You do not need an account to connect to MUDs or use local client features. A free Smudgy account adds cloud map synchronization and sharing, friends, and package publishing.
Entering a new email address creates an account during the same flow. Smudgy does not ask you to create an account password.
Verify the email address before using friends, sharing, or synchronization. If the message does not arrive, check the address and spam folder before requesting another code.
Smudgy tries to protect the signed-in session credential in the operating system's credential store. If that store is unavailable, it uses an obfuscated file in the Smudgy data directory; obfuscation is not encryption. Account profile details are cached locally so the UI can identify the account while the service is temporarily unavailable. Signing out removes the local session credential; it does not delete local profiles, automations, packages, or maps.
Cloud features send the data needed for that feature to Smudgy's service. For example, sharing a map uploads mapping data and identifies the people who can access it. Do not put passwords or private game tokens in map names, room text, package metadata, or other fields you intend to share.
Open Settings → Security to see API keys and signed-in sessions.
If an API key secret is exposed, revoke the key and create a replacement. Editing a screenshot to cover a secret after capture is less safe than arranging the screen so the secret never appears.