Signing in
There is no password
Verdemar has never had one. You sign in either with a one-time link sent to your email address, or with your Google account. There is no password to guess, to reuse somewhere it shouldn't be reused, or to find in somebody else's breach, and no password for us to store, which means no store of them to lose.
The email route is checked by Cloudflare Turnstile before it reaches our authentication provider, so an automated attempt to work through a list of addresses does not get that far. The Google route uses PKCE: the code Google hands back is tied to a secret your own browser generated and never sent anywhere, so intercepting the code on its own gets an attacker nothing.
The practical consequence is worth stating, because it moves rather than removes the risk: whoever controls your email account, or your Google account, can reach your Verdemar account. Protect those two the way you would protect a bank login, with a second factor on each.