyze in the character editor. The vision model tags each image once, and from then on the live portrait picks the best one automatically as the story moves: emotion, outfit, and pose in a single read. No typing descriptions, no sorting images into slots — that's the model's job.

v0.1.40

  • Portraits change outfits with the story. Give a character more than one look (a portrait set per outfit), add a short description to each — or let the vision model write it for you with “Describe looks” — and turn on Auto-switch in a chat. When the story has them change clothes (“she slips into the red dress”), the live portrait follows. The mood read also lands in one clean switch now, instead of a double-flicker.

v0.1.39

  • Smarter live portraits + working export. The live portrait now asks the model what the character is actually feeling — reading their personality and the subtext — instead of guessing from word choice, so a dry, guarded, or flirtatious character stops reading as “angry.” And the Export buttons (chat, story, tree, backup) now use a proper Save dialog, fixing the ones that silently did nothing.

v0.1.38

  • Under-the-hood cleanup. A maintenance release: every backend call now goes through one typed boundary instead of ~40 scattered spots (fewer places for bugs to hide), and cutting a release is a single command. No user-facing change.

v0.1.37

  • Portraits off your storage budget. Character portraits you upload now save to disk instead of into the app's small local-storage bucket — so you can illustrate as many characters and portrait sets as you like without filling it up. Existing portraits keep working and will move to disk in a following update.

v0.1.36

  • Engine reliability. Under the hood: the model server now reports a clear error if it can't start (e.g. a port conflict) instead of hanging, one bad file during knowledge ingestion can no longer take down the backend, and a chatty engine can't deadlock. Nothing changes in how you use it — it just fails gracefully where it used to get stuck.

v0.1.35

  • Your data is safer. Aphelion no longer silently loses work if local storage fills up — a failed save now warns you and offers a one-click backup instead of vanishing, and a corrupt save boots to a clean state instead of a blank screen. New Export / Import backup in Settings, and a recovery screen replaces any hard crash.

v0.1.34

  • Confirm before losing anything. Deleting a character, chat, Ask thread, story, dialogue tree, message, expert, or portrait set — or removing someone from a chat — now asks first, with a clean on-brand dialog instead of the old browser popup. Regenerating a dialogue tree only asks when it would overwrite an existing one.

v0.1.33

  • First-run fix. On a fresh install the startup splash no longer sits on top of the setup wizard waiting to load a model that isn’t downloaded yet. Setup now runs on its own, and the splash appears only once there’s a model to load. New users are also greeted with the welcome tour right after setup finishes.

v0.1.32

  • Seraphina, fully illustrated. The built-in example character now ships with a complete portrait set — all eight emotions — so the live portrait works out of the box. Open a chat with her, switch on the live portrait, and watch her expression follow the scene.

v0.1.31

  • Handier Settings + helpful tips. “Check for updates” now sits at the top of Settings, and the sidebar carries a rotating tip — updates, replaying the tour, portrait sets, and more — that changes every few minutes. Click it for the next one.

v0.1.30

  • Welcome tour. A first-run guided tour introduces the main features — the modes, characters & portrait sets, the routed Ask experts, and the privacy model — with a “Don’t show this again” checkbox. Replay it anytime from Quick tour in the sidebar footer.

v0.1.29

  • Portrait sets fix. You can now add any number of portrait sets reliably. A stray-click bug in the editor panel meant a third set could overwrite the second, and clicking in the emotion-slot area could spawn an extra set — both fixed.

v0.1.28

  • Named portrait sets. A character can now hold multiple named looks — "Hair up", "Hair down", whatever you like — each with its own full set of emotion portraits. Build and name them in the character editor, then pick the active look from a new dropdown in a chat's Tuning panel; the live portrait follows your choice. Existing portraits migrate automatically.

v0.1.27

  • More installer polish. The uninstaller now carries the Aphelion icon (it already inherited the eclipse header/sidebar), and the installer's prompts are written in Aphelion's voice. A first-run install is now branded end to end.

v0.1.26

  • Live portrait framing fix. The rounded portrait frame now hugs the image instead of leaving dark bars above and below it.

v0.1.25

  • Sharper portraits. Uploaded portraits are now stored at a higher resolution, so the Medium / Large live-portrait sizes look crisp instead of upscaled. Re-upload existing portraits to pick up the sharper version.

v0.1.24

  • Resizable live portraits. The reactive character portrait now has a Small / Medium / Large control in a chat's Tuning panel (the old fixed size is "Small").
  • Bigger startup splash. The loading-screen eclipse is much larger and front-and-center.
  • An Aphelion-branded installer. First-run setup now carries the eclipse, wordmark, and brand colours instead of the generic installer.

v0.1.23

  • On-brand startup mark. The eclipse on the loading splash now carries the full aphelion mark — the tilted orbital track with the lone planet at its far point — matching the refreshed logo.

v0.1.22

  • A startup splash. Loading the model into your GPU at launch can briefly hitch the interface — now a polished loading screen (the glowing eclipse, with the VRAM gauge filling as the model loads) covers that moment and fades away the instant the engine is ready. It's GPU-animated, so it stays smooth through the load.

v0.1.21

  • Steadier live portraits + expert emblems in the picker. The reactive character portrait now reads the tone of the finished reply and settles on one mood, instead of flickering word-by-word as it streams. And the Ask expert dropdown now shows each expert's eclipse emblem instead of cartoon emoji.

v0.1.20

  • Live stats in the menu bar. The engine status, model, a VRAM gauge, and the context window now sit as live chips on the right of the top bar (moved up out of the sidebar) — the data-rich command-bar look from the reference, with the numbers always in view.

v0.1.19

  • A refined main menu bar. The chat modes are now hero tabs in a single top bar alongside the brand, with clean line icons instead of cartoon emoji. The duplicate "Aphelion" logo is gone.

v0.1.18

  • A custom title bar — the gray Windows bar is gone. The app is now frameless with its own dark glass title bar. Drag to move, click the square to maximize, grab any edge or corner to resize.

v0.1.17

  • Expert emblems + a deep-space backdrop. Each built-in Ask expert now wears its own glowing eclipse emblem, shown as its reply avatar; and a subtle deep-space background sits behind the whole app, dimmed so text stays crisp.

v0.1.16

  • Live portraits (part 2) — they react now. Flip on Live portrait in a chat's Tuning panel and a large character portrait appears above the conversation, reading each reply's emotional tone and crossfading to the matching mood from the character's Living set. Collapsible, with neutral fallback.

v0.1.15

  • Living character portraits (part 1). Give a character a portrait per mood — happy, sad, angry, and more — in the new Living set. A built-in ✨ Art prompts button writes a ready-to-paste, consistency-engineered image-prompt set from the character's description.

v0.1.14

  • Character portraits. Give any character a real picture — upload your own (auto-resized so it won't bloat your save) or pick a built-in generic. It shows everywhere that character appears; no picture set falls back to the emoji tile, just like before.

v0.1.13

  • A fresh coat of paint (first pass). Custom glowing scrollbars (no more gray native bars), frosted-glass side panels, and soft focus glows on the active tab, send button, and inputs. More is coming — a custom dark title bar and refined icons next.

v0.1.12

  • Character chats scroll again. Fixed a layout bug where, in the character-chat view (the one with the cast/tuning panel), a long conversation pushed the message box and prompt bar off-screen. Ask mode was already fine.

v0.1.11

  • Stronger file safety. When you open a file to edit, the app can now only read or write within that file's own folder — enforced in the core, not just the interface. Together with v0.1.10's CSP, this closes the items from a security review.

v0.1.10

  • Hardened security. A strict Content-Security-Policy locks the app to its own code, so even malformed content (a model reply, a file) can't run injected scripts. No change to how anything works.

v0.1.9

  • Seamless updates. The in-app updater now shuts the model engine down before installing, so an update no longer fails on a locked engine file ("error opening file for writing"). One-click from here on.

v0.1.8

  • Smarter model fit. The model's context window is now sized to your VRAM, so smaller graphics cards don't run out of memory loading a model.
  • Clarity & polish. Plainer wording (what VRAM is, who it's for), more honest security language, and internal cleanup — from a round of outside feedback.

v0.1.7

  • One-click updates. "Check for updates" now downloads and installs the new version in-app with a progress bar, then relaunches — no browser, no running the installer, no uninstall prompt. Still manual and disclosed (it only reaches the internet when you press it), and every update is signature-verified.

v0.1.6

  • Fixed: a layout regression that could push the message box below the window so you couldn't scroll to it. The conversation now scrolls correctly and the prompt bar stays pinned at the bottom.

v0.1.5

  • Smart actions, now reliable. The control net recognizes folder / image / PDF and document requests instantly and deterministically — it no longer depends on the model returning structured output, so the one-click action actually appears (e.g. "check my folder for cat pictures" → Find images → PDF).

v0.1.4

  • Smart actions (control net) — in Ask mode, Aphelion recognizes when you're asking for a task (find images → PDF, generate a document, edit a file, answer from your folder) and offers a one-click action. Off / Quick / Full in Settings; nothing runs until you click.
  • Accessibility — full keyboard navigation with a visible focus ring, screen-reader labels and proper dialogs, a skip-to-content link, reduced-motion support (honors your OS setting), plus Reduce-motion and High-contrast toggles.

v0.1.3

  • Check for updates — a manual button in Settings. Aphelion stays fully offline until you press it, and it discloses before connecting: the app (never the model) contacts GitHub only to read the latest release version — nothing about you or your chats is sent.
  • Cleaner internals — the Rust backend was refactored into focused modules and the UI fully decoupled from the engine, with more tests. Same features, sturdier foundation.

v0.1.2

  • Knowledge folder — point it at a folder of PDFs or notes and it answers from them; your files stay on disk, only relevant passages are read.
  • Document generator — describe it and get a polished PDF (math & tables, via Typst) or a ready-to-use text/code file (HTML, Java, Python, Markdown…). Open & edit existing files too.
  • Vision (optional) — add a Gemma 3 vision model to describe images, ask about pictures you drag in, or scan a folder and build a PDF of the matches ("find the cats").
  • Model management — resumable background downloads with a status indicator, plus switch or delete models.
  • Quality of life — "continue" on an empty Enter in chat, drag-drop of images / text / PDF, and an image-describer expert for coders.

v0.1.1

  • Cross-platform builds — Windows, macOS (Apple Silicon), and Linux.
  • Penumbra rebrand, in-depth sampler controls with tooltips, shipped experts (Code, Raw Truth), and a first-run tutorial.

Full history on the GitHub releases page.

SUPPORT

Free — and staying that way.

Aphelion is free and open source. It's also unsigned — the only reason Windows shows that "unknown publisher" warning — because a code-signing certificate is a recurring monthly cost, and I haven't paid for one. If donations start coming in, that's the first thing they'll go toward. They also help keep Aphelion free: the more they offset what it costs to build and ship, the less chance I'd ever have to charge for it. No pressure — if it's useful to you, anything helps.

Venmo@drfaustus $penumbrapro
Cards accepted
Powered by PayPal

No pressure, ever — the app stays free either way. Donations just decide how fast the rough edges (like that signing warning) get smoothed out.