# BuddiesIRL Changelog

This file records every published BuddiesIRL release and all meaningful work waiting for the next release.

## How this file is maintained

- New work is recorded under **Unreleased** as it is completed.
- When a release is published, its Unreleased notes move into a dated **Version N** section.
- Release numbers match the saved hosting version. The public footer uses the matching beta build number (for example, Version 56 is Beta v0.5.56).
- Published entries are permanent. Later corrections are added as new notes rather than silently rewriting history.
- Versions 1 through current below were reconstructed from saved hosting releases and their exact Git commits on 2026-07-17. Future entries will include fuller change details as the work happens.

## Unreleased

## Version 65 - 2026-07-23

- Turned “Also add this public Place to Nearby” on by default when creating a Place inside a private Circle, while preserving an easy opt-out for homes and private meeting spots.
- Made “Add + Nearby” the first recommendation action for private Circles and kept an explicit Circle-only alternative.

## Version 64 - 2026-07-22

- Added an explicit Google Maps matching step when creating or editing a Place, letting members choose the official listing instead of relying on typed-name matching.
- Gave Google-matched Places one shared sitewide identity so live attendance counts and canonical names remain connected across Circles.
- Changed private-Circle Place sharing into a clear “Also add this public Place to Nearby” option while keeping homes and private meeting spots private.
- Added separate “Add to Circle” and “Add + Nearby” actions to Google place recommendations.
- Prevented duplicate public Place cards in Nearby when multiple Circles save the same Google Maps location.
- Required every Place published to Nearby to be connected to Google Maps and expanded live Google details across the full Nearby ZIP radius.
- Added migration 0029 to upgrade existing Google-connected Places and check-ins to their shared sitewide identity.

## Version 63 - 2026-07-21

- Required the expanded welcome instructions to appear once for every existing and new member on their next app open, remaining available until that member finishes or dismisses the tour.

## Version 62 - 2026-07-21

- Reworded the Places & People welcome-tour headline to use natural comma punctuation instead of em dashes.
- Reworded the Nearby safety reminder with comma punctuation and changed the first-buddy checklist step into a clear Circle invite-code action.
- Made the Circle invitation show a prominent copyable invite code alongside its QR code and shareable link.
- Expanded Nearby from one exact ZIP to a local cluster of surrounding ZIP codes within about 10 miles, covering public Places, Google suggestions, live people, and Beacon refreshes across ZIP borders.
- Refined the v0.62 homepage with optimistic empty states, a compact Circle momentum strip, shorter hero language, and a clearly emphasized primary Beacon action.
- Reworked onboarding language around automatic Nearby access, private communities, consent-based Place sharing, and the distinction between coordination and location tracking.
- Added a mission-focused onboarding close built around “Life happens together,” putting the phone away, and enjoying the real-world moment.

## Version 61 - 2026-07-21

- Corrected production schema readiness so an existing database automatically completes pending application migrations and updates its health revision after deployment.

## Version 60 - 2026-07-21

- Moved the persistent First IRL Moment checklist onto the main Home view, where it remains until every milestone is complete or the member dismisses it.
- Corrected onboarding completion so a Nearby ZIP space never counts as creating or joining a private Circle, and stale legacy completion is repaired automatically.
- Added a five-step first-use welcome tour covering BuddiesIRL's purpose, private Circles versus Nearby, Plans versus Beacons, Places and privacy, and quiet-by-default notifications.
- Added controls to dismiss or restore the homepage checklist and replay the welcome tour from Account settings.
- Added durable per-account onboarding tutorial and checklist preferences with migration 0028; existing accounts are not forced through the new first-use tutorial.
- Moved the “Life happens together” banner, personalized Circle introduction, and connected-member summary from More to the top of Home.
- Linked the footer’s beta version number to the public changelog and made every build publish the maintained `CHANGELOG.md` automatically.
- Promoted the footer into the shared site layout so it now appears on Home, authentication and policy pages, every app section, and every Control Room or Brand Studio page.

## Version 59 - 2026-07-21

- Added an explicit, fail-closed staging-only administrator MFA bypass so private testing does not require a second authenticator enrollment. Production continues to require administrator 2FA.
- Redesigned the signed-in homepage as a compact Circle front porch focused on upcoming Plans, live Beacons, and one fast Beacon action.
- Replaced the long dashboard stack with Home, Plans, People, Places, and More navigation so secondary tools remain available without overwhelming the homepage.
- Moved advanced Beacon audience, arrival, invitation, and duration controls behind an optional disclosure while keeping the primary choices immediately accessible.
- Replaced permanent Circle deletion with recoverable archiving that stops joins, Beacons, Plans, and notifications while preserving history and administrative visibility.
- Let every member, including the owner, leave a private Circle; ownership now passes first to a leader, then a moderator, then the longest-standing active member, and an empty Circle archives automatically.
- Added Super Admin Circle membership management with searchable bulk add/remove controls, optional one-time assignment notices, assignment-source records, and private audit entries.
- Added opt-out private participation-history capture and deletion controls for a future Memory Lane feature, included this history in personal data exports, and documented it in the Privacy Policy.
- Added dormant database foundations for future weekly traditions, weather context, and anonymous place/activity trend intelligence without exposing unfinished features to users.
- Quieted routine Beacon and new-Plan push notifications while retaining ride requests, SOS, overdue Safety Checks, important Plan changes, and direct notices when someone joins an organizer's Plan.
- Kept Circle content synchronized silently when notification preferences suppress a visible alert.
- Added archived Circle classifications, membership status/source metadata, and database migration 0027 for the v0.59 lifecycle and future-feature foundations.
- Improved keyboard and screen-reader support with a skip link, visible focus treatment, polite status announcements, reduced-motion handling, and larger mobile interaction targets.
- Added permanent product-principles and v0.59 acceptance documents so the no-dark-pattern commitments and real-world success tests remain part of future development and release review.

## Version 58 - 2026-07-17

### Added

- Added a durable five-step first-use checklist covering profiles, tested notifications, Circle membership, inviting a buddy, and sharing a first Beacon.
- Added server-enforced Super Admin feature switches for Nearby, Google place suggestions, SOS buddy alerts, push notifications, and new registrations.
- Added a minimal public health endpoint for uptime monitors plus hourly operational email alerts when recent server or delivery errors need attention.
- Added a non-destructive encrypted-backup recovery rehearsal that verifies the current schema, every expected table, unique identities, and Circle relationships.
- Added privacy-friendly 30-day product signals for the major onboarding and real-life coordination steps without session recording or message-content collection.
- Added automatic app build, browser, page, and request-ID diagnostics to beta feedback.
- Added a formal safety and moderation runbook for immediate danger, harassment, underage accounts, SOS misuse, data requests, and incident closeout.
- Added `hello@buddiesirl.app` as the public support and reply address throughout the app and configuration templates.

### Changed

- Expanded System Health with recovery-rehearsal status, operational-email readiness, staging readiness, product signals, and one-click tests.
- Expanded Site Settings into an operational control panel that can pause major services without a new deployment.
- Updated the Privacy Policy for limited product-event measurement and feedback diagnostics.
- Added migration 0026 for onboarding milestones, product signals, feedback diagnostics, recovery-rehearsal results, and feature-switch defaults.

### Operations note

- Transactional and operational email code is ready, but live delivery still requires a verified sender domain and provider key.
- A private staging project with isolated database and object storage is provisioned for test accounts; live production data must never be copied into it.

## Version 57 - 2026-07-17

### Added

- Added encrypted daily recovery snapshots containing the database and private copies of uploaded media, with seven-daily/four-weekly retention and checksum/decryption validation.
- Added safe hourly maintenance for expired sessions, recovery tokens, inactive Beacons, old activity, delivery records, rate limits, orphaned relationships, and abandoned media.
- Added tracked push-notification delivery states, automatic retries, failure reporting, and cleanup of unreachable subscriptions.
- Added authenticator-app MFA and a one-time recovery code for every Super Admin and Design Admin account.
- Expanded System Health with schema, integrity, maintenance, backup, configuration, session, storage, and 24-hour push-delivery status.
- Added request idempotency protection for Beacons and SOS alerts.

### Security

- Added same-origin enforcement for every write request, a Content Security Policy, anti-framing, content-type, referrer, permissions, request-ID, and timing headers.
- Added sanitized server-error capture with user-facing request IDs.
- Added production-only encryption keys for administrator MFA and disaster-recovery snapshots.
- Updated the hosting and build dependencies and cleared all known package-audit vulnerabilities without forced breaking downgrades.

### Data and quality

- Added migration 0025 and an enforced schema-version check, making the migration history the upgrade source of truth while retaining the existing empty-database bootstrap.
- Added strict TypeScript checks, a practical lint gate, migration continuity validation, reliability regression tests, and a live HTTPS smoke-test script.
- Added operations, staging, restore-validation, rollback, incident, backup-retention, and secret-rotation runbooks.
- Renamed the internal package from the generic starter name to `buddiesirl`.
- Established this changelog and automated protection against footer/release-number drift.

### Operations note

- System Health now explicitly flags transactional email until an email-provider key and sender are configured; it no longer remains an invisible production configuration gap.

## Version 56 - 2026-07-17

### Changed

- Completed the BuddiesIRL naming cleanup across active project files. (`f791940`)

## Version 55 - 2026-07-17

### Fixed

- Fixed Brand Studio loading for Design Admin accounts. (`c0bde80`)

## Version 54 - 2026-07-17

### Security

- Restricted Design Admin accounts to Brand Studio instead of the full administration area. (`3166779`)

## Version 53 - 2026-07-17

### Added

- Added the revocable Design Admin role and Brand Studio. (`c8b8a6f`)

## Version 52 - 2026-07-16

### Added

- Added private birthday collection during signup for adult eligibility and future birthday features. (`30c235f`)

## Version 51 - 2026-07-16

### Changed

- Updated the public footer to identify Beta version 50. (`f3bb3fb`)

## Version 50 - 2026-07-16

### Added

- Added timed Nearby visits and support for multiple Circle leaders. (`b002228`)

## Version 49 - 2026-07-16

### Changed

- Matched Beacons to saved Place identities instead of relying only on typed place names. (`8bfe871`)

## Version 48 - 2026-07-15

### Fixed

- Repaired duplicate Circle memberships and added protection against future duplicates. (`f81a043`)

## Version 47 - 2026-07-15

### Changed

- Replaced the ambiguous initials mark with a gathering-focused BuddiesIRL mark. (`1e3ed97`)

## Version 46 - 2026-07-15

### Added

- Added lightweight responses to outings. (`4633a1f`)

## Version 45 - 2026-07-15

### Added

- Added social momentum tools and temporary Nearby features. (`c357c93`)

## Version 44 - 2026-07-14

### Fixed

- Stabilized Nearby notifications and improved the field-testing experience. (`6068bf2`)

## Version 43 - 2026-07-14

### Changed

- Clarified how Place suggestions adapt to a Circle's activity. (`64d2b67`)

## Version 42 - 2026-07-14

### Added

- Added activity-specific Beacon wording and Circle deletion for authorized leaders. (`00090aa`)

## Version 41 - 2026-07-14

### Added

- Launched the BuddiesIRL V3 activity-based Circle model. (`af4e088`)

## Version 40 - 2026-07-14

### Fixed

- Cleared stale recommendation rate-limit locks after limits were increased. (`faa7829`)

## Version 39 - 2026-07-14

### Operations

- Raised the Google Places beta request limits. (`b3ff939`)

## Version 38 - 2026-07-14

### Performance

- Improved session startup speed and indexed Circle activity. (`5fd9464`)

## Version 37 - 2026-07-14

### Changed

- Condensed Circle activity history into a manageable recent-activity view. (`879009b`)

## Version 36 - 2026-07-14

### Performance

- Changed Google Place recommendations to load on demand. (`c10c6ef`)

## Version 35 - 2026-07-14

### Changed

- Reduced Places requests and began displaying the beta version in the site footer. (`ec24157`)

## Version 34 - 2026-07-14

### Added

- Added Google Place details and ZIP codes for Circles. (`4831bce`)

## Version 33 - 2026-07-14

### Added

- Added Google Places recommendations. (`98f4623`)

## Version 32 - 2026-07-14

### Added

- Added safe Place deletion. (`db16d77`)

## Version 31 - 2026-07-14

### Added

- Added a ZIP-based directory for public Places. (`c0513c7`)

## Version 30 - 2026-07-14

### Added

- Added anonymous, sitewide live counts to Place cards. (`82bfb68`)

## Version 29 - 2026-07-14

### Added

- Added advanced super-admin controls for user roles, removal, and timed suspension. (`0dcce17`)

## Version 28 - 2026-07-14

### Added

- Added a sitewide Circle activity view for super administrators. (`e899783`)

## Version 27 - 2026-07-14

### Changed

- Polished the ride-matching and safety-check action cards. (`2527291`)

## Version 26 - 2026-07-14

### Changed

- Polished the safety-check composer. (`97b1d34`)

## Version 25 - 2026-07-14

### Added

- Replaced the crowded admin popup with a standalone administration control room. (`4e7710f`)

## Version 24 - 2026-07-13

### Changed

- Added a clearer startup progress experience. (`59d1a08`)

## Version 23 - 2026-07-13

### Fixed

- Prevented startup loading dead ends. (`7e940b4`)

## Version 22 - 2026-07-13

### Added

- Added buddy safety checks and ride matching. (`84de6b3`)

## Version 21 - 2026-07-13

### Changed

- Moved quiet mode into the Staying In flow. (`c5574c3`)

## Version 20 - 2026-07-13

### Added

- Added Place photos and fully clickable Place cards. (`108a431`)

## Version 19 - 2026-07-13

### Fixed

- Made startup honor the member's saved default Circle. (`c36ac4a`)

## Version 18 - 2026-07-13

### Added

- Shipped Complete Plans and Useful Places. (`7534eb2`)

## Version 17 - 2026-07-13

### Added

- Added the first Circle identity and visual customization release. (`35e1a82`)

## Version 16 - 2026-07-13

### Added

- Added a persistent default Circle preference. (`38034bf`)

## Version 15 - 2026-07-13

### Performance

- Expanded quiet mode and reduced unnecessary refresh work. (`76ea0bd`)

## Version 14 - 2026-07-13

### Added

- Added temporary notification muting when selecting Staying In. (`78d3acb`)

## Version 13 - 2026-07-13

### Fixed

- Made the full plan option cards clickable. (`9d35d53`)

## Version 12 - 2026-07-13

### Fixed

- Fixed feedback form submission. (`a723428`)

## Version 11 - 2026-07-13

### Added

- Added beta-readiness safeguards and support tools. (`9696df5`)

## Version 10 - 2026-07-13

### Security

- Removed the completed temporary administrator-promotion path. (`24b9461`)

## Version 9 - 2026-07-13

### Security

- Promoted the existing Nick account through a one-time controlled migration. (`923103b`)

## Version 8 - 2026-07-13

### Security

- Locked the super-admin role after bootstrap. (`02a28c1`)

## Version 7 - 2026-07-13

### Changed

- Tuned secure password hashing for the beta hosting environment. (`9ac7273`)

## Version 6 - 2026-07-13

### Security

- Adopted hosting-compatible secure password hashing. (`cec0844`)

## Version 5 - 2026-07-13

### Added

- Added protected signup diagnostics. (`d3842c0`)

## Version 4 - 2026-07-13

### Fixed

- Added a clear error when password setup fails. (`285c3bf`)

## Version 3 - 2026-07-13

### Fixed

- Fixed hosted account signup and runtime settings. (`da5f873`)

## Version 2 - 2026-07-13

### Security

- Secured the super-admin bootstrap process. (`0ab8a65`)

## Version 1 - 2026-07-13

### Added

- Prepared the initial public beta release. (`3b4da54`)
