Pendant Rig drives a Limitless Pendant whose cloud service ended and a PLAUD NotePin whose app deletes what it syncs — entirely from one Windows PC. BLE capture lands in append-only journals, a fail-closed codec decodes it, and faster-whisper transcribes on the local GPU at roughly 25× realtime. No cloud, no accounts.

The Limitless Pendant’s cloud no longer exists: Meta acquired Limitless, the UK service ended on 5 December 2025, and accounts in unsupported regions were deleted on 19 December 2025. The hardware still records; the upload destination vanished.
The PLAUD NotePin takes the other road to the same cliff: a required app account whose sync deletes recordings from the device, 300 free minutes a month, then $17.99–$29.99/month — on hardware that sells at $159 (GBP 125).
The rig’s premise: replace both vendors with one Windows PC. Wear the pendant or pocket the NotePin; when Bluetooth sees a device, the rig syncs by itself — each device at most every 60 minutes, plus a 03:00 sweep — pages land in the journal first, and only after a verified flush does the ACK free device flash. The GPU transcribes and files audio and transcript under the day, playable from the web app.
Proven moments: a spoken “baseline test, orange bicycle, 42” came back verbatim, and the first drain pulled 3,381 pages — about 86 minutes of audio — off a pendant whose cloud no longer existed. The rig has run nightly since 25 September 2026.
This is the rig’s real UI: a dark, terminal-adjacent panel on FastAPI and vanilla JS, served at 127.0.0.1:8737 to this PC only. A tour of what an operator actually sees.

Every paired device reports to one row of cards: battery level, charging state, pairing status, free space and the last successful sync. A pendant and a NotePin sit side by side — the NotePin added by nothing more than its serial number, with no vendor account anywhere.

When Bluetooth sees a device, the run starts without anyone asking: Copy, Prepare, Transcribe, Save, live from the server’s event stream. Each device syncs at most every 60 minutes, with a 03:00 sweep for anything the day missed.

Recordings file under their day as compiled audio with transcripts alongside. Click any line and playback seeks to that moment, streamed over HTTP Range requests — nothing leaves the PC. A spoken “baseline test, orange bicycle, 42” came back verbatim.

Freeing device flash is the rig’s one irreversible action, so it is gated hardest. “Free space now” ACKs only up to the contiguous watermark already flushed to disk and verified; a gap halts the delete at gap−1, and a flush failure rolls back instead of ACKing.

One page holds the operating dials: sync cadence, whether the ACK gate runs unattended, whether transcription follows each sync, and a per-device link-health row for the last 24 hours. Weak signal shows up as data here — the rig keeps receipts, seven consecutive failures at −92 dBm among them.

The rig can show its own wiring: an ACK sequence diagram rendered from the protocol notes, or a pendant diag readout from the CLI. The same facts the tests assert, made visible to whoever is watching the drain — no second documentation drifting out of date.
The rules a user never sees but always depends on: deletion that carries proof, decode that fails closed, and a journal that stays the single source of truth.
An ACK permanently deletes the pendant’s stored pages, so it is sent only after an fsync barrier and only up to the verified contiguous watermark. Fifteen fault-injection tests attack exactly this rule.
A PLAUD session is complete only when the journaled bytes size-match the device, the session identity agrees across every record, and a disk replay reproduces the session — with an interpreted cmd-117 checksum on top.
Decode is a replay from raw CRC32-framed journal bytes. Audio pages that yield zero frames are never surfaced and never ACKed; zero-frame marker pages still advance the watermark, exactly as the protocol specifies.
faster-whisper runs as a subprocess on the GPU, so a native crash never takes the GUI down; any CUDA failure falls back to CPU int8 and one --cpu re-run.
Two undocumented BLE protocols, one rig. The PLAUD transmit surface is an explicit allowlist that blocks 112 of 114 commands, so nothing outside capture-and-read can ever be sent.
A cross-process lock means every journal user — GUI, CLI, scheduled task — queues instead of racing; hidden scheduled tasks restart the rig every 10 minutes; a redeploy lands only while idle and from a clean tree.
Six stages take a whisper in a room to a searchable transcript, and exactly one of them is irreversible — so that one is gated hardest.
--cpu re-run.# pendant/drain/engine.py — the device deletes what an ACK covers,
# so an ACK may only target the journal's contiguous FLUSHED watermark.
def _ack_watermark(self) -> int | None:
watermark = self._anchored_watermark() # contiguous flushed prefix
if watermark is None or self._stream_low is None:
return None # a gap below the run: nothing ACKable
watermark = min(watermark, self._stream_high) # never ahead of the stream
# _send_ack: fsync barrier first, then ACK the watermark — never beyond it,
# never twice. A flush failure rolls back: nothing is acked, nothing is lost.Capture, decode, transcription and the web app all run on the machine they serve: the same box that wears the RTX 3050.
There is no public URL, and that is the point: the rig serves one Windows PC at 127.0.0.1:8737, keeps its journals on that machine, and answers to no vendor. Everything on this page — capture, ACK gates, transcripts — runs from that box today.
The Pendant Rig replaced two vendors' clouds with one PC, a written protocol and a deletion rule enforced in code. If you have orphaned hardware or a fragile data pipeline that needs the same treatment, let's talk it through.