Documentation

Profile & Security

Path: /profile. Account-level (cross-workspace) settings.

Personal data

  • First name, last name, nickname
  • UI language (defaults from browser)
  • Time zone
  • Avatar

Appearance (theme)

  • Theme: Light / Dark / System (Dark is in beta — top-level surfaces done, components being tuned)
  • Density: Comfortable / Compact — Compact shrinks rows and padding for data-heavy work on smaller screens
  • Accent color: Brand default / Teal / Blue / Violet / Amber / Green / Crimson — colors buttons, links, active-state highlights

Login & password

  • Change password
  • Reset password by email (link valid 1 hour)
  • Email verification
  • Connected accounts (Google / GitHub OAuth)

Passkeys (passwordless login)

Passwordless login per the WebAuthn standard (Touch ID, Windows Hello, hardware key). Requires recent Chrome / Safari / Firefox / Edge.

  1. Profile → Passkeys → "Add passkey"
  2. Confirm with biometrics / PIN
  3. On next login, Sytalog offers passkey as the primary method

Two-factor authentication (2FA)

Profile → Two-factor authentication → "Enable":

  1. Sytalog shows a QR code
  2. Scan it in Google Authenticator / 1Password / Authy
  3. Enter the first TOTP code
  4. Save your backup codes — without them, losing the 2FA device requires support intervention

Active sessions

Profile → Sessions → list of active sessions (device, browser, IP location, last activity).

  • Log out a specific session
  • Log out of all others — in case of a lost phone

Delete account

Profile → Danger → "Delete account" → confirm with password.

  • Personal data, sessions, passkeys, 2FA are removed within 30 days
  • Workspaces where you were the Owner stay — someone else must delete or take them over
  • Offers and files in other workspaces stay (they don't belong to you personally)
Warning: Deletion cannot be undone.

Offer tracking & recipient privacy

  • Email opens (1×1 pixel) — weak signal, pre-render filters applied
  • Public link views — strong signal
  • Mail provider pre-render (Outlook safe-link, Gmail prefetch) — detected and separable in Activity
  • Recipient IP is anonymized to /24 (IPv4) or /64 (IPv6) before storage
  • No cookies, no fingerprints on the recipient device

GDPR / DPA

Sytalog is a data processor for end-customer personal data. Hosting is in the EU (exact DC depends on deployment).

A DPA is available on request (typically Enterprise + Provoz). Contact sales / support for the DPA document and a description of security measures.