v1.8.49

WhosZoo Update Notes

The version number at the bottom of Settings now brings you here.

Your memory files are untouched, and you will not be asked to re-enter anything. Hard-refresh your browser (Ctrl+Shift+R on Windows, Cmd+Shift+R on Mac) to load the new version.
Improved
Improved The version number at the bottom of Settings is now a link to this page. Nothing inside the app pointed at these notes before — the only way here was the setup wizard’s final screen, which you see once and then never again. So an update would land and there was no way, from inside the app, to find out what had changed in it.
Improved The app now calls itself WhosZoo. Same product, shorter name — the one the website and the address bar have always used. “Who’s who in your zoo” stays as the phrase that explains it. Older screens still carry the longer spelling in places; those will catch up.
The code became open source here
On 26 September 2026 the Worker and the frontend — the parts that run in your own Cloudflare account — were published under the MIT licence at github.com/hansreno/whoszoo. You can read every line that handles your memory, and deploy it yourself without paying anyone. The setup wizard that does it for you is still a paid product. Releases from v1.8.49 onward are public code; everything below this line shipped closed.
Previous release (v1.8.48)
Fixed On a phone or tablet, Enter now starts a new line instead of sending. Tap the blue arrow to send, the way every other chat app works. Previously Enter always sent the message, and since a phone keyboard has no practical Shift key, there was no way at all to type a second line — which made journalling or pasting anything structured impossible on the device this app is built for first. On a computer nothing changes: Enter still sends, Shift+Enter still makes a new line.
Previous release (v1.8.47)
Fixed On a computer, Recommend to a friend now simply copies the message. It was opening Windows’ share dialog instead — which, for a message with no separate link attached, hides “Copy link” and offers Teams, Outlook and Copilot rather than anything useful for texting someone. Chrome on the desktop supports the same share feature phones use, so the app was handing the job to it there too. Now it copies straight to your clipboard and tells you it did. On a phone nothing changes: you still get the normal share sheet, one tap into Messages or WhatsApp.
Previous release (v1.8.46)
Improved The recommend-to-a-friend message is shorter, and the link now sits on its own line. It read as a paragraph with a link trailing off the end — which in a text thread looks like something forwarded rather than something a person sent you. It is now one sentence, a blank line, then the link. It also no longer describes WhosWhoZoo as being only for remembering people: you can tell it anything worth keeping, and the message says so.

The layout is composed by the app rather than handed to your phone’s share sheet, so it arrives the same way regardless of which app you send it through. The trade is that some apps will no longer draw a preview card for the link.
Previous release (v1.8.45)
New Settings now has “Recommend WhosWhoZoo to a friend.” Tap it and your phone’s normal share sheet opens with a short message ready to send; on a computer it copies to your clipboard instead. It always points at whoszoo.app, the product page — never at your own app. That distinction is built into the code, not just the wording: the share button cannot reach your Worker address at all. Worth knowing, because until now the only thing you could hand someone was whatever was in your address bar, which is the login page to your own memory.
Previous release (v1.8.45), continued
Improved The sign-in screen no longer says your notes are “never visible to anyone else.” It now says they are never used to train AI and never sent to us, which is both true and the part that actually matters. The old wording was the last unqualified claim left anywhere, and it ignored the same detail the rest of this month’s corrections covered: the Cloudflare API token from setup can read your memory files directly, which is why we recommend deleting it once you are installed.
Previous release (v1.8.44)
Improved “We structurally cannot read what you write” and “technically impossible for us to read your data” now say what is precisely true. Both claims held for your notes — there is no WhosWhoZoo memory database, and your files sit in a Cloudflare account we hold no credentials to. But stated as unqualified absolutes they collided with our own privacy page, which says plainly that the setup relay can technically see your keys while forwarding them, and that we keep one install record. The homepage now makes the scope explicit and links to the detail instead of asking you to take a superlative on faith.
Fixed “Nothing is ever written to a WhosWhoZoo database, not even for a moment” was false. Your notes never are — that part stands, and Hans still could not produce them under subpoena. But one line per install is written: your purchase email, licence key and a hashed account ID. The How it works page now says so and points at the itemised list.
Fixed The comparison page said ChatGPT gives you “zero control over what it remembers.” That is not defensible — ChatGPT lets you view, correct, delete and disable memories. The real difference is that what it remembers stays managed inside ChatGPT rather than as source files you own outright, and that is what the page now says. We would rather win on the actual difference than on making a competitor sound worse than it is.
Improved The How it works page now covers voice input properly. It described only Whisper, while the privacy page had already been corrected to disclose that Auto mode sends audio to your browser's speech service. The data-flow page is the one a careful reader inspects, so it now names both engines and where each one goes.
Improved Spanish, French and Hindi help pages caught up. The translations still carried the old absolutes in their own languages — “accessible only with your passphrase,” “no blending in facts about the wrong person,” and “all searches are fuzzy.” A correction that only lands in English is not a correction, so all three now match.
Improved The ElevenLabs install note no longer claims free-tier keys cannot use the API. They can — the free tier includes API access. What is actually true is that it is small (about 10 minutes a month) and carries no commercial-use licence, which is the real reason to add a little credit if you use WhosWhoZoo for work.
Previous release (v1.8.43)
Important Auto voice input sends your audio to your browser’s speech service, not through your Worker. Auto mode — the default — transcribes using speech recognition built into your browser. On Chrome and Edge that is not done on your device: the browser streams the audio clip to Google’s speech service, along with the address of the app. That path never passes through your Worker, which means it sits outside the “your notes stay in your own Cloudflare account” boundary everything else in WhosWhoZoo is built to keep. Our privacy page previously described the provider list as complete, and it was not. That is now corrected, and this release adds a one-time notice the first time you start a voice session in Auto mode, with a single tap to switch.

Nothing about the app’s behaviour changed here — Auto has always worked this way, and it is how the browser feature itself works. What changed is that we now tell you. If you speak confidential names or details aloud, switch Settings → Voice input to Whisper, which routes audio through your own Worker to OpenAI under no-training API terms for a fraction of a cent per clip. iPhone and iPad were never affected — iOS has no Web Speech API, so it has always used Whisper. Typing was never affected either.
Previous release (v1.8.43), continued
Fixed Help no longer promises something the model cannot always deliver. The in-app help said answers came with “no blending in facts about the wrong person.” In testing, a partial or misspelled name can occasionally match the wrong record, or have the assistant report that someone is missing when they are not. The help now says so and tells you what to do about it: give the full name, and reset the context if it insists a person is not there.
Fixed Help was wrong about what your passphrase protects. It said your memory was “accessible only with your passphrase.” The Cloudflare API token from setup can read those files directly without it — which is exactly why we recommend deleting that token once you are installed. The support page always said this correctly; the help page now agrees.
Fixed Long-pressing the voice button could start journal mode without opening voice mode. A latent edge case: if voice mode declined to open, journal dictation could still engage. Now it only starts when voice mode actually opened.
Improved A pass over every privacy, security and comparison claim on the website. Several statements were true in spirit but overstated as written, and a few were simply wrong. Corrections include: Claude’s consumer accounts use conversations for training only if you opt in, not by default; Anthropic deletes API inputs and outputs within 30 days rather than retaining nothing at all; ElevenLabs’ terms do allow training unless you opt out, which is why those voices ship off by default; and the site no longer claims your notes are readable by nobody but you without also explaining the one credential that bypasses that. The comparison table now credits ChatGPT’s June 2026 memory rewrite as the real improvement it is, with its figures attributed to OpenAI’s own unpublished evaluation.
Previous release (v1.8.42)
Improved Clearer wording about what running costs look like. The in-app help said usage was “typically a few cents per session.” That is true early on, but it understates things as your memory grows — every question re-sends everything you have written, so a large, long-used memory costs more per question than a small one. The help now says so plainly, and points at /costs and the daily spending cap. Nothing about how the app works has changed; only the description of it.
Previous release (v1.8.41)
Fixed Copying a conversation left things out. The copy button captured only the messages. Anything else the app had put on screen — the “Context Reset” marker, the note about a conversation growing long, and the “Search archive?” / “Search cold storage?” offers — was silently dropped. A pasted conversation could therefore read as one unbroken thread when the assistant had actually been given a fresh start partway through, which is misleading if you are sharing it to get help with something. All of it now comes through, each on its own line.
Previous release (v1.8.40)
Fixed The install banner’s buttons were too small and sat too close together. On a phone, a tap aimed at “Install” could land on the small ✕ beside it instead — which permanently dismissed the banner, with no way back in from inside the app. Both buttons are now full-sized touch targets with real space between them.
Added An “Install to home screen” option in Settings. If the banner is ever dismissed — on purpose or by accident — this brings it back, so a mistap or a change of mind is never a dead end.
Fixed Multiple installs on one device showed the same name. If you install WhosWhoZoo more than once — say, one for yourself and one for a family member, each pointed at its own memory — every icon was labelled plain “WhosWhoZoo,” making them hard to tell apart on a home screen. Each install can now show its own name. Existing icons keep their old label until removed and re-added; new installs pick up the new name right away.
Previous release (v1.8.39)
Added An “Install” button inside the app. Adding WhosWhoZoo to your home screen previously meant knowing to open your browser’s ⋮ menu and find “Install app” or “Add to Home Screen”. A small banner now offers it directly, once, and remembers if you dismiss it. Installing gives each of your installs its own icon that opens without browser chrome around it.
Improved This only appears on Chrome, Edge and other Chromium browsers. Safari and iPhone have no way for a website to offer this, so nothing will appear there — adding WhosWhoZoo to an iPhone home screen still works exactly as it always has, through Share → Add to Home Screen. Nothing is cached on your device either way: the app still loads fresh every time, so a hard refresh keeps working as the way to pick up an update.
Previous release (v1.8.38)
Fixed “View sources” could name a record that would not open. Tapping a source sometimes answered “not found” even though the record was plainly there. It happened when the detail you asked about lived under a sub-heading — a ### line inside a larger record, the way a licence or an account sits inside a longer notes entry. The link named the sub-heading, which was the honest answer, but only whole records can be opened. Those links now open the record that contains the detail and highlight the part you asked for.
Previous release (v1.8.37)
Fixed Overlapping text in loop checklists. When a loop had several items and any of them ran to more than one line, the rows were being squeezed and their text printed on top of each other — unreadable. Short items looked fine, which is why it seemed to come and go. Rows now keep their full height and the list scrolls instead. The same fault was found and fixed in the /browse list before anyone hit it.
Previous release (v1.8.36)
Improved Photos in chat now say who they belong to. When an answer mentions someone you have photos of, those photos appear underneath it. Until now they appeared with no label, so a photo could look like it belonged to whatever was directly above — a picture of a friend showing under an answer about your house, for instance, purely because the answer happened to mention him. Each set of photos is now captioned with the record it came from.
Improved Those thumbnails now show the whole photo. They were being cropped to a square, which zoomed in on the middle and made portrait photos look oddly framed next to the full-size version. You now see the entire picture at its proper proportions.
Previous release (v1.8.34)
Security Your browser now enforces what the app is allowed to do. WhosWhoZoo now tells your browser exactly which code it may run and where it may send data — only its own code, and only back to your own install. If a flaw ever let hostile content into a page, your browser would refuse to run it and refuse to send your memory anywhere else, rather than relying on the app to have caught it. Nothing changes in how you use the app; this is a safety net underneath it.
Previous release (v1.8.33)
Fixed Changing your passphrase failed, and new installs could not complete setup. A change two releases ago asked the platform WhosWhoZoo runs on to store passphrases with six times more work behind them. That platform caps the setting at its existing value and rejected the request outright — so any attempt to set a passphrase failed, including during first-time setup. Signing in was never affected, which is why it went unnoticed. Now corrected.
Improved Nothing about your stored passphrase changed at any point. The failed change could not alter anything — it was refused before taking effect. Your existing passphrase works exactly as it always has, and the 12-character minimum for new passphrases is unaffected.
Previous release (v1.8.32)
Added You can now read what changed in a release. This page is linked from the setup wizard’s final screen, next to the version number, so after installing or updating you can see what you just got. It was being written for every release but published nowhere — so nobody could actually read it until now.
Fixed Corrected some out-of-date help text. The install guide still asked for a passphrase of at least 8 characters when the app now requires 12, and the Technical Reference still said a plain-text export needed your Access Key — it has asked for your passphrase since an earlier release. Both are fixed, in every language.
Added Settings now says where to rotate your Access Key. A short line under “Change passphrase” points at the setup wizard. Rotation stays outside the app deliberately — keeping it there means that even if someone got into your session, they could not replace the key you would use to get back in.
Previous release (v1.8.31)
Security An attempt to strengthen passphrase storage that did not take effect. The intended change was rejected by the platform WhosWhoZoo runs on, which caps that setting at its existing value. Nothing got weaker, and nothing about your passphrase changed — but the improvement described here did not happen. See v1.8.33 above.
Improved New passphrases now need 12 characters instead of 8. Length protects you far more than anything else here: every extra character multiplies the effort required to guess it. This applies only when you set a passphrase — if yours is currently shorter, you can keep signing in with it as normal and will not be locked out. You will be asked for 12 the next time you change it.
Improved Encrypted backups do use a stronger setting. Exports run in your browser rather than on the server, so that part was not affected by the limit above.
Signing in may take a fraction of a second longer. That delay is the point — it is the same delay anyone guessing at your passphrase has to pay, on every attempt.
Previous release (v1.8.30)
Improved Removed code that no longer did anything. Five leftover routes from the old downloadable installer have been deleted, along with two helpers that only they used. Nothing you can see or do in the app changed; there is simply less surface for anything to go wrong on.
Previous release (v1.8.29)
Fixed Garbled text in Spanish, French and Hindi. A handful of messages added two releases ago were stored with the wrong character encoding, so accented letters and the entire Hindi text appeared as nonsense — biométrico instead of biométrico. Everything affected has been repaired, and there is now an automatic check that catches this before a release can ship. English was never affected, and no memory content was ever involved — only the app’s own labels.
Security You can delete it once setup is done — and we now recommend it. The token you created during install is the most powerful key in your whole setup: it can read your memory files straight out of your Cloudflare account, without your passphrase, and nothing it does will ever appear in /security. Your app does not use it — delete it and everything keeps working exactly as it does now.
Improved You’ll need a fresh one to update later, and that’s fine. It takes about a minute, and the steps are now shown on the setup wizard’s final screen, in the install guide, and in the Technical Reference page inside the app. Please don’t skip updates to avoid this — running an old version is a bigger risk than briefly holding a token. Keeping the token is a reasonable choice too; if you do, store it in a password manager rather than a notes app and turn on two-factor authentication for your Cloudflare login.
Previous release (v1.8.28)
Security A stranger can no longer lock you out of your own app. Failed sign-in attempts were counted for the whole app, so anyone who knew your app’s web address could fail five sign-ins every five minutes and keep you locked out indefinitely without knowing your passphrase. Attempts are now counted per device, so they only ever lock out themselves.
Previous release (v1.8.27)
Security Exporting or importing your memory asks for your passphrase, and gets recorded. An export is a complete, portable copy of everything you have saved, and previously anyone at your unlocked app could produce one in seconds with no trace. All three now ask for your passphrase, appear in /security, and are reported to you at sign-in if one happened while you were away.
Previous release (v1.8.26)
Security Your Access Key can no longer read your memory. The Access Key you saved at the end of setup is meant for one job: getting back in if you forget your passphrase. Underneath, it was doing far more — it worked as a full stand-in for being logged in, on every part of the app. It now works only for resetting your passphrase, it cannot erase your memory on its own, and every use is recorded in /security.
Previous release (v1.8.25)
Fixed View Sources could credit only one record when an answer came from two. If the same detail is written in two places — a grandchild’s birthday recorded in both your record and your son’s, say — only the more obvious record was listed, even when the answer clearly drew on both. Every record an answer actually used is now credited. Answers themselves were never wrong; only the source list was incomplete.
Previous release (v1.8.24)
Fixed A save could show raw JSON in the chat instead of the save preview. When this happened the update was not saved, and re-asking was the only way through. It came from Claude occasionally writing the save request in a slightly malformed way that the app did not recognise. The app now identifies the save by its contents rather than by the exact surrounding punctuation, so any variation of it is handled — nothing appears on screen, and the normal preview shows up as usual.
Updating from further back? This page is the full history — every release is listed above, newest first, so you can read everything that landed since whichever version you were on.