Third-Party Models, Runtimes, and Licenses
Phlox bundles inference runtimes and downloads a number of third-party models whose licenses require attribution. Models are not bundled in the app artifacts — they are downloaded on demand from HuggingFace on first use (the speaker embedding model below is the exception: it is fetched at build time from its GitHub release).
Large Language Models
Qwen3.5 (0.8B / 2B / 4B / 9B / 27B / 35B-A3B — Q4_K_M GGUF)
- Creator: Qwen Team at Alibaba Cloud; GGUF quantizations by Unsloth.
- Source: https://huggingface.co/unsloth/Qwen3.5-*-GGUF
- Quantization: Q4_K_M.
- Vision projector: each download also fetches an
mmproj-BF16.ggufmultimodal projector from the same repo, which enables vision when loaded into the LLM server. - License: Apache-2.0.
Qwen3-Embedding-0.6B (Q8_0 GGUF)
- Creator: Qwen Team at Alibaba Cloud.
- Source: https://huggingface.co/Qwen/Qwen3-Embedding-0.6B-GGUF
- License: Apache-2.0.
- Used by the embedding sidecar to power RAG.
Omi Med STT v1 (q8_0 GGUF)
- Creator: omi-health.
- Source: https://huggingface.co/omi-health/omi-med-stt-v1-gguf
- License: Creative Commons Attribution 4.0 International (CC-BY-4.0).
- Derivative of: nvidia/parakeet-tdt-0.6b-v2 (CC-BY-4.0).
- Used by the bundled transcription engine.
CAM++ Speaker Embedding (3D-Speaker, ONNX)
- Creator: Speech Lab, Alibaba Group (the 3D-Speaker project); ONNX export via the k2-fsa/sherpa-onnx speaker-recognition model release.
- Model:
3dspeaker_speech_campplus_sv_zh-cn_16k-common.onnx(192-dimensional embeddings). - Source: https://github.com/k2-fsa/sherpa-onnx/releases/tag/speaker-recongition-models
- License: Apache-2.0.
- Used by the live agent for best-effort speaker diarization during consultations. Fetched (pinned by SHA256) at build time rather than on first use.
Bundled Inference Runtimes (desktop)
parakeet.cpp (patched)
- Authors: Ettore Di Giacinto (@mudler), Richard Palethorpe; the LocalAI team.
- Source: https://github.com/mudler/parakeet.cpp
- License: MIT.
- The bundled
phlox-whisper-serveris parakeet.cpp with an in-house patch (parakeet-cpp-omi-adapter.patch) that adds the Omi Med STT adapter, derived from the MIT-licensed omi-med-stt-runtime reference.
llama.cpp
- Source: https://github.com/ggml-org/llama.cpp
- License: MIT.
- Phlox runs two llama.cpp server processes on desktop: one for the LLM (with optional vision projector) and one in
--embeddingmode for embeddings.
System Components
TEN VAD (WebAssembly)
- Creator: Agora / the TEN Framework project.
- Source: https://github.com/TEN-framework/ten-vad
- License: Apache-2.0 with additional conditions — notably a non-compete clause regarding Agora's offerings. Derivative works remain subject to these conditions; the upstream
NOTICESfile covers BSD-2/BSD-3-licensed derived code. - The VAD wasm artifacts are vendored into the app and run in a Web Worker to segment live-agent utterances on-device.
SQLCipher
- Source: https://github.com/sqlcipher/sqlcipher
- License: BSD-3-Clause with OpenSSL Exception.
- Provides encryption at rest for the SQLite database (both desktop and Docker).
Tesseract OCR (Docker only)
- Source: https://github.com/tesseract-ocr/tesseract
- License: Apache-2.0.
- Docker-only: Tesseract is installed in the Docker image (via
apt, used throughpytesseract). The desktop (macOS) and Flatpak (Linux) builds do not bundle Tesseract — the OCR fallback path is unavailable there, and document processing relies on text-layer extraction or vision instead.
Notable Dependencies
The following Apache-2.0 / copyleft dependencies are used by Phlox. Each retains its original license and copyright notices.
Python:
- openai — Apache-2.0
- mcp — MIT
- pytesseract — Apache-2.0 (Docker only)
- pypdf — BSD-3-Clause
- sherpa-onnx — Apache-2.0 (ONNX Runtime speech stack; runs the CAM++ speaker embedding model above on CPU)
JavaScript:
- pdfjs-dist — Apache-2.0
- @tauri-apps/api, @tauri-apps/plugin-http — Apache-2.0 / MIT
The complete list of Python dependencies with resolved licenses is in server/uv.lock. The complete list of JavaScript dependencies is in package-lock.json. All third-party packages retain their original licenses and copyright notices.