Account
Sign in with Google, GitHub, X or Twitch
What each provider shares, why X asks for an email afterwards, where to revoke access, and what to do if the email is already taken.
Updated
What we receive
| Provider | Fields shared | Email? |
|---|---|---|
| Email address, name | Yes | |
| GitHub | Email address, name | Yes |
| Twitch | Email address, user id, login, display name, avatar | Yes |
| X | Account id, username, name, avatar | No |
The sign-in token the provider issues is used once and discarded; we never store it and cannot act on your provider account later. We ask for the minimum read-only scope and never post, read messages or take any action there.
The email step for X
Because X shares no email address, the site shows a short "One more thing" step after you authorise: type an email address, and we send a verification link to it. The account exists immediately but is unverified until you click the link, and checkout and the creator program wait for that. Disposable addresses are rejected.
The terms box
A new account is only created after you tick the box confirming you have read the Terms of Service and acknowledge the Privacy Policy. On the sign-up page the box sits above the provider buttons; if you started from the sign-in page and have no account yet, the "One more thing" step asks for it. We record which version of the Terms you accepted, when, and from which address and browser. Signing in to an existing account never asks again.
Revoking access
Google: myaccount.google.com/permissions. GitHub: github.com/settings/applications. Twitch: twitch.tv/settings/connections. X: x.com/settings/connected_apps. Because we hold no token, revoking changes nothing on our side except that you will authorise again next time.
The email already has an account
If the address the provider shares (or that you type) already belongs to an account, sign-in stops with "That email already has an account". Sign in the way you did before. See Email already in use.
A provider button does nothing
That provider is not configured on our side yet. Use another method or email support. See OAuth sign-in errors.