Signing in to the feedback portal

The available methods, why sign-in is required, and what a portal account is not.

Written By Dustin

Last updated 18 minutes ago

Sign in with GitHub, Google, or Discord, or with an email address and a password. These are the portal vendor's own methods; TOVIO adds none and removes none.

Why sign-in is required to post or vote

Guest posting, voting, and commenting are switched off. The reason is practical rather than bureaucratic: an anonymous poster or voter can never be notified — not when someone asks a clarifying question, and not when the thing they asked for ships. An anonymous vote is a number that can never be closed back to a person, which makes it worth less to you than to us.

What a portal account is not

It is not a TOVIO account. It does not authenticate you to the hosted service, the web app, or any repository. A portal session is never treated as authentication elsewhere, even though the portal sits on a tovio.dev subdomain and a cookie scoped to the parent domain would reach it. That invariant is written down for exactly that reason.

It is also unrelated to your TOVIO identity keys, which live on your own devices and never reach the portal.

Single sign-on is deliberately never enabled

Portal SSO is out of scope and is not planned. Turning it on would disable every other sign-in method, and it would bind the portal to a hosted-service sign-in that does not exist yet. A future identity integration, if it ever happens, is a separate recorded decision that must first settle whether an email address is shared at all.

Posts filed on your behalf

An operator files a post under your email only after asking in writing and receiving a yes, and that consent is logged with the post address. Without it, they write the post themselves and follow up with you by email instead. An on-behalf post creates a contact record and does not notify you, which is precisely why the consent is asked for first.

Moderation

New posts are reviewed before they appear. That stays on until general availability, because it is the only control that keeps an accidentally posted vulnerability or a pasted repository fragment out of public view.

Removing your account

Write to privacy@tovio.dev. See Request your data, or its deletion.