Built for controlled account and sync flows.
Passwords are hashed with Node's crypto.scrypt. Email verification, password reset, session, and OAuth state tokens are stored hashed and expire automatically. OAuth callbacks validate the state that was created when sign-in started.
Hosting
The service can run behind Caddy, Nginx, Cloudflare Tunnel, or a managed platform proxy. Production deployments should use HTTPS, persistent storage, SMTP delivery, provider secrets in environment variables, and regular backups.
Imports
Contact and social imports are designed to avoid central credential collection. The backend receives normalized birthday rows after user review.