04 - iPhone and Apple Watch apps
Build the native iPhone app and its Apple Watch companion as presentation shells over crates/storage through crates/apple. The iPhone follows Gotcha's native tab-and-navigation design with Home remote activity and pull-to-refresh, hierarchical Passwords, a TOTP tab, and Preferences. It uses application-token HTTPS Git authentication, optional biometric access to the GPG key passphrase in iPhone Keychain, and QR transfer of ASCII-armored GPG keys. The Watch securely receives only explicitly shared TOTP entries and computes/displays codes through Rust. Swift must not own password-store, Git, GPG, OTP, secure-storage policy, or transfer-domain behavior, and neither app may launch external processes. Full CLI/TUI command parity, a command palette, and AutoFill are outside this milestone. The final issue prepares, notarizes, publishes, and verifies an install through AltStore PAL while documenting Apple's exclusion of watchOS apps from alternative-marketplace packages.