Skip to content

Release notes

This is the public changelog for AuroraDocs. It is updated when a public release is prepared and focuses on visible product changes, compatibility notes, and important fixes.

Internal engineering notes, private issue links, and commit-level details are intentionally left out. Changes that do not affect day-to-day use are only mentioned when they improve availability, security, compatibility, or trust.

AuroraDocs is in public beta (free while beta). See Beta limitations for encryption scope, desktop platform coverage, hosted speech status, and other disclosed limits.

Recent releases

0.12.0 — 2026-09-17

Week Planning, new image providers, and a big drop in idle resource use.

New and improved

  • Week Planning shows a daily-note strip. Each day in the /week view carries a journal preview and accepts one-line captures without opening a full editor.
  • Two new image providers. Ideogram (3.0 Turbo / Default / Quality) and Black Forest Labs (EU) are available as bring-your-own-key providers for covers, inserts, backgrounds, and workspace avatars.
  • OpenAI images move to GPT Image. Image generation now uses gpt-image-2 with updated sizes and cost estimates.
  • Links to other apps ask first. Opening an obsidian://, zotero://, or similar link shows a confirmation — native on desktop, in-app on web. Script and file links stay blocked outright.
  • Much lower idle CPU and network use. Notification, health, and sync polling is consolidated, visibility-gated, and floored, and sidebar and table lookups no longer scan row by row.
  • Layout fix. The right panel and status bar no longer overlap on desktop.

Compatibility

  • If you sync an encrypted workspace, update to 0.12.0 or newer before October 15, 2026 — the AuroraCloud server starts requiring a write checkpoint on encrypted changes from that date, and older versions will be asked to update. A mobile update with the same support will follow before that date.

Reliability and security

  • Document-controlled links and embeds pass a strict scheme allowlist everywhere they can appear, the desktop AuroraCloud endpoint change requires a native confirmation, and security prompts on desktop default to the safe button so pressing Return cannot confirm them by accident.

0.11.5 — 2026-09-15

A patch for workspace folders that contain leftover or invalid object files, in both the web app and the desktop app.

Fixes

  • A reachable workspace folder no longer locks the app to read-only. If some files in the folder had leftover empty-property placeholders or other invalid values, the app used to treat the whole folder as unavailable. Those files are now listed in the sync center. You can keep editing; folder writes pause until the files are resolved. Known empty placeholders are repaired automatically (with a backup), and you can recheck or repair a file from this device's copy.

0.11.4 — 2026-09-14

A patch for pages that froze on open, plus Mistral as a bring-your-own-key speech option, in both the web app and the desktop app.

Highlights

  • Mistral speech when you bring your own key. With a Mistral API key in Settings, you can use Voxtral Mini for dictation and Voxtral TTS for reading text aloud, including picking from your saved Mistral voices.

Fixes

  • Opening a page no longer traps you on it. If your saved AI writing provider had no API key but another provider (for example a local model) was configured, opening any page could spin the editor forever: the address bar and tab title changed, but the old page stayed on screen and the app used a full CPU core. The editor now settles on one provider immediately, and navigation works whether or not the AI dialog is open.

0.11.3 — 2026-09-14

A patch for the desktop app when a workspace folder is missing.

Fixes

  • Opening a page no longer freezes after the workspace folder read-only banner. On packaged 0.11.2, recovery could keep restarting after it had already given up, when the folder was already unavailable, or when a storage update targeted every workspace. The banner can still appear when the folder cannot be opened; navigation and the rest of the app stay responsive.

0.11.2 — 2026-09-13

A public-beta honesty release with clearer speech settings, broader model discovery, and download links that stay on AuroraDocs infrastructure.

Highlights

  • AuroraDocs is in public beta. Marketing pages, About, and signup say so plainly, and Docs → Beta limitations lists encryption scope, desktop platform coverage, hosted speech status, and related disclosures.
  • Speech settings know which languages each model supports. Whisper, Kokoro, and similar STT/TTS options show a real language list (including honest gaps such as no Norwegian Kokoro voices), and dictation prefers your UI language instead of guessing English.
  • Model lists come from your provider connections. Anthropic, Gemini, and custom endpoints refresh after you change a connection, keep your current selection when possible, and say when a cached list is shown.
  • Clipper and MCP downloads stay on downloads.auroradocs.eu. The download page no longer depends on a personal GitHub account for those packages; public GitHub and npm remain as fallbacks.

0.11.1 — 2026-09-09

A small fix release for the desktop app and the page header.

Fixes

  • The desktop app no longer freezes after a workspace folder goes missing. If the folder was unavailable and then came back, the app got stuck in a loop trying to recover it: the page looked merely read-only, but nothing could be opened and no button responded. Recovery now runs calmly in the background and the app stays usable while the folder is checked.
  • The page header stopped bouncing. The row of page actions that appears when you hover the title keeps its space, so the page no longer jumps down and back up.
  • Cover and background pickers open where you can use them. On pages without a cover they used to slide under the sidebar.
  • The What's new card on Home is aligned. The version and its dismiss button sit on one line, and every entry's text starts at the same column.

0.11.0 — 2026-09-09

Before you upgrade

  • AuroraCloud updates its database as part of this release. Nothing is asked of you, and your workspaces stay where they are, but a hosted account may see a short window during the upgrade where sign-in and sync are unavailable. Local and folder workspaces are unaffected.
  • Sign-in gains a "trust this device" option. It is off until you choose it, and it changes only the login challenge — see below.
  • Settings navigation moved. The Data group is now Data & sync and holds Storage, Sync, Backup and Import; Sync has moved out of Workspace settings. Old addresses redirect, so saved links keep working. Font size, line height and paragraph spacing moved from Appearance into Typography, and Automations moved from Integrations to Workspace → Features.
  • Very large workspaces no longer load everything up front. AuroraDocs used to hold your whole workspace in memory and rebuild it on every change; it now loads what a view actually needs, in bounded pages. Opening a big workspace is faster and stays responsive while it fills in. If you notice a list that fills in a moment after it appears, that is this change working as intended.
  • The location map runs on a new mapping library. Maps render the same; the upgrade clears a security advisory in the previous version.

A calmer workspace

  • The sidebar starts with the four places you go daily — Inbox, Calendar, Tasks and Settings. Notifications, For you, Week Planning, Graph and Sharing begin as status-bar icons and can be promoted back into the sidebar from its edit mode. If you had already arranged your sidebar, your arrangement is kept.
  • A compact month calendar sits at the bottom of the sidebar, with ISO week numbers. Clicking a day opens that day's journal page, or creates it.
  • Pages have a heading scrubber down the right edge of the editor, so you can see the shape of a long document and jump through it.
  • The clutter under a page title is one line instead of three. Type, tags, Properties and backlinks now share a single meta row. Empty Inbox, notification and task lists show one clear action rather than a wall of text, and Quick Capture shows its ⌘J / Ctrl+J shortcut as keycaps.

Settings and sync

  • Settings reads as one product again. Every page uses the same content width, the same buttons, the same segmented controls for either/or choices, and sentence-case headings. Toggles announce the row they belong to, the "Saved" flash is read out by screen readers, and group labels no longer just repeat the page title.
  • The Sync page is a status header, not five cards. It opens with one plain state — synced, changes waiting, offline, or needs attention — with the last sync time, a Sync now button and Prepare offline. Details, queue contents and troubleshooting are behind disclosures, and Reset local cache now lives in a danger zone whose confirmation counts the unsynced changes on this device that would be lost, or says plainly that it could not check.
  • Settings copy in browser-only and offline setups tells the truth. Cloud features say "Sign in to enable" rather than reporting a server problem, calendar connection warnings no longer contradict each other, and the storage page says "browser-only" once instead of five times.

Sign-in and sessions

  • You can trust a device for 30 days. After you complete a two-factor login, AuroraDocs can skip the login challenge on that device for 30 days, for password, email-code and all four sign-in providers. Only the login challenge is skipped: sensitive actions still ask you to verify. Trusts are dropped automatically when you change your password or your two-factor setup, and you can review and revoke them in Settings → Security → Trusted devices.
  • Sessions no longer end hours early. Two separate faults were cutting sessions short: a desktop session that still held a valid login could fail to find its renewal credential and sign itself out, and a laptop that slept and woke could be mistaken for a stolen session, which revoked every device at once. The desktop app now recovers the credential from the system keychain, and the timing window is wide enough to survive sleep.
  • Signing in from one browser tab is picked up by the others again, and a Safari session whose local data aged out no longer drops you at the sign-in screen while your session is still valid. One consequence to know: if you clear your browser's site data, you will be asked to sign in again rather than restored silently.

Encrypted content and conflicts

  • Encrypted edits can no longer silently overwrite each other. Every encrypted save now carries a freshness check. If two devices change the same content, page details, properties, comments or links at once, the second one is not written over the first — it is kept for review and retried against the current version, and Sync explains a genuine fork in plain language instead of getting stuck.
  • Keeping the local side of an offline conflict actually keeps it. Choosing your offline version now survives on both clients and across reloads, without duplicating the text you chose.
  • Interrupted encryption setup can be resumed. Turning on encryption and losing power, closing the tab or switching accounts mid-way now leaves a recoverable state rather than a half-encrypted workspace, and switching accounts sets aside the previous account's pending work instead of mixing it in.
  • Recovery key files can be added again. Adding a key file failed at the point of saving it; it now saves.

Privacy and security

  • Local and folder workspaces make no cloud calls at all. The rule that an account-free workspace reaches nothing outside your machine now covers the whole app — pages, plugins, the weather widget, image generation, PDF re-extraction, generated avatars, the offline worker and the desktop update check — not just its shared core. The offline worker no longer works in the background with a closed tab, and sign-in responses are never kept in the offline cache.
  • Diagnostics you export are scrubbed before they leave. Startup, sync, performance and desktop diagnostics now remove tokens, keys, passwords, email addresses, cookies, signed link parameters and document contents, and hash workspace identifiers, while keeping the timings and counts that make the export useful. Share links and invite addresses lose their secret part.
  • Profile pictures are stored more carefully. Replacing or clearing your picture retires the old file, a failed upload can no longer replace a live picture, and deleting your account removes leftovers rather than only the current image.
  • What is kept offline is now an explicit, enforced policy. The offline cache has a written rule for what it may store, sign-in and sharing responses are excluded, account-sensitive caches are cleared when you sign out or switch accounts, and pending edits are flushed before the app reloads for an update.
  • Calendar feeds and remote plugins are held to stricter rules. Calendar requests verify where they are actually going, cap what they will download and keep secret feed addresses out of logs. Installing a plugin from a URL is disabled until third-party code can run in a proper sandbox.

Fixed

  • Your local data survives a browser that will not let go of it. Suspending a tab, closing it mid-save, running out of storage or hitting a stuck database now pauses safely instead of resetting local data. Queued edits stay durable and flush when AuroraDocs is open again, and automatic repair refuses to delete anything while unsynced work exists or when it cannot prove the store is empty.
  • Clearing the attachment cache stays cleared, downloads in flight can no longer repopulate it, and a full disk no longer reports files as cached when they were not. If pinned files alone exceed your cache limit, Settings says so and tells you what to do about it.
  • "Sync now" says when another tab is already syncing instead of spinning and stopping without explanation.
  • Dictation and read-aloud work on your own AI provider. When built-in AuroraAI is unavailable for a workspace, both now use the provider the settings panel was already showing as selected.
  • Policy update emails link to pages you can read without signing in. The notice sent when the Terms or Privacy Policy change previously linked only into the app, which the accounts most in need of the notice could not open.
  • AI answers are no longer cut off, and no longer ask before doing. Actions that are themselves the confirmation — rephrase, summarise, inbox triage — now return the result instead of a question, answers are given room to finish, and a stored older assistant model is updated rather than failing every request.
  • Missing translations filled in. Inbox capture, account security screens and several Settings labels are now translated in English and Norwegian, including ones that were showing a raw label or a broken plural.

Reliability and security housekeeping

  • Server-side checks were tightened so that people who are not members of a workspace cannot learn anything about its encryption state, and removing a co-owner requires the same verification as changing an owner's role.
  • Runtime components were updated to versions with current security fixes, and the release ships with no known advisories in its production dependencies.
  • Live page includes now resolve only from content you can actually read, and refuse rather than guess when a workspace is locked.

0.10.1 — 2026-08-30

Legal and privacy

  • The Terms and Privacy Policy are readable again. Section headings, bold labels, inline code and table headers were painted in a near-black that was close to invisible on dark themes — on the two documents you are asked to accept. Colours now come from the theme, checked across all 32 of them.
  • Both documents show the version that was actually published. The pages read the current policy from AuroraCloud, but the address they read from was never served, so every reader silently got text baked in at build time. That is why the website and the app could show different dates. A page that has fallen back to bundled text now says so instead of failing quietly.
  • The privacy policy describes the encryption the app actually does. It still said content keys were derived from your login password. They are not, and have not been since June: your keys come from the devices you approve and your recovery phrase. That is what lets you sign in with Google or GitHub and keep the same encrypted content — and it is a stronger guarantee than the old wording claimed, not a weaker one.
  • Clearer processor disclosure. Email dispatch runs on Resend's European infrastructure in Ireland, with account data, delivery metadata and logs processed in the United States under standard contractual clauses. Built-in AuroraAI chat runs only on EU-region providers configured to retain nothing you send.

Terms

  • Paid plans will be open to everyone on the same terms. The Terms had said the first paid release was for business customers only. If you are a consumer in Norway or the EU/EEA they now state your 14-day right of withdrawal, the consent to start immediately, and the proportionate charge if you withdraw after using part of the period.
  • Beta pricing is stated plainly. There are no paid plans during beta. Paid plans will be phased in afterwards, the free tier stays as it is, and existing free accounts are not moved onto a paid plan.

New

  • AuroraDocs asks you to re-accept the Terms when they change materially. A prompt at your next sign-in links both documents and records your acceptance. Your data stays where it is while you decide, and signing out is always available.

0.10.0 — 2026-08-29

New

  • Presentations are a first-class page type. Build a deck, run it as a slideshow with autoplay, and let the assistant draft and edit slides.
  • Draw and diagram on canvas. Freehand drawing and diagram shapes sit alongside the existing canvas cards.
  • Split view and read/edit both have working keyboard shortcuts again. Split view is now ⌘/Ctrl+Shift+D — the previous chord could not be typed at all on Nordic and other ISO keyboards. Read/edit is ⌘/Ctrl+Shift+E.
  • Research Studio gained a per-project dashboard, direct file and PDF ingestion, artifact export, and citation confidence.

Privacy

  • Profile pictures no longer contact an outside service. Avatars without an uploaded picture used to load an image keyed on a hash of your email address. They now show initials and load nothing externally. Uploaded pictures are unaffected; if you relied on a Gravatar image, upload one to restore it.
  • Link previews, URL properties and bookmarks no longer fetch site icons from a third party. They show a local glyph instead.
  • Workspaces with no account send nothing at all. Network access from the shared workspace layer now passes a single boundary that refuses by default, with a short audited list of calls that must work without an account. The anonymous usage ping no longer fires from account-free workspaces.

Security

  • Realtime connections authenticate with a short-lived, single-purpose ticket instead of a full session token carried in the URL, so a token captured from a log cannot be reused against the rest of the API.

Fixed

  • Templates you create are checked the same way templates an agent creates always were, so an oversized name or body is reported instead of silently saved.
  • Assistant citations show what they matched, and encrypted or unavailable sources render an explicit state rather than a broken link.
  • Long lists no longer clip. A scrolling area could hide most of its rows.
  • Admin status chips meet contrast requirements in the light theme.

0.9.7 — 2026-08-28

Fixed

  • Google sign-in is available in the browser when desktop sign-in is not configured. The browser login action now stays visible and usable without advertising an incomplete desktop-only Google setup.
  • The desktop login window can be moved before sign-in. The unauthenticated login surface now keeps a native drag area without covering its controls.

0.9.6 — 2026-08-28

New

  • Exclude results in live queries. Property filters gain "does not contain" and "does not equal", so a live query can leave matching pages out instead of only pulling them in.

Improved

  • Map queries explain an empty map. A map-view live query whose matches have no location now says the matches aren't mappable, instead of looking like it found nothing.
  • Encrypted workspaces show when retrieval is locked. In an end-to-end encrypted workspace, knowledge and assistant retrieval now states plainly that it is locked until you unlock the workspace, and offers an unlock action, instead of appearing empty or stale.
  • No repeated MFA prompt on sign-in. Signing in with a provider that has already verified a second factor no longer asks you to do it again.
  • Research Studio surfaces unconfirmed sources. When a generated artifact relies on a source that is still being fetched, the citation review flags it so the unconfirmed source is visible.

Fixed

  • Desktop keeps your configured AI providers. They no longer disappear after you restart the desktop app.
  • airouter.ch can be used for chat again.

0.9.5 — 2026-08-26

New

  • Turn on end-to-end encryption while creating a workspace. Its contents stay unreadable to anyone you have not shared them with.

  • The assistant works on the page you are reading. It can edit that page, accept a pasted screenshot, and take your next message while it is still answering the last one. Scope it to the page or the whole workspace.

  • Dictate, and have answers read back to you. Speech-to-text and text-to-speech are available, and you choose the transcription and voice models from a list.

  • Custom databases from reusable templates. Build them from templates, import and export their contents, and place live query cards directly on a canvas. AuroraAI can propose an editable structure for contacts, interests, equipment, subscriptions, expenses and other specialized collections before applying an approved additive plan.

  • Signing up sends a confirmation email, so an address can be recovered later.

Improved

  • Ask and the assistant are one panel in one window, instead of two separate places to type the same question.

  • Pick a model from the list the provider supplies instead of typing its name, and add a provider from a shelf of cards rather than a list of names. Requesty and airouter.ch join the available providers, each carrying a data-residency flag.

  • The app starts faster, loading about a megabyte less code, and syncing a large workspace no longer stalls on long change scans.

  • Sensitive account, billing and security changes ask you to confirm. Checkout, billing-portal access, account deletion, MFA changes and TOTP enrollment each require a fresh email-code or authenticator challenge on the current session before anything changes.

  • "Object" is the app's own word — it now says "page", and the built-in assistant is called AuroraAI throughout.

Fixed

  • The graph opens at a readable zoom instead of a handful of enormous nodes.

  • Notices along the bottom of the window stack instead of landing on top of each other, and no longer cover the status bar.

  • Right-clicking near the bottom of the window opens the menu next to the pointer, rather than a fixed distance up the page.

  • Norwegian is Norwegian again on the surfaces that had quietly fallen back to English.

  • Desktop Local folders fail safely during permission and recovery problems. Affected workspaces stay protected from writes until their folder state is fully reconciled, and a renamed or missing folder pauses the mirror instead of being replaced with an empty one.

  • Editing the same page in two places no longer loses one side's changes, and an edit overridden by someone else is raised as a conflict for you to review rather than disappearing.

Security and availability

  • Sensitive account, billing, and multi-factor changes are bound to the current session, so a stale or rotated session cannot complete them.
  • A webhook address that resolved to an internal network could previously slip past the outbound guard; it no longer can.
  • Diagnostic output redacts secrets in more of the shapes they actually appear in.

0.9.4 — 2026-07-16

Improved

  • Sensitive session controls now guide you through fresh verification. When revoking a session requires renewed confirmation, Security settings offer the account's email-code or authenticator method and safely retry the action after verification.

  • MCP workspace access is more reliable for approved agents. Workspace owners can issue scoped grants without the database error that previously interrupted grant creation, while deny-by-default policy, independent revocation, and explicit workspace selection remain enforced.

  • Scheduled backup handling is safer under pressure. AuroraCloud now stops exhausted backup jobs from being leased again and reads bounded metadata when checking stored artifacts, reducing memory and disk pressure without changing restore compatibility.

Fixed

  • The in-app changelog shows the complete recent release history again. The Changelog view no longer skips directly from the latest release to an older entry.

0.9.3 — 2026-07-15

New

  • Closed-app E2EE capture is safer and more useful. The browser clipper can submit opaque encrypted captures for approval after the workspace is unlocked, without receiving workspace keys or read access.

  • MCP access can now span explicitly approved workspaces. Workspace owners control client identities, grants, scopes, expiry, and revocation, while project context remains bounded and least-privilege by default.

Improved

  • Sign-in is clearer across browser and desktop. Provider controls use recognizable monochrome marks, browser OAuth completes in the current window, and Apple login/signup behavior is aligned across supported surfaces.

  • Desktop endpoint switching is safer. Switching between production, staging, local, and self-hosted AuroraCloud realms now protects pending work, closes secondary contexts, and fails closed before destructive cleanup when a prerequisite is not met.

Fixed

  • Password recovery is available directly from sign-in. Users can request a reset link without exposing whether an account exists, and signup recovery verification can return to the phrase display without losing entered words.

0.9.2 — 2026-07-12

New

  • Important workspace notices can appear directly in AuroraDocs. Workspace operators can publish active alerts that appear in the app and Notification Center, making service and operational notices easier to see.

Improved

  • Research and retrieval evidence is easier to inspect. Research Studio provides more reviewable source citations, while Ask and Intelligence expose clearer retrieval readiness and source diagnostics. Optional local embeddings can improve matching while preserving sparse search as a fallback.

  • Block references are more durable. Addressable editor blocks now retain stable anchors through ordinary edits and moves, while copied or restored content avoids accidental duplicate identities.

  • Desktop builds can connect to self-hosted AuroraCloud servers. A hidden maintainer control can switch between production, hosted staging, a local backend, or a validated custom endpoint. Production remains the default.

0.9.1 — 2026-07-09

Improved

  • Hosted AuroraAI has stricter fair-use protection. AuroraCloud now protects the hosted provider path with provider-wide request pressure limits, a cap on concurrent hosted requests, per-user anti-abuse limits, and output-token caps before provider calls are made.

  • AuroraAI allowances can be tuned without another deploy. Operators can adjust Plus and Pro hosted-AI allowance values from the AuroraAI admin settings page, while the default allowances now match the fixed-price provider path.

Fixed

  • Production API and desktop release packaging are unblocked. The API release package installs cleanly from its standalone server directory, and the Windows desktop release job can run the web build step during stable desktop packaging.

0.8.8 — 2026-06-24

Improved

  • Desktop pages open from local data first. AuroraDocs Desktop now paints object pages from the local cache before cloud collaboration catch-up runs, so opening a note is no longer blocked by AuroraCloud or a full collaboration document load.

  • Desktop sync does less duplicate work. Local editor saves write to the device first, queued sync work is coalesced when repeated changes target the same resource, and existing folder imports wake open documents through the same local document update path.

  • The desktop updater currently focuses on Apple silicon macOS. To save build time while the desktop recovery work is being tested, this release publishes the macOS Apple silicon installer/update artifact. Linux, Windows, and macOS Intel artifacts can be re-enabled later.

Fixed

  • Opening a page no longer creates extra tag sync writes. Aurora no longer rewrites hashtag metadata just because existing content was loaded, reducing page-open queue noise and avoiding unnecessary sync retries.

  • Collaboration recovery is safer around large or unhealthy documents. Desktop collaboration state loads lazily, uses smaller catch-up requests when available, and avoids applying oversized remote collaboration blobs on the UI thread before the page is usable.

  • Existing desktop sessions recover more calmly from missing local folders. If a previously selected local folder is missing or inaccessible, Aurora now keeps the recovery screen available instead of clearing the device session automatically during a passive startup check.

0.8.4 — 2026-06-23

Fixed

  • Desktop collaborative editing uses less CPU. Cursor presence now avoids redundant editor redraws, repeated cursor-label animation, and extra avatar image fetches while keeping local and remote cursor visibility intact.

0.8.3 — 2026-06-23

Improved

  • Large object lists open much faster. Default note, page, and custom-object lists now load a visible window first and continue loading as you scroll, instead of waiting for every object and property to be prepared up front.

  • Cross-device changes arrive sooner. Object, property, and content updates now wake other open Aurora clients through realtime notifications, while polling remains in place as the safety net.

  • Collaborative editing is lighter. Shared editor sessions save smaller Yjs updates, avoid re-applying unchanged remote document snapshots, and show your own cursor/avatar locally alongside collaborators.

Fixed

  • Sync Center recovers temporary network failures more reliably. Browser and desktop transport errors such as Network — Load failed, request timeouts, and rate limits now stay retryable instead of turning into permanent stuck rows after repeated attempts.

  • Sync Center actions match the visible queue state. The bulk retry and recover controls now include stuck/dead-letter rows when appropriate, and recent manual sync results include permanent queue errors that still need attention.

  • Manual sync is safer around permanent failures. Sync now retries ordinary failed work and protected temporary network failures, while explicit retry actions remain the way to intentionally re-run permanent dead-letter rows.

  • Long desktop and PWA sessions are less likely to ask for password and MFA again. Aurora now coordinates refreshes across tabs and closed-window background sync so a background refresh does not leave the foreground app with an older rotated session.

  • Admin operations stays available when host metrics are restricted. If the server cannot read host uptime, CPU, load, or memory values, the operations dashboard now marks those metrics unavailable instead of failing the page.

0.8.2 — 2026-06-21

New

  • Automations can now be created from Settings. Workspace managers can open Settings → Preferences → Connected services → Automations to list rules, inspect recent runs, and create rules for object-created or object-updated triggers. The first builder supports object type, parent, and status filters, plus actions such as updating a property, archiving the object, sending a connector notification, or starting an AI digest.

  • A new "For you" feed summarizes what needs attention. Aurora can post a daily workspace brief with recent changes, stale pages, and due tasks. Encrypted workspaces are skipped, and non-AI fallback summaries are used when hosted AI is unavailable or over budget.

  • Home now has a Live Dashboard. The home screen leads with configurable widgets for the daily brief, tasks, and recent changes, with per-workspace layout persistence.

  • Desktop sign-in is faster for returning users. The desktop app can show the previous identity and ask only for the password, while "Sign in as another user" performs a full switch and keeps each user's local folder isolated.

Improved

  • Collaborative editing updates arrive faster. Shared cloud documents now use server-sent events for near-instant document and cursor/presence updates, with polling retained as a safety net.

  • Collaborative document content is safer under concurrent edits. The server derives the API/search snapshot from the Y.Doc source of truth, so stale content pushes and public-link edits no longer overwrite merged collaborative edits.

  • Long editing sessions and automation triggers are steadier. Realtime collaboration reconnects after token refresh, rapid status-change automations no longer drop the transition that rules are waiting for, and repeated no-op object updates create less background sync churn.

  • Calendar and automation setup is clearer for operators. API environment examples now include the calendar OAuth variables, and the "For you" feed is available from the sidebar when enabled.

0.8.0 — 2026-06-14

Security

  • E2EE unlock is now independent of your login password. Content keys are protected by a recovery phrase (BIP39 mnemonic) and a per-device key stored in your browser. Your login password no longer unlocks content — so changing, resetting, or switching to an OAuth provider never puts your workspace at risk. Existing accounts migrate automatically on next sign-in; a one-time prompt confirms your recovery phrase is saved before the server-stored copy is removed.

  • Trust a new device without your recovery phrase. A device you already trust can approve a new one by scanning a QR code or entering a short code. The new device receives the account key via an end-to-end-encrypted handshake and unlocks silently going forward — no recovery phrase entry needed.

  • MCP access tokens are scoped service credentials. Workspace MCP tokens have explicit scopes, expiry, audit history, and access checks. Existing tokens may need to be recreated.

  • Manage how your account unlocks. You can now rotate your recovery phrase, add a passphrase or a key file as an extra unlock method, and remove methods you no longer use — with safeguards that never let you remove your last recovery option.

  • Unlock with a key file. Provision a downloadable key file and use it to unlock end-to-end encryption on a device, as an alternative to typing your recovery phrase.

  • See exactly what the server can and cannot do. A new transparency panel in settings explains, in plain language, what AuroraCloud can and cannot access while end-to-end encryption is on.

  • Removing a workspace member now rotates the workspace key. When someone is removed, the workspace key is rotated and existing content is re-encrypted in the background, so a former member's old key can no longer open new changes.

  • Forward-looking encryption (opt-in). AuroraDocs can wrap keys with a hybrid post-quantum scheme (X25519 + ML-KEM) for protection against future quantum attacks. It is off by default while mobile support lands.

  • Hardened server access checks. A round of trust-boundary fixes tightened which records each account can read, kept end-to-end-encrypted content out of the server search index, scoped invite codes to their creator, and moved login rate limiting to a shared store.

New

  • Print or save any page as PDF. The page menu now includes Print / Save as PDF, which opens a clean, readable snapshot and triggers the browser print dialog. Cmd/Ctrl+P from any open page routes directly to this view.

  • Inbox triage shows which AI model is making suggestions. A source badge identifies whether recommendations come from Auto, AuroraAI, your own API key, or local rules. You can switch modes from the inbox settings popover.

  • AI Assistant uses explicit workspace reads before answering. The hosted assistant now plans and executes read-only workspace tools (current object, semantic search, related objects, recent pages) and passes source citations into its answer, so responses are grounded in your content rather than hallucinated.

  • AI Assistant can rewrite the current page on request. With your own API key (BYOK mode), the assistant can replace an object's body through a governed tool. AuroraAI handles explicit rewrite/enhance requests from the panel.

  • Choose your AI provider on the Intelligence page. Pick the text-generation provider inline and attach several workspace objects as grounded context, with search and sort to find them quickly.

  • Drag objects into folders. In the object list, drag an item onto a folder to move it in, or drop it on the root to take it out — across the table, gallery, and hierarchy views.

Improved

  • Desktop Local folder watcher is more reliable. Partial writes (mid-save truncation) are retried automatically. Parse failures are logged in the Recent File Activity panel so you can see what happened. The watcher now activates for offline-only folder workspaces as well as cloud-connected ones.

  • Initial sync is faster for large workspaces. Page fetches during the first load are now parallelised with bounded concurrency, and the server-side query is backed by a composite index on (workspace_id, updated_at).

  • CI and deploy lanes are path-scoped. API-only pushes deploy only the API. Desktop and companion builds skip CI checks when no relevant paths changed. AuroraNotes and AuroraTasks have a separate manual publish workflow.

  • The sync conflict center is clearer. When a change differs between this device and the cloud, you now get a plain-language status, a focused per-item view with an optional side-by-side comparison, and two clearly labelled choices — "Keep this device" or "Use the cloud" — with the technical diagnostics moved into a collapsible "Sync details & troubleshooting" drawer.

  • Sync is more crash-safe. A batch of reliability fixes prevents edge-case data loss: an object's properties are replaced atomically, dirty-state flags clear correctly so nothing re-syncs forever, and an unreadable local folder is treated as temporarily unavailable rather than as a mass deletion.

0.7.21 — 2026-05-14

New

  • Live coauthoring baseline for AuroraCloud. Two signed-in browser sessions can open the same page, see the other session, type from both editors, and keep both edits after reload.
  • Built-in plugin improvements. Saved Searches now uses workspace-scoped plugin storage, Broken Links can preview and apply title-based fixes, and PDF Import & OCR can attach the source PDF and re-extract from it later.

Improved

  • Broader help coverage. The docs gained more complete guides for habits, templates, blocks, collaboration, mobile, desktop, and security.

0.7.20 — 2026-05-14

New

  • Provider sign-in for existing AuroraCloud accounts. When the server is configured for them, the login screen can now offer Apple, GitHub, Google, and Microsoft sign-in.

Security

  • Account rules still apply. Provider sign-in links verified emails to existing Aurora users and keeps invite, consent, MFA, and encrypted-workspace unlock rules in place.

0.7.19 — 2026-05-14

New

  • Encrypted AuroraBak restore guardrails. AuroraBak backups from encrypted workspaces now stay encrypted by design. Restoring into the original workspace preserves encrypted content, while unsafe encrypted clone restores are blocked.
  • More reliable offline sync recovery. Chromium Background Sync can now finish supported queued AuroraCloud writes even after the last AuroraDocs tab is closed.

Improved

  • Semantic workspace retrieval lifecycle. Settings -> AI now controls AuroraCloud semantic indexing. Turning semantic retrieval off clears stored workspace vectors and keeps them off until you enable the toggle again.

0.7.18 — 2026-05-13

Fixed

  • Turning off workspace encryption no longer leaves the workspace locked after refresh. Aurora now handles the transition more safely and keeps the workspace recoverable if the change cannot complete.
  • Split-pane navigation keeps the active pane. Sidebar links that can render in split view now open in the active pane, and closing split view preserves the split tabs in the main tab bar instead of discarding them.

0.7.17 — 2026-05-12

New

  • Active pane for split view. When split view is open, new pages, tasks, command-palette picks, quick capture, and sidebar opens land in the active pane. Click a pane to arm it, or use the keyboard shortcut to switch active panes.

Improved

  • Object Explorer and Tasks are easier to scan. Object Explorer gained inline title search and newest-first sorting. Tasks now use bucketed list sections, slimmer board cards, compact priority pills, and within-column reordering.

0.6.39 — 2026-04-28

New

  • More themes in Settings → Appearance — GitHub-style light/dark plus popular palettes (Gruvbox, Dracula, Tokyo Night, and others).
  • Side panel on your phone: use the header button or Quick actions → Side panel to open tasks, calendar, pomodoro, and other widgets in a bottom sheet. The AI assistant opens the same way on small screens.

Improved

  • AuroraNotes and AuroraTasks on the desktop have updated title-bar styling, clearer window dragging on macOS, and new app icons.

0.6.24 — 2026-04-27

New

  • Pin objects directly to the sidebar. Right-click any object and choose Pin to sidebar to keep it as a top-level shortcut. Pins can show their first-level children and can be reordered.
  • Recurring tasks. The task editor has a new Repeats row with Daily / Weekly (with weekday picker) / Monthly (with day-of-month picker) / Yearly / Custom RRULE options. Marking a recurring task as Done auto- creates the next instance with the same properties and the next due date computed from the rule; the calendar and the daily-notes "due today" panel show recurring tasks on every matching date.

Fixed

  • Workspaces no longer drop into "desktop read-only mode" just because you're an owner who hasn't set up a local folder copy yet. Read-only is now triggered only by an explicit opt-in, not by an inferred owner default.
  • Status bar storage-mode badge now reads "Cloud" until you actually configure a local folder copy via Settings → Data → Local folders or desktop onboarding, instead of incorrectly claiming "Cloud + Local" for every owner.

0.6.23 — 2026-04-27

Mobile PWA milestone shipped. The installable web app is much more usable on phones:

  • Phones now use a slide-out sidebar drawer instead of a compact desktop rail.
  • A phone-only Quick Actions button exposes Quick Capture, New Page, Search, Tasks, and theme switching.
  • A new editor formatting toolbar pins above the soft keyboard while you type on a phone: Bold, Italic, Heading, Bullet list, Task list, Code, Link, Undo, and keyboard dismissal.
  • The installed iOS PWA now shows a branded splash on launch instead of the white flash.
  • The app shell respects iOS notches, the Dynamic Island, and gesture-bar home indicators.

Settings reorg. Settings → Workspace → Sync now opens with Action and Activity at the top; the four diagnostics panels are tucked behind a single collapsed Diagnostics fold so the page no longer leads with a wall of debug logs. Settings → Desktop → Updates is now the fourth row instead of being buried below sync internals.

Fixed

  • The PWA install prompt now actually appears on phones rather than also showing on iPads in landscape.
  • Workspace context loading flag no longer stays stuck after the cloud snapshot has been applied for Cloud + Local workspaces.
  • Authentication requests have stronger abuse protection.
  • Diagnostics panel scroll lists now actually scroll again.
  • Removed duplicate page headings on Workspace settings pages.

0.6.22 — 2026-04-27

  • Markdown mirror is now configurable for every workspace at once. A new device-level default applies to every workspace in the Aurora folder, with optional per-workspace overrides. Bulk actions: "Apply default to all workspaces" and "Reset overrides".
  • Removed the "Recent Aurora folders" shortcut in Settings — quietly swapping local-folder roots without signing out was creating more problems than it solved.

0.6.21 — 2026-04-27

  • Cloud + Local sync no longer mistakes Aurora's own folder writes for external imports.
  • Sidebar no longer hides behind the loading skeleton after workspace data has hydrated.
  • Data conflicts panel rewritten for readability — plain-English summaries, group-level "Keep all local" / "Use all server" shortcuts, and trivial timestamp-only mismatches under 5 seconds of clock skew no longer surface as conflicts.

Older public release summaries will be added here when they are relevant for current users.

Built with AuroraDocs.