Accounts
Hosted workspace, by explicit choice
Guest mode stays on this device. An email/password account adds one durable, private workspace in Cloudflare D1.
What sign-in does
Sign-in opens the account's own local cache and reads its hosted workspace. It does not upload an existing guest workspace. Each account has its own user-owned workspace row, and stale writes are rejected rather than silently replacing newer data.
When data reaches the cloud
Choose Upload to cloud from the account menu. The server validates the complete versioned workspace, stores it under the authenticated user, and returns a new version. Edits after upload remain local until the next explicit upload.
Recovery and deletion
Export a JSON backup before changing devices, reloading a cloud copy, or deleting an account. Delete account removes the account and its hosted workspace. Exported backups remain under your control and are not deleted from the device by that action.
Current prerequisite
Email verification and password recovery are not enabled because this deployment has no transactional mail provider configured. There is no fake verification or reset flow.