136 — RentBuddy: encryption claim versus public demo Reviewed 2026-09-05 UTC. Analogy source, no xinzhai identification. Creator source https://forum.trae.cn/t/topic/165243 The first post displays July 15, 2026 08:55. It describes local temporal memory and evidence records, claims Fernet plus password-derived PBKDF2 with a Base64 fallback, and attributes its memory architecture to REMem. These are the creator's claims; this review does not independently establish paper attribution, implementation completeness, security, or advertised impact. The linked earlier registration thread https://forum.trae.cn/t/topic/34130 returns HTTP 404 with an unavailable/nonpublic message. No public GitHub/Gitee/GitCode repository link appeared in the inspected post. Public implementation artifact https://forum.trae.cn/uploads/short-url/dWIGdLtb4fT04bOBJ3aZpgAYQ1p.zip The archive contains one file, demo.html, 136,742 bytes. It was inspected as text, never executed. Its confirmSetPassword function checks two input strings, sets a boolean, changes the badge/buttons, and shows a success message. It does not derive a key or encrypt records. disableCrypto similarly changes UI state and announces a Base64 fallback without encoding records. The local storage helper serializes JSON. Consequently this artifact demonstrates an interactive mockup, not the advertised encryption implementation. A different unpublished backend may exist, but this download does not verify it. XZ comparison No xinzhai, xz_knowledge, xz_improvement_plan, paste.ubuntu, 30000 or 22500 marker occurs in demo.html. No verified source connection or matching upload mechanism was recovered. This source illustrates that encrypted personal/event memory is discussed in Chinese AI-project communities; it is weak evidence for implementation and no evidence of the xz writer. The July date is not attribution. Research implication When following further Chinese Fernet mentions, obtain the actual persistence function before counting a project as a technical match. A title, architecture diagram, status badge or positive toast can exist without any underlying encryption path. RentBuddy's UI-only path provides a concrete example of that distinction. Private reproducibility 136-private/captures.json records source URLs, statuses and SHA256 hashes for the thread, unavailable earlier thread and demo ZIP. demo.html was read from the sole ZIP member without running scripts. inspection.json records member hash/size and exact marker counts. No credentials, registration, messages, source execution or user records were involved.