Smart Incubator started as a Windows desktop system for one specific job: run the physical hardware around a clutch of eggs — sensors, a CNC pick-and-place arm, a camera — so an operator doesn't have to. The account layer you're looking at now exists to let that same login follow you to the web, not to replace the desktop app.
What runs where
The hardware automation and the web account are deliberately separate concerns.
Desktop app runs
Environment monitoring & relay automation — live, on the incubator
Candling, photography & scheduled imaging — twelve-step sequence per egg
Rotation, lockdown transfer & hatch countdown — fully automatic once taught
24-hour offline grace mode — keeps running if the connection drops
Cloud & website run
Account registration, email verification & sign-in — this site
Login attempt logging — every attempt, success or failure
Action-log sync from each device — for the admin log viewer
A web dashboard with graphs & photos — not built yet
Remote setpoint control from the web — not built yet
"Assumption: the spec doesn't say which board carries the relay — so the sender is injectable." Every module that touches hardware the spec doesn't fully pin down gets a line like that, on purpose, instead of a silent guess.
— the pattern behind every module in the build documentation
That habit extends to this website: the register, verify, and login pages document every assumption they make about the API they call, and this page won't tell you the web dashboard exists before it does. What's built is built, what's deferred says so.
Security & reliability
Carried over from the desktop app's own login screen, not reinvented for the web.
No account enumeration. Registering and signing in both give the same response shape whether or not an email is already on file.
Passwords are hashed, never reversible. The backend only ever stores and checks a hash, the same as the desktop app has always relied on.
Every login attempt is logged. Success or failure, with a timestamp, on the server — independent of anything logged locally.
Sessions aren't kept longer than they need to be. The desktop app encrypts its cached session with Windows' own per-user protection; this website keeps its session in the tab only, since there's no dashboard yet for it to outlive a closed browser for.
Ready to give your clutch an account of its own?
The web account is the same one the desktop app already asks for.