Privacy
Crystal Prism accounts is the sign-in service for crystalprism.io and its apps. One person runs it. It has no ads, and it sells or shares nothing with anyone.
When you sign in with Google, Google tells us your name, email address and profile picture. We check only that Google has confirmed the address, then put a sign-in cookie in your browser that carries them. Nothing from Google is saved on our side, and we ask Google for nothing else.
When you create a password account, we keep your email address, the name you give (if any), when you confirmed the address, and your password as a one-way bcrypt hash, never the password itself. An account whose address is never confirmed is deleted after 30 days.
Emails we send you go out through Resend. We keep only a one-way fingerprint of each link, and delete it once the link expires: 24 hours for a confirmation link, one hour for a password reset.
To stop abuse, we count recent attempts against your email address and your IP address. Each count is deleted after its window closes, from 15 minutes to one day.
If you ask for a username on the original crystalprism.io site, we keep your email address and the name you asked for, and create that account on the site once it is approved.
Cookies: one sign-in cookie, shared by the crystalprism.io apps, plus the short-lived ones Google sign-in needs to finish safely. No analytics and no tracking.
Where it lives: account records are stored on Turso and the service runs on Vercel. When a page breaks, a report of the error and the page it happened on is sent so it can be fixed.
To have your account and everything tied to it deleted, email accounts@crystalprism.io from the address you sign in with. Each crystalprism.io app keeps its own data, so write to that app too. Last updated September 29, 2026.
Go to crystalprism.io