A small privacy-focused update. We no longer store email addresses on accounts, the column has been dropped from the database, not just hidden in the UI. Discord sign-in now only requests your Discord id and handle (identify scope); we do not pull email or avatar from Discord anymore.
This is not a 'trust me bro, we will not use it' situation, the policy and the app are aligned: we do not collect or store email at all. The privacy page has been updated with a visible changelog for this revision.
With all the recent controversy around Discord, I know some of you would rather not rely on it for login. I may explore adding more OAuth providers in the future, if you have a preference (Google, GitHub, etc.), send a ticket or ping me on Discord and I will gladly take suggestions.
Account & privacy
- Removed email from registration, profile, and the database.
- Discord OAuth limited to
identifyonly (no email or avatar). - Privacy policy revised (July 2026) with highlighted changes.
- Password recovery for username/password accounts: pick a security question and case-sensitive answer at registration (stored hashed). Reset via Forgot password on the homepage. Discord/OAuth accounts use provider login, not security questions.
- Existing username/password users can set recovery in Profile.
Registration
- Register page layout refreshed (two-column, same width as other pages).
- Security question + visible answer required on manual registration.