In Android, Adiantum is an alternative to AES-XTS for devices without AES instructions.
I cannot understand the reason for why such a convoluted scheme was chosen.
There are 128-bit ARX block ciphers that could have been a drop-in with XTS infrastructure already in place.
Or using a BLAKE quarter round on 64-bit processors, a 256-bit block cipher.