Updates
What we built and what we fixed, newest first.
2026-10-05
Limits against abuse
Added- A quiet human check (Cloudflare Turnstile) protects trip creation. Most people never see it; a network that starts many trips in a day is asked to pass it.
- Starting trips, asking the quick-note reader and opening checkout pages are now rate limited, so nobody can run up costs by flooding the service. Normal use is nowhere near the limits.
2026-10-05
Sign in with Google for the person who pays
Added- Whoever unlocks a trip signs in with Google first, so the payment can be matched to a person for support and refunds. Stripe checkout opens with that email filled in.
- Anyone can link a Google account under ⋯ → Your access, then use it on a new phone to get back into their name without the recovery code.
- New phone? On the home screen, sign in with Google and every trip where that account is linked comes back at once.
- The site now lives at tripsplit.sagasu.art.
2026-10-05
Data retention, terms and privacy
Added- Free trips are deleted two years after they end; trips that were unlocked are kept. A free trip shows the date it will be deleted on once it has ended.
- Receipt photos of unlocked trips are kept with the trip.
- New pages: terms of use, privacy policy, and how long we keep data.
2026-10-04
Change the trip end date
Added- The person who made the trip can move the end date from ⋯ → Trip dates. Before the trip starts it is free; once it has started, only an unlocked trip can change it (including the last two days); after the last day nobody can.
- Invites and the read-only day follow the new end date, so a trip that runs longer keeps working.
2026-10-04
Short invite codes, recovery codes and several phones per person
Added- Trips are joined with an 8-letter code (or a short link) instead of a long link. It works from the day the trip is made until 31 days after it ends.
- Everyone gets a recovery code when they join. A name that is already taken can only be reclaimed with its recovery code, so having the invite is no longer enough to take someone else's place.
- One person can use up to 3 phones. Add a phone with a 5-minute pairing code, see them under Your access, and sign one out.
- The person who made the trip can reset a friend's name with a one-time code if they lost their phone and their recovery code.
- Guessing codes is limited: a few wrong tries lock the name or address for 15 minutes.
- On the join screen, names that are already taken are kept apart from the free ones, so a new friend cannot pick someone else's name by mistake.
- The long trip key no longer travels in links or requests; a phone proves itself with its own key.
- Joining closes 31 days after the trip ends, matching the day the trip becomes read-only.
2026-10-02
Quick notes now read by Gemini
Added- A note that is ready to confirm now has a "Review and confirm" button right in the waiting list.
- Model set to gemini-3.8-flash; API key stays an encrypted secret in Cloudflare.
- The quick-note reader moved to Gemini (OpenAI-compatible endpoint, fixed-format function call).
- When the model service refuses a request, its own reason is shown on the waiting note, so a wrong key or model name is easy to spot.
- Gemini answered 400 to the forced-function request. The reader now falls back to a looser (still fixed-format) way of asking when a provider refuses the strict one.
- The reader uses the documented model id gemini-3.8-flash instead of the unconfirmed "latest" alias.
- Quick notes failed with 502 while the model service was misconfigured; the real reason was hidden.
2026-10-02
Clearer errors, who-you-are, and a DeepSeek reader
Added- The ledger shows which member this phone is ("Alex · you are owed") and a "Not you?" link in the ⋯ menu to pick your name again.
- Currency is now a dropdown (settlement currency first, "Other…" for any 3-letter code).
- Unlock prompt is a bottom sheet with separate wording for "free readings used up", "unlock" and "final bill".
- Quick notes are read by DeepSeek through the same fixed-format function call as before.
- This Updates page.
- A trip the server refuses (for example a name that is too long) no longer retries forever. The ledger explains it and lets you rename it, try again, or remove it from this phone.
- Trip names are limited to 60 characters and member names to 40 on the phone, so the server never has to say no.
- If the server has no reader configured, a quick note now says so instead of "Reading this failed".
- "Not signed in" and "trip not uploaded yet" are no longer mixed up in recognition and payment errors.
- Long amounts shrink to fit, and "1 expense" is singular.
- Landing page text now describes the typed quick note, the hero buttons are the same height, and the FAQ arrows are consistent.
2026-10-02
Small-phone redesign and routing fix
Added- Screens rebuilt for an iPhone SE (375×667): bigger tap targets, bottom sheets, one attention banner at a time, a quiet sync badge.
- Recording an expense for someone else: the payer defaults to you but can be changed.
- "Start a trip" used to show the home page again. Screens now live after the # (for example /app/#/new), which Cloudflare cannot rewrite.
2026-09-30
Payments, test switch and pluggable reader
Added- Payments switched to Stripe Checkout with a signed webhook.
- A UNLOCK_ALL test switch for trying the paid features.
- The quick-note reader can be any OpenAI-compatible model or Anthropic.
2026-09-29
First version
Added- Trip ledger that works offline, with sync, invite links and minimum-transfer settlement.
- Multi-currency conversion, four ways to split, exchange records, final bill with share link and CSV.
- Daily exchange-rate job and the landing pages.