Trip Split

Updates

What we built and what we fixed, newest first.

2026-10-05

Limits against abuse

Added
  • A quiet human check (Cloudflare Turnstile) protects trip creation. Most people never see it; a network that starts many trips in a day is asked to pass it.
  • Starting trips, asking the quick-note reader and opening checkout pages are now rate limited, so nobody can run up costs by flooding the service. Normal use is nowhere near the limits.

2026-10-05

Sign in with Google for the person who pays

Added
  • Whoever unlocks a trip signs in with Google first, so the payment can be matched to a person for support and refunds. Stripe checkout opens with that email filled in.
  • Anyone can link a Google account under ⋯ → Your access, then use it on a new phone to get back into their name without the recovery code.
  • New phone? On the home screen, sign in with Google and every trip where that account is linked comes back at once.
  • The site now lives at tripsplit.sagasu.art.

2026-10-05

Data retention, terms and privacy

Added
  • Free trips are deleted two years after they end; trips that were unlocked are kept. A free trip shows the date it will be deleted on once it has ended.
  • Receipt photos of unlocked trips are kept with the trip.
  • New pages: terms of use, privacy policy, and how long we keep data.

2026-10-04

Change the trip end date

Added
  • The person who made the trip can move the end date from ⋯ → Trip dates. Before the trip starts it is free; once it has started, only an unlocked trip can change it (including the last two days); after the last day nobody can.
  • Invites and the read-only day follow the new end date, so a trip that runs longer keeps working.

2026-10-04

Short invite codes, recovery codes and several phones per person

Added
  • Trips are joined with an 8-letter code (or a short link) instead of a long link. It works from the day the trip is made until 31 days after it ends.
  • Everyone gets a recovery code when they join. A name that is already taken can only be reclaimed with its recovery code, so having the invite is no longer enough to take someone else's place.
  • One person can use up to 3 phones. Add a phone with a 5-minute pairing code, see them under Your access, and sign one out.
  • The person who made the trip can reset a friend's name with a one-time code if they lost their phone and their recovery code.
  • Guessing codes is limited: a few wrong tries lock the name or address for 15 minutes.
Fixed
  • On the join screen, names that are already taken are kept apart from the free ones, so a new friend cannot pick someone else's name by mistake.
  • The long trip key no longer travels in links or requests; a phone proves itself with its own key.
  • Joining closes 31 days after the trip ends, matching the day the trip becomes read-only.

2026-10-02

Quick notes now read by Gemini

Added
  • A note that is ready to confirm now has a "Review and confirm" button right in the waiting list.
  • Model set to gemini-3.8-flash; API key stays an encrypted secret in Cloudflare.
  • The quick-note reader moved to Gemini (OpenAI-compatible endpoint, fixed-format function call).
  • When the model service refuses a request, its own reason is shown on the waiting note, so a wrong key or model name is easy to spot.
Fixed
  • Gemini answered 400 to the forced-function request. The reader now falls back to a looser (still fixed-format) way of asking when a provider refuses the strict one.
  • The reader uses the documented model id gemini-3.8-flash instead of the unconfirmed "latest" alias.
  • Quick notes failed with 502 while the model service was misconfigured; the real reason was hidden.

2026-10-02

Clearer errors, who-you-are, and a DeepSeek reader

Added
  • The ledger shows which member this phone is ("Alex · you are owed") and a "Not you?" link in the ⋯ menu to pick your name again.
  • Currency is now a dropdown (settlement currency first, "Other…" for any 3-letter code).
  • Unlock prompt is a bottom sheet with separate wording for "free readings used up", "unlock" and "final bill".
  • Quick notes are read by DeepSeek through the same fixed-format function call as before.
  • This Updates page.
Fixed
  • A trip the server refuses (for example a name that is too long) no longer retries forever. The ledger explains it and lets you rename it, try again, or remove it from this phone.
  • Trip names are limited to 60 characters and member names to 40 on the phone, so the server never has to say no.
  • If the server has no reader configured, a quick note now says so instead of "Reading this failed".
  • "Not signed in" and "trip not uploaded yet" are no longer mixed up in recognition and payment errors.
  • Long amounts shrink to fit, and "1 expense" is singular.
  • Landing page text now describes the typed quick note, the hero buttons are the same height, and the FAQ arrows are consistent.

2026-10-02

Small-phone redesign and routing fix

Added
  • Screens rebuilt for an iPhone SE (375×667): bigger tap targets, bottom sheets, one attention banner at a time, a quiet sync badge.
  • Recording an expense for someone else: the payer defaults to you but can be changed.
Fixed
  • "Start a trip" used to show the home page again. Screens now live after the # (for example /app/#/new), which Cloudflare cannot rewrite.

2026-09-30

Payments, test switch and pluggable reader

Added
  • Payments switched to Stripe Checkout with a signed webhook.
  • A UNLOCK_ALL test switch for trying the paid features.
  • The quick-note reader can be any OpenAI-compatible model or Anthropic.

2026-09-29

First version

Added
  • Trip ledger that works offline, with sync, invite links and minimum-transfer settlement.
  • Multi-currency conversion, four ways to split, exchange records, final bill with share link and CSV.
  • Daily exchange-rate job and the landing pages.