oxedyne/daimond/www/guide/accounts.html
10.2 KiB, 1 run
created by r2519314175:1149, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | <!DOCTYPE html> |
| 2 | <html lang="en" data-guide-locale="en" data-guide-locales="en de es fr ja ko pt-BR zh-Hans"> |
| 3 | <head> |
| 4 | <meta charset="UTF-8"> |
| 5 | <meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover"> |
| 6 | <title>Accounts & privacy — Daimond guide</title> |
| 7 | <link rel="icon" type="image/svg+xml" href="../assets/daimond_mark.svg"> |
| 8 | <link rel="stylesheet" href="../css/variables.css"> |
| 9 | <link rel="stylesheet" href="../css/guide.css"> |
| 10 | <script src="frame.js"></script> |
| 11 | <script src="search-index.js"></script> |
| 12 | <script src="search.js"></script> |
| 13 | </head> |
| 14 | <body> |
| 15 | |
| 16 | <header class="site-head"> |
| 17 | <div class="site-head-inner"> |
| 18 | <a class="brand" href="index.html" aria-label="Daimond guide, home"> |
| 19 | <img class="wordmark wm-dark" src="../assets/daimond_word.svg" alt="Daimond" translate="no"> |
| 20 | <img class="wordmark wm-light" src="../assets/daimond_word_dark.svg" alt="Daimond" translate="no"> |
| 21 | <span class="brand-sub">Guide</span> |
| 22 | </a> |
| 23 | <nav class="site-nav" aria-label="Guide pages"> |
| 24 | <a href="index.html">Getting started</a> |
| 25 | <a href="interface.html">The interface</a> |
| 26 | <a href="models.html">Models & credits</a> |
| 27 | <a href="chats-and-diamonds.html">Chats & Diamonds</a> |
| 28 | <a href="capps.html">Capps</a> |
| 29 | <a href="email-web-files.html">Email, Web & files</a> |
| 30 | <a href="accounts.html" aria-current="page">Accounts</a> |
| 31 | <a href="sync.html">Cross-device sync</a> |
| 32 | <a href="spending.html">Spending</a> |
| 33 | <a href="machine-operations.html">Machine Operations</a> |
| 34 | <a href="social.html">Social</a> |
| 35 | </nav> |
| 36 | </div> |
| 37 | </header> |
| 38 | |
| 39 | <main> |
| 40 | <h1>Accounts & privacy</h1> |
| 41 | <p class="lede">An account in Daimond is a passphrase held on this device. There is no account on a server: your identity, your keys and your files live only in this browser. This page covers the passphrase, sharing a browser with other people, and what stays private.</p> |
| 42 | |
| 43 | <h2 id="s1">Your account is a passphrase</h2> |
| 44 | <p>On first run Daimond offers to <strong>protect this device</strong>. You give a name and a passphrase, and that passphrase becomes your account. It does two jobs: it encrypts your stored provider key and mail credentials so an onlooker cannot read them, and it is the identity that signs you in for credits. Nothing about it leaves the browser.</p> |
| 45 | |
| 46 | <div class="note"><strong>The passphrase is never stored and cannot be recovered.</strong> Daimond keeps only the encrypted data, not the passphrase that unlocks it. If you forget it, the encrypted keys and credentials are gone, so keep it somewhere safe. You can carry on without one by choosing <span class="ui">Skip for now</span>, but a provider key is best added once a passphrase is protecting it.</div> |
| 47 | |
| 48 | <h2 id="s2">A faster unlock with a passkey</h2> |
| 49 | <p>Once a passphrase is protecting the app you can add a <strong>passkey</strong> for a faster unlock: a face, a fingerprint or a security key, the same passwordless sign-in your device already offers. A passkey does not replace the passphrase but unseals it for you, so the passphrase stays the root and the always-available fallback, and a lost passkey costs nothing while you still hold it. None of this reaches a server: the unlock happens on the device, and the credits service only ever sees a public key.</p> |
| 50 | |
| 51 | <h2 id="s3">The account controls</h2> |
| 52 | <p>Your identity sits at the top of the admin panel, bottom-left. The admin home lists the controls for it:</p> |
| 53 | |
| 54 | <figure class="shot" data-shot="accounts-switch"> |
| 55 | <img alt="The account controls in the admin panel: change name, change passphrase, export or import a backup, log out, and forget this identity." src="shots/accounts-switch.png" loading="lazy"> |
| 56 | <figcaption>The account controls: change your name or passphrase, back up or restore, log out, or forget the identity entirely.</figcaption> |
| 57 | </figure> |
| 58 | |
| 59 | <ul> |
| 60 | <li><span class="ui">Change name…</span>: rename the identity.</li> |
| 61 | <li><span class="ui">Change passphrase…</span>: set a new one; your encrypted data is re-wrapped under it.</li> |
| 62 | <li><span class="ui">Add a passkey…</span>: a face, a fingerprint or a security key for a faster unlock.</li> |
| 63 | <li><span class="ui">Export a backup</span>: write your chats, Diamonds, workspace files and your account key to a file you keep. The key goes in wrapped, exactly as this browser holds it, so the file is no weaker than the browser and opens to nothing but your passphrase.</li> |
| 64 | <li><span class="ui">Import a backup…</span>: bring that file back here. Where this browser holds no account of its own the backup's account is adopted, and you unlock it with that account's passphrase; where an account is already here the backup's is left alone and only the work returns.</li> |
| 65 | <li><span class="ui">Log out</span>: lock the app. Your data stays on the device, encrypted, until the passphrase is entered again.</li> |
| 66 | <li><span class="ui">Forget this identity…</span>: remove the identity and its encrypted data from this browser for good.</li> |
| 67 | </ul> |
| 68 | <p>Two more rows sit alongside them. <strong>Syncing</strong> turns this device's sync on or off; stopping is immediate and loses nothing. <strong>Diagnostics</strong> shows and copies the app's own trail (event names and a clock, with no keys, no message text and nothing from your files), which is what to paste into a bug report.</p> |
| 69 | |
| 70 | <h2 id="s4">More than one person on one browser</h2> |
| 71 | <p>One browser can hold several accounts, each with its own chats, keys, credits and files. Nobody sees another account's data.</p> |
| 72 | <ul> |
| 73 | <li><strong>Stepping away.</strong> Choose <span class="ui">Log out</span> to lock the app. Your chats, keys and files remain on the device and cannot be read without your passphrase.</li> |
| 74 | <li><strong>Returning.</strong> Enter your passphrase to unlock. Every reload locks the app again, a hard refresh and a restarted browser included, because the key it derives is held in memory and never written to disk: nothing of yours is lost, and nothing opens until it is entered. A passkey, or a password manager holding the passphrase, supplies it for you.</li> |
| 75 | <li><strong>Someone else's turn.</strong> <span class="ui">+ Add another account</span> in the admin panel makes a second one, and the row above it switches between them. Switching locks this account first (its keys are forgotten) and then opens the other.</li> |
| 76 | <li><strong>Handing the browser over for good.</strong> <span class="ui">Forget this identity…</span> clears your account from this browser.</li> |
| 77 | </ul> |
| 78 | |
| 79 | <h2 id="s5">Moving your account between devices</h2> |
| 80 | <p>Your account is a signing key held in this browser. The passphrase does not recreate it, only decrypts the copy already stored here, so the same passphrase in a fresh browser starts a <em>separate</em> account with its own credits and no Pro. The key itself has to travel, and three things carry it: <span class="ui">Link another device</span>, which shows a pairing code to type into the new browser; a passkey, which stands a new device up in one gesture; and <span class="ui">Export a backup</span>, whose file holds the key wrapped for <span class="ui">Import a backup…</span> to adopt in a browser that has no account yet. Do one of them <strong>before</strong> you remove a browser: once its storage is gone, and no backup was taken, the key is gone with it, and with it the credits and any Pro licence, which nothing else unlocks.</p> |
| 81 | <div class="note"><strong>A backup holds your work in the clear and your key under your passphrase.</strong> Every chat, Diamond and workspace file is in it as plain text, so keep it as private as the work itself. The key beside them is wrapped, so importing the file alone makes nobody you, but whoever holds the file and the passphrase holds the account, which is why the two should never travel together.</div> |
| 82 | |
| 83 | <h2 id="s6">What stays private</h2> |
| 84 | <p>Your passphrase, provider keys, mail credentials, chats, Diamonds and files live in this browser and are not sent to us. What we hold on the gateway is money and ciphertext: your credit balance and licences, and, for cross-device sync, one encrypted parcel we cannot open. We do not have the key, so we cannot read your work.</p> |
| 85 | <p>Where data goes bears saying exactly. Your messages reach a model provider directly with your own key, or through our metered service when you spend credits. Fetching a page, and syncing or sending mail, pass through the gateway, and a sync carries an encrypted parcel between your own devices. So the honest claim is not that nothing ever leaves: it is that with your own key your chats and files never leave in the clear, and you can watch only ciphertext leave for our servers.</p> |
| 86 | <div class="note"><strong>You need not take that on trust.</strong> Daimond's client (the code running in this browser, which decides what is sent) is open source. Read it, build it, and open your browser's network panel to confirm that only ciphertext leaves. The one claim every private tool makes, we let you check: <a href="https://github.com/oxedyne-com/daimond">github.com/oxedyne-com/daimond</a>.</div> |
| 87 | <p>The protection has honest limits. The passphrase guards against casual local inspection and shared-device snooping: someone opening the browser's developer tools finds encrypted data and not your keys. It is no guard against a compromised browser, a malicious extension or a keylogger, which defeat any in-browser scheme, so keep the device itself trustworthy. And what a remote server does inside itself cannot be proven from outside, which is why it is the client, the part you can check, that we open to you.</p> |
| 88 | |
| 89 | <div class="next"> |
| 90 | <a href="email-web-files.html">← Email, Web & files</a> |
| 91 | <a href="sync.html">Next: Cross-device sync →</a> |
| 92 | </div> |
| 93 | </main> |
| 94 | |
| 95 | <footer class="site-foot"> |
| 96 | <span>Daimond runs in your browser. Nothing here is sent to us.</span> |
| 97 | <nav aria-label="Guide pages"> |
| 98 | <a href="index.html">Getting started</a> |
| 99 | <a href="interface.html">Interface</a> |
| 100 | <a href="models.html">Models</a> |
| 101 | <a href="chats-and-diamonds.html">Chats & Diamonds</a> |
| 102 | <a href="capps.html">Capps</a> |
| 103 | <a href="email-web-files.html">Email, Web & files</a> |
| 104 | <a href="accounts.html">Accounts</a> |
| 105 | <a href="sync.html">Cross-device sync</a> |
| 106 | <a href="spending.html">Spending</a> |
| 107 | <a href="machine-operations.html">Machine Operations</a> |
| 108 | <a href="social.html">Social</a> |
| 109 | </nav> |
| 110 | </footer> |
| 111 | </body> |
| 112 | </html> |