Receiver SDK

Receive a signal. Resolve an intent.

Native Android and iOS microphone capture with a local ggwave ultrasonic decoder. The Flutter package contains no publisher secret and leaves purpose-specific consent and reporting to the host application.

XR

Ultrasound included

Decode Xaere protocols 3, 4 and 5 locally. Raw microphone samples never leave the device.

Cryptographically verified

Core signs each short-lived resolution and the SDK verifies Ed25519 locally before exposing an intent.

No mobile secret

API keys and Audience HMAC credentials stay on integrator backends. Consent-bound reporting is optional and off by default.

Current release

Developer preview 0.3.28 revision 3.

Physical speaker-to-microphone validation on representative Android and iOS phones remains required before a stable release.

Resolution security

Audience proofs are accepted only for Core's five-minute lifetime and two-minute clock-skew bound. Failed Core resolution is exposed through a closed, host-safe enum: unavailable (unknown or revoked), expired, rate-limited, temporarily unavailable or rejected. Only temporary states are retryable, and Core or gateway messages are never copied into host UI. Successful Core resolution and Ed25519 key-discovery responses must use JSON media types before the SDK parses them. The SDK rejects altered, expired, unsigned or key-mismatched Core resolutions.

Consent and lifecycle

Audience measurement, advertising and personalization are separate host privacy choices; all default off, and the current SDK acts only on Audience measurement. Audience consent is now rejected until an integrator backend reporter is configured; host interfaces can use the explicit availability flag instead of presenting an ineffective measurement switch. Advertising and personalization cannot start capture, resolution, reporting or profiling. Closing a Flutter receiver session permanently disposes its owned native transport and prevents hidden reuse after the host widget is destroyed.

Toolchain and privacy manifest

The independently consumable clean source archive requires Flutter 3.47 and Dart 3.13, enforces complete public API documentation, uses AGP 9 built-in Kotlin 2.3.20 without applying the legacy Kotlin Android plugin, passed all source tests and analyses after extraction without monorepo build state, then built the Android ARM64 example. The iOS CocoaPods and Swift Package Manager distributions compile the same reviewed Swift, Objective-C++ and ggwave sources and bundle the same privacy manifest declaring no tracking, collected data or required-reason API use; microphone samples remain on-device.

Runtime evidence

A byte-exact Ed25519 fixture is verified independently by Core and Dart, pinning the same canonical resolution bytes and signature. Android observes the active recording configuration and fails capture closed when the system silences it or changes the microphone route, matching the explicit-restart behavior enforced on iOS. An installed Android x86_64 integration test also crossed Dart, Flutter, Kotlin, JNI and the bundled ggwave codec and validated the closed identifier-free diagnostic contract. Encrypted Audience queue flushes are serialized so lifecycle and host retries cannot deliver the same stored snapshot concurrently; the stable per-event idempotency key remains an independent server safeguard. The SDK revalidates the closed event-bound proof before and after encrypted retry persistence, and requires the closed Audience acknowledgement before removing a queued event.

Offline release authenticity

The immutable revision manifest is signed with a dedicated Ed25519 release key kept outside the VPS. Download the signature, public key and dependency-free verifier to authenticate the exact manifest and archive bytes offline. A digest copied from this same website alone is not treated as an independent authenticity proof.

Xaere-specific code remains a proprietary preview; vendored ggwave and Reed-Solomon components retain their MIT licences.

SHA-256: ab04fd2b5632e81d13c72f527ea7e4f77e0ade5258fed4834b27d3f0fcd1426d