Ordinary use
With the optional account and AI connector off, journal content remains on devices, private iCloud storage, or end-to-end encrypted shared-trip transport. Codonic cannot read it.
Souvenir · Optional AI access
Souvenir has a hosted remote connector, so using it does not depend on a desktop relay. You choose whether to create a Souvenir account, whether to enable AI access, and which requested permissions to approve.
Update Souvenir on the phone or tablet where you use it. In Souvenir, create or recover an optional account and store the recovery code somewhere safe. The recovery code is the only way to recover that account on another device: Codonic never receives it and cannot reset it for you.
Then enable Claude and ChatGPT access in Souvenir. Access is account-wide: every current or future shared Bridge trip with a valid binding for your account becomes eligible. The account authority fixes the participant identity used for attribution; it does not expose another participant’s identity or a trip the account cannot access.
souvenir:// link. Depending on
provider UI, initial custom-connector setup may still need the provider’s web app.
https://integrations.codonic.dev/mcp Never approve a request you did not start. Souvenir uses OAuth 2.1 authorization-code flow with PKCE. Access tokens last about 15 minutes; refresh credentials rotate and can last up to 90 days. Disconnecting at the provider does not necessarily disable the Souvenir-side AI grant, so use the in-app switch when you want to stop both.
A connection covers the account’s currently granted trips; it is not limited to one trip. With read access, Claude or ChatGPT can list trips and participants, summarize or search expenses, and retrieve a specific expense. With write access it can create, update or delete an expense. Local and private-iCloud trips are not exposed because they do not have an always-on server source. Shared-trip reads and writes go directly through Souvenir's canonical Bridge service; no enrolled device has to relay or apply a tool call. The provider decides when to ask you for confirmation according to its own interface and settings.
Enabling the connector makes every current and future trip reachable through this account eligible; it is not a per-trip picker. In a shared trip, the limited projection includes the display names and shared expenses of other participants, including people who did not create a Souvenir account or connect an AI provider. Only enable it when you have authority to share that group data, and notify the group when appropriate.
Every write is attributed to the exact trip participant linked to your Souvenir account. The payer is a separate field and may be any current trip member. Choosing a payer never changes who performed the AI action.
With the optional account and AI connector off, journal content remains on devices, private iCloud storage, or end-to-end encrypted shared-trip transport. Codonic cannot read it.
The service stores pseudonymous but linkable account, device and trip-binding identifiers, public signing keys, statuses and timestamps, plus encrypted recovery envelopes. These operational indexes are not anonymous. An account binds identity across devices; it is not a second copy of the trip journal.
For each granted shared trip, Souvenir stores its trip key encrypted at rest plus an expiring, revocable AI signing key. The service verifies and decrypts the canonical Bridge history for each tool call, returns only the limited fields below, and commits attributed writes directly. This opt-in path is not end-to-end encrypted from Codonic or the selected provider, and no phone needs to stay online.
The AI projection can include the trip name, currency, dates, member IDs and display names, and expense IDs, dates, amounts, currencies, categories, short descriptions, payer and split information. It excludes private notes, exact coordinates, card identifiers, nicknames and last four digits, attachments, photos, receipts and other media.
For a shared trip, those names and expense details can describe other participants who never made a Souvenir account or enabled the connector themselves. The participant who opts in is responsible for having authority to send the shared ledger to the selected provider.
The selected provider receives tool inputs and results and may retain them under its own terms, privacy policy, plan and conversation controls. Read the provider’s settings before sending sensitive questions.
See the full Souvenir privacy policy and terms of use for the authoritative details.
Codonic currently charges no separate fee for the Souvenir account or connector and does not buy model API calls on your behalf. You bring your own Claude or ChatGPT access; that provider may require a paid plan or impose its own message, connector and regional limits.
As of 13 August 2026, Claude Free permits one custom remote connector, but a custom entry is unverified and not searchable. Anthropic currently requires a Team or Enterprise organization to submit to its searchable directory and documents no free submission waiver or guarantee that a listing remains after cancellation. Directory discovery is therefore not promised as part of Codonic's no-cost launch; custom hosted access remains the available no-desktop path where the provider account supports it.
The hosted service is designed around the free allowances of Cloudflare and Apple CloudKit. Those allowances are finite, not a promise of unlimited service. During heavy use the connector may rate-limit requests, return a temporary error, or ask a device to retry later. Normal mobile-data and provider charges still apply.
Still stuck? Email support@codonic.dev and tell us which provider and app version you used. Do not send your recovery code, access token or trip secrets.