# Changelog
All changes made on geniebot.io are documented in this file.

## [Released]

## [1.2.1] - 2026-08-11
Release focus:
- Added GDPR and EU AI Act readiness controls for embedded chatbot deployments, with owner attestations, privacy-policy checks, compliance reporting, retention notices, and platform-admin review tools.

Compliance and Deployment Controls:
- Added a deployment compliance gate requiring each chatbot owner to save allowed domains, add a valid client privacy-policy URL, accept the Terms, accept the Data Processing Addendum, and confirm controller/use responsibilities before an embed can load.
- Enforced the compliance gate server-side for widget loading, public widget configuration, and public chat requests so incomplete deployments do not spend tokens or serve visitor conversations.
- Added versioned Terms/DPA/controller-attestation acceptance records per chatbot, including account owner, timestamp, IP address, and user agent for new acceptances.
- Added re-acceptance behavior tied to compliance document versions, so materially changed Terms/DPA/attestation versions can require owners to accept again.
- Updated public Terms and Privacy/Cookie Policy language for AI-use restrictions, customer controller duties, prohibited high-risk uses, suspension rights, subprocessors, retention, cookies, and embedded chatbot privacy handling.
- Condensed the embedded widget footer to a compact AI/privacy/report disclosure instead of overloading the chat UI with long legal text.

Privacy Operations and Retention:
- Added a CLI privacy purge job for scheduled deletion/redaction of retained personal data.
- Set the retention baseline to remove visitor IP/device metadata after 7 days, delete conversations/messages after 90 days, delete usage logs after 90 days, and clear expired RAG query cache entries.
- Added owner-facing retention notices in Interactions and Analytics, including the fact that Analytics is calculated from retained data rather than lifetime history.
- Added owner tools to export or delete individual conversations, with related query cache cleanup on deletion.
- Masked retained IP metadata in normal dashboard views while preserving more detailed acceptance audit records for platform compliance review.

Compliance Reporting and Admin Review:
- Added a public "Report privacy/compliance concern" form for embedded bots, with bot-scoped abuse controls and clean public URL routing.
- Kept public report responses neutral and avoided exposing abuse-control timing details.
- Stored compliance reports for platform-admin review and notified chatbot owners through dashboard notifications and email when a new report is submitted.
- Added a platform compliance panel guarded by a dedicated platform-admin allowlist rather than the normal business-owner role alone.
- Added platform-admin pages for compliance reports and acceptance audits, including CSV export for both report records and owner acceptance records.
- Added report review actions to suspend/reinstate chatbot deployments, mark reports resolved, and hide deployment action buttons on resolved reports.
- Added an authoritative platform-admin allowlist for compliance administration.

## [1.2.0] - 2026-07-30
Release focus:
- Repositioned GenieBot as a production-ready RAG support platform: customers can add knowledge sources, choose a model provider, build a searchable knowledge index, deploy a branded widget, and improve answer quality from real conversation feedback.

LLM and Model Configuration:
- Added chatbot-level provider selection for OpenAI, OpenRouter, and BoldRouter, with OpenAI-compatible routing for router-backed models.
- Replaced free-form model entry with provider-aware model dropdowns and clearer legacy/deprecated model handling.
- Added frontend and backend provider API-key validation before chatbot settings are saved.
- Added router-backed chat support using customer-provided provider keys without exposing key values in the dashboard or changelog.
- Clarified model characteristics and router-backed limitations so users understand which models are used for chat and which embeddings power RAG.
- Sanitized LLM request logging so production logs keep diagnostics without storing full prompts or customer knowledge context.

Knowledge Sources and Indexing:
- Redesigned the Sources page into a guided setup flow for uploading files, crawling websites, building the knowledge index, and testing answers.
- Improved website crawling with sitemap discovery, duplicate handling, crawl progress messaging, and clearer post-crawl status updates.
- Added optional path-scoped website crawling and a bulk delete action for crawled web pages so admins can safely restart a crawl.
- Removed raw SQL upload support from new knowledge-source flows and updated copy to recommend safer sanitized exports.
- Added resumable indexing batches, progress bars, source/chunk counters, single-action spinners, clearer failure messages, and safer handling for larger sites.
- Added estimated embedding token and cost visibility during and after index builds, including backfilled estimates when historical chunk metadata is incomplete.
- Improved retrieval behavior for broad questions by combining vector search, keyword matching, and chatbot-level fallback context.
- Added a per-chatbot RAG query-embedding cache for repeated popular questions, reducing repeated embedding calls while keeping answers generated against current context.

Chat Behavior and Answer Quality:
- Improved test-chat and live-chat answer formatting for paragraphs, lists, bold labels, and compact service summaries.
- Tuned RAG responses to be shorter, clearer, and less likely to dump excessively long service lists.
- Added guardrails for greetings, test messages, casual prompts, shorthand service questions, unrelated homework/general-assistant requests, and unknown-answer situations.
- Replaced blunt fallback responses with friendlier copy that guides visitors toward questions the bot can answer.
- Added upstream-error messaging so temporary provider failures do not appear as confusing generic failures.

Authentication and Email:
- Switched transactional email delivery to Resend using the GenieBot sender domain, while keeping a safe SMTP fallback for environments that have not configured Resend yet.
- Strengthened authentication with required company name, full name, business email, passwordless signup, email-code login, Turnstile-protected registration/login, email-code ownership verification before session creation, and matching frontend/backend validation that blocks personal and disposable email domains.
- Fixed the passwordless verification-code step so CSRF fields are submitted before forms are disabled, refreshed CSRF tokens between async auth steps, and allowed unverified duplicate registration attempts to safely resend a validation code.

Deploy and Embedded Widget:
- Rebuilt the Deploy page around launcher settings, live preview, and copy-ready embed code.
- Added launcher choices for the GenieBot icon, custom SVG, text button, and uploaded business logo icon.
- Moved uploaded widget logo icons to a public widget-assets path, randomized filenames, limited uploads to validated raster images, and migrated legacy private upload references so deployed launchers can load custom icons correctly.
- Added clearer widget-logo upload failure messages and a Save Settings spinner on the Deploy page.
- Set the GenieBot PNG launcher and `#6517AB` purple as the default launcher branding.
- Added self-initializing embed script support that reads dashboard-generated data attributes for theme, title, icon, launcher type, and position.
- Restyled the embedded chat widget with a branded header, clearer visitor and GenieBot bubbles, compact feedback/copy controls, Enter-to-send support, and improved mobile layout.
- Added production embed requirements: close button, visible privacy-policy link, plan-based "Powered by GenieBot.io" branding, and content-aware suggested question chips.
- Updated widget branding rules so Free and Hobby display GenieBot.io attribution, while Standard and Small Business remove it.
- Updated paid embedded chat bubbles to use the configured chatbot name instead of the GenieBot brand label.
- Removed rating controls from the initial greeting and replaced fixed suggested-question templates with generated, cached, RAG-verified questions based on indexed knowledge chunks; suggestions disappear instead of showing unsafe fallback questions.
- Improved suggested-question chip readability by allowing compact wrapped text instead of truncating important words.
- Matched the production widget typing state to the frontend demo with a branded three-dot GenieBot typing bubble instead of a generic spinner.
- Added required deployment safety settings for allowed website domains and client privacy-policy URLs, with server-side embed-domain enforcement before public chat can spend tokens.
- Added embed auto-disable behavior when a bot is not deployable, a paid owner subscription is inactive, or a provider billing/credit failure prevents chat responses.
- Added public-chat abuse controls with server-side message throttling, bot-level burst limits, and message length caps before RAG or LLM calls run.
- Delayed the embedded chat launcher until the chat iframe has loaded to prevent visitors from opening a blank widget panel.
- Added the production GenieBot widget embed across public frontend pages, login, and registration.
- Added embedded chat history hydration so visitors can continue the same visible conversation while navigating between frontend pages.
- Removed the contact suggested-question preset to avoid surfacing prompts that may lead to unsupported-answer fallbacks.
- Refreshed the root demo page into a safer embed smoke-test page for validating the production widget bundle.
- Added cleanup for legacy duplicate widget scripts so old and new embeds do not visually stack.
- Stabilized custom launcher logos by resolving the current public widget configuration at embed runtime instead of baking uploaded logo filenames into copied snippets.
- Stopped automatically deleting replaced widget-logo files so already-copied embeds do not break with 404s after a logo is changed.

Interactions Dashboard:
- Expanded Interactions into a dashboard-style analytics view with summary KPIs, latest conversations, recent rated responses, and a useful empty/landing state.
- Added an Advanced Analytics view for Standard and Small Business plans, available both account-wide and per chatbot, with conversation, rating, audience, source, usage-token, and estimated-cost summaries.
- Added a locked Analytics preview for Free and Hobby plans, showing top-level metrics while blurring deeper charts and lists behind plan-specific upgrade prompts.
- Hardened the embedded chat open/send flow so Enter key submissions do not accidentally close the popup, and added signed domain validation for message sends when embedded browser sessions do not preserve the initial domain-check flag.
- Added chart-style Advanced Analytics cards for 14-day conversation activity, rating health, source mix, visitor countries, and platform mix with country flags plus device, OS, and browser icons.
- Added chatbot filtering to account-level Analytics and changed the activity graph to compare conversation volume by chatbot instead of mixing conversations and messages.
- Added y-axis labels and hover details to Analytics activity charts so each data point explains the chatbot, date, and conversation count.
- Linked Analytics recent conversations to their matching Interactions sessions when a representative conversation is available.
- Added Interactions search for encrypted conversation text and linked Analytics popular questions to search results for the matching phrase.
- Added 8-session pagination to the session sidebar and message pagination inside selected conversations.
- Filtered Interactions to show only sessions where a visitor has asked at least one question, preventing greeting-only widget impressions from polluting analytics.
- Improved session rows with tighter spacing, clearer active states, relative times, rating pills, and location badges when available.
- Improved selected conversation views with cleaner user/bot bubbles, date separators, detail cards, loading states, and smoother transitions when switching sessions.
- Added immediate loading spinners when opening sessions so old conversation content does not remain visible while new data loads.
- Added metadata display for browser, device type, operating system, IP address, and country when available.
- Added SVG icons for metadata cards and rectangular country flag badges for location display.
- Fixed metadata-card icon alignment so long IPs, browser/device values, and flags stay visually aligned.
- Added best-effort country resolution for older conversations that only had stored IP data.
- Added a privacy-safe IP geolocation cache keyed by hashed IP, with failed-lookup cooldowns, so refreshes do not repeatedly call external geolocation services.
- Kept sensitive values out of the UI and changelog while preserving owner-visible diagnostic context needed for support.

Quality Center:
- Added a bot-level Quality tab focused on improving answer quality from visitor feedback.
- Added quality KPIs, negative-answer review queues, positive-answer examples, and suggested improvement actions.
- Added persistent review actions so negative responses can be marked fixed, ignored, or reopened.
- Connected response ratings from the live widget into dashboard review workflows.

Dashboard and Branding:
- Refreshed the dashboard sidebar with GenieBot purple-gradient branding, softer active states, and clearer menu grouping.
- Fixed sidebar overflow issues around the chatbot selector and active menu items.
- Unified first-chatbot creation and chatbot management so every new bot asks for name, provider, model, and API key from the start.
- Added the Quality view to the dashboard route whitelist so it loads its own page instead of falling back to settings.
- Standardized Interactions backgrounds around a consistent light-purple GenieBot surface.

Public Website and SEO:
- Updated the homepage above the fold to explain GenieBot quickly: crawl a site, upload knowledge, choose a model catalog, deploy a branded support bot, and improve answers from feedback.
- Reworked the homepage hero from a generic visual into a softer genie-inspired purple direction with responsive mobile treatment.
- Added local model/provider icons for BoldRouter, OpenAI, Gemini, Claude, Meta, and Ollama, with BoldRouter positioned as the main model catalog.
- Consolidated provider logos into a compact model-catalog card that works on desktop and mobile.
- Rebuilt the homepage chat preview to match the real embedded widget, including typed-question animation, loading dots, GenieBot avatar, visitor bubbles, and fixed header/input areas.
- Removed SQL-export language from public-facing demo copy to avoid implying unsafe database upload workflows.
- Improved SEO across public pages with stronger titles, descriptions, canonical metadata, social metadata, structured data, and an optimized pricing FAQ section.

## [1.1.8] - 2026-06-03
What's New:
- Completed a production-readiness audit across authentication, sessions, uploads, public chat, billing, LLM training, configuration, and runtime artifacts.
- Defined production readiness priorities from P0 through P3 for security, billing, data-model consistency, operations, and release automation.
- Identified high-priority hardening work across credential management, access controls, abuse controls, session handling, and runtime artifacts.
- Identified P1 work around Stripe subscription correctness, chatbot/project schema consistency, LLM pipeline hardening, and upload validation.
- Identified P2/P3 work around operational readiness, legacy path cleanup, database/runtime cleanup, CI, smoke tests, and staging validation on PHP 7.4.

## [1.1.7] - 2026-05-10
What's New:
- Released platform hardening and stability improvements.
- Improved dashboard request handling and background status synchronization.
- Updated storefront footer year handling to load dynamically.
- Refreshed the storefront design with updated purple-themed presentation.
- Expanded the storefront into a deeper product-led landing page.
- Refined storefront navigation, typography, and chatbot-focused positioning.
- Added polished storefront motion and scroll-based section reveals.
- Updated available chatbot model options and training model selection.

Fixes:
- Strengthened validation across key dashboard workflows.
- Improved file handling reliability.
- Improved login error handling and browser form hints.
- Improved registration view fallback handling.
- Added loading states to login and registration submissions.
- Improved subscription upgrade and payment-method handling.
- Improved subscription payment form readability and upgrade guidance.
- Improved API error response consistency.
- Improved configuration compatibility for existing deployments.
- Restored existing database credential precedence for deployed environments.
- Refined subscription and training status updates for more consistent user feedback.
- Reduced diagnostic output and cleaned up legacy maintenance code.

## [1.1.6] - 2025-04-22
What's New:
- New CDN geniebot-chat-1.0.7.min
- Improved handling of user names across registration, login, and dashboard flows.
- Ensured proper name formatting in welcome emails and session data.
- Enhanced consistency for user-facing messages and account information.
- Added fetchFineTuneEvents method
- Updated sendMessage method
- Updated llm_integration
- Updated generateTrainingExtample to send the chatbotName parameter

Fixes:
- Resolved an issue where user names could appear incorrectly formatted in certain scenarios.
- Improved overall stability of the registration and login process.
- Improved delete_website file

## [1.1.5] - 2025-02-06
- Added checkEmailforSpam method in post
- Added isValidEmailDomain method in post
- Increased security
- Updated Webhook
- Updated Fine tune status script

## [1.1.4] - 2025-01-16
- Hotfix in dashboard

## [1.1.3] - 2025-01-12
- Added CDN to manage embed code properly
- Added versioning in the embed code filename, to track the versions easily in the future
- Latest version of the embed code is 1.0.6 (min)
- Added massive encryptions throughout the apis
- Massive revamp of the embed code generated to be lighter using data-attributes
- Overall security improvements

## [1.1.2] - 2025-01-05
- Continuous security additions
- Added the fine_tuned_model in chat_with_llm
- Added get_llm_status
- Updated translation

## [1.1.1] - 2025-01-04
- Added dynamic title in getHead
- Added open-graph

## [1.1.0] - 2025-01-04
- Continue to test LLM sources and quality of responses
- Added CURL helper function
- Added utils helper function
- Improved URL crawling of websites
- Improved train LLM api to use multistep process to build robust jsonl files based on the uploaded Knowledge based
- Added working fine-tuning using openai.com API
- Revamped the chat embedding CSS styling. Added minimal design svg instead of emoji.
- Updated dashboard post for sources
- Improved embedding code generation in deploy
- Revamped Sources to listen actively to status updates of the LLM
- Separated roadmap into a separate md file

## [1.0.9] - 2025-01-03
Storefront
- Added translation handling
- Updated methods in init.php
- Rewrite htaccess to be dynamic
- Removed all individual pages, consolidated into index

Dashboard
- Fixed mobile issues for tabs
- Fixed issue with font
- In subscription page, links outside geniebot are redirected out
- Styled further the access view

## [1.0.8] - 2025-01-02
- Invitations of users to chatbots (called Access and is managed bot by bot)
- Display a message if there are zero results in interactions until data is found
- Block possibility to embed if an API was removed or is not valid
- Integrate PHPMailer

Details:
- Added transactional email support.
- Updated core security, tooling, and authentication internals.
- Added a reusable email template.
- Various large updates
- Removed business-user

## [1.0.7] - 2025-01-01
- Updated ToU
- Updated Privacy Policy
- Updated logo in registration page
- Removed forgot-password

## [1.0.6] - 2025-01-01
- Corrected pricing tables
- Added getFAQs for frontend pages
- Added getWhiteLabelFAQs for frontend pages
- Minor css fix on button in chat

## [1.0.5] - 2025-01-01
- Display message in sources, deploy and interactions if no API key is defined
- Display alert when API key is missing
- Removed hardcoded url in register

## [1.0.4] - 2024-12-31
- Load price data dynamically

## [1.0.3] - 2024-12-31
- Adjustment of paths and major cleanup and consolidations
- Completed v1 of storefront

## [1.0.2] - 2024-12-30
- Subscriptions are now fully tested and working under subscription
- Added new icon set (+favicon)
- Consolidated manage-subscription into subscription
- Made the default view of dashboard -> chatbots
- Added title of page viewed in dashboard in title
- Added subscription link in dashboard
- Added settings link in dashboard
- Added create setup intent in api
- Added save payment method in api
- Added updated settings in api
- Updated stripe webhook in api
- Revamp of the subscription page in dashboard
- Removed chatbot-settings
- Added vendors via composer
- Added stripe-php in vendors
- Added phpmailer in vendors

## [1.0.1] - 2024-12-29
- Successfully got the chat to work
- Successfully got the embedding to work
- Harmonized style across the board
- Added interactions
- Added security
- Added get_messages
- Added get_sessions
- Added public_chat_with_llm
- Added rate_message 
- Added upload_chunk
- Added tools
- Added tab
- Added demo
- Added serve
- Updated train_llm
- Updated crawl_website
- Updated chatbots
- Updated invitations
- Updated sources
- Updated audit_logger
- Updated llm_integration
- Updated project_id -> chatbot_id
- Removed overview
- Removed settings
- Merged apparences and install-chatbot and preview into deploy

## [1.0.0] - 2024-12-28
- Initial commit
