branch/work

Your account

How signing in works, what is connected to you, and how to leave.

Who can have an account

Branchwork is for UNC Charlotte students. An account requires an email address ending in charlotte.edu or uncc.edu. Departmental subdomains such as cs.charlotte.edu count.

Signing in

There are no passwords, anywhere, at all. You give us your address, we email you a link, the link signs you in. The link works once and expires in fifteen minutes.

Which means:

  • There is no password for you to reuse from another site, or to lose.
  • There is no password for us to store badly.
  • Whoever can read your university email can sign in as you. That is the trade. Keep your email account secure.

Sessions last fourteen days. Asking for too many links in a short window gets you throttled for a few minutes, which is there to stop someone flooding your inbox.

Your handle

Chosen once, when you first sign in, and permanent. Every profile link and every review attribution points at it, so changing it would break the record of work other people did with you. Your display name, bio, location and website are all editable under Settings.

Connected devices

Each machine running bw holds its own token. Settings, Devices lists them with when they were added and last used, and revokes any of them immediately.

Revoke a token if a laptop is lost or shared, or if you connected something you no longer use. The next command that device runs will be told to sign in again.

When you approve a device, check that the code in your browser matches the one in your terminal. That match is the whole security of the flow.

What we store

The short version: your email address, your profile, your work, your sessions and your tokens. No passwords, no payment details, no advertising cookies, no cross-site tracking. The privacy page is the full list, and it is short enough to actually read.

Deleting your account

Under Settings, Delete account. It takes two deliberate steps: type your handle to confirm, then click the link we email you. The link works once and expires in thirty minutes. Nothing is deleted until you click it, and ignoring the email leaves your account exactly as it was.

When you confirm:

  • Your profile, your page, your sessions, your tokens and your group memberships go.
  • Stacks you own are released rather than deleted.
  • Changes, revisions and reviews on shared work are reassigned to an anonymous account rather than erased.

That last one is deliberate. Your review of a teammate's code is part of the record of work they did, and deleting it out from under them would damage their history to tidy yours. If you need that handled differently, ask us.

It cannot be undone. There is no grace period and no restore.

Something unclear or wrong here? Tell us - that is a bug in the docs, and we treat it like one.