Help & Documentation
Offline-first guidance for safe gear lists.
Account Security
Two-factor authentication, recovery codes, sessions, and deleting your account
Everything that protects access to your account lives in Settings → Security & Privacy: turning on two-factor authentication (2FA), saving recovery codes, changing your password and email, reviewing the devices you're signed in on, and permanently deleting the account. Security-critical changes always ask you to re-enter your password — and your 6-digit code too, once 2FA is on.
Where account security lives
All of these controls are on one screen. Open Settings, then the 'Security & Privacy' tab. Scroll to the area you need.
- 'Email & Password' — change your sign-in email or password.
- 'Two-Factor Authentication' — add an authenticator app and manage recovery codes.
- 'Sessions & Devices' — see where you're signed in, revoke a session or sign out all other devices, and your device ID.
- 'Danger Zone' — sign out of this device and delete the account.
Tips
- Changing anything sensitive asks for your current password again. That's deliberate — it stops someone using an unlocked screen.
- Once 2FA is on, those same actions also ask for a 6-digit code.
Turn on two-factor authentication
Two-factor authentication adds a second step at sign-in: after your password, you enter a 6-digit code from an authenticator app. Even if someone learns your password, they can't get in without your phone.
- Open Settings → Security & Privacy and find 'Two-Factor Authentication'.
- Click 'Add authenticator app'. A dialog shows a QR code and a text secret.
- In your authenticator app (Google Authenticator, 1Password, Authy, Microsoft Authenticator…), scan the QR code — or type the secret if you can't scan.
- Your app now shows a 6-digit code that rotates every 30 seconds.
- Type that code into the verification field and confirm.
- On success, a 'Save your recovery codes' window appears — do not skip it (see the next section).
Tips
- Any standard TOTP authenticator works; you're not tied to one brand.
- The QR code is single-use. If you close the dialog before finishing, reopen 'Add authenticator app' to get a fresh one.
Common Pitfalls
- Closing the recovery-codes window without saving the codes — you can't see them again, only regenerate.
- A code rejected as wrong is usually a clock-skew issue; wait for the next code and check your phone's time is set automatically.
Recovery codes — your backup way in
When you first enable 2FA you're shown a set of one-time recovery codes. If you ever lose your authenticator app, a recovery code gets you back into your account. This is the safety net — treat it like a spare key.
- You get a fixed set of single-use codes. Each one works exactly once.
- 'Copy' puts them on the clipboard; 'Download' saves a small text file.
- You must tick 'I have saved my recovery codes in a safe place' before the window will close.
- The codes are shown only once. They are never displayed again — you can only regenerate a fresh set.
- Regenerating new codes immediately invalidates all the old ones.
Tips
- Store them somewhere separate from your phone — a password manager, or printed and locked away.
- If you've used several codes, regenerate to get a full set again.
Common Pitfalls
- Saving recovery codes in the same place as your authenticator — if you lose the phone you lose both.
- Assuming a used code still works. Once redeemed, it's gone.
Manage or remove your authenticator
Enrolled authenticators are listed under 'Two-Factor Authentication'. From here you can remove a factor or generate a new set of recovery codes — both require your password.
- To remove an authenticator, click 'Remove' next to it and enter your password to confirm.
- Removing your last remaining factor switches 2FA off entirely.
- To refresh your backup codes, click 'Regenerate recovery codes', enter your password, and save the new list.
- Acknowledge that the previous codes stop working before the new ones are shown.
Tips
- Set up a second authenticator (for example on a backup phone) before removing the first, so you're never locked out.
- Regenerating codes is the right move any time you suspect your saved list was exposed.
Add a passkey
Passkeys are not switched on in the released app yet: until they are, 'Add a passkey' does not appear and the authenticator app is your second step. Once enabled, a passkey lets you clear the second step with Touch ID, Face ID or a security key instead of typing a 6-digit code. It replaces the CODE, not your password — you still sign in with your email and password first, then confirm with the passkey.
- Open Settings → Security & Privacy → Two-Factor Authentication and click 'Add a passkey'.
- Give it a name that tells your devices apart — 'MacBook Touch ID', 'YubiKey' — so the factor list stays readable.
- Click 'Register passkey' and confirm on your device when it asks.
- The passkey then appears in the factor list beside any authenticator apps, and can be removed the same way.
Tips
- If this is the first second factor you add, your one-time recovery codes are shown straight afterwards — save them before closing the panel.
- You can register several passkeys, one per device, and still keep an authenticator app as well.
- Changed your mind mid-way? Dismissing your device's prompt simply cancels the registration — nothing is saved and nothing is broken.
Common Pitfalls
- Expecting to sign in with only a passkey. It is a second step, not a password replacement — the sign-in screen still asks for your password first.
- Looking for it in the mobile apps. Passkeys are web-only: the iOS and Android apps hide the option entirely, and so does a browser without passkey support.
Signing in with 2FA
With 2FA on, after your password you'll see a challenge screen asking for your 6-digit code. This screen is a gate — you can't click past it; you either pass the check or sign out.
- Enter the current 6-digit code from your authenticator app.
- Have a passkey on this device (where passkeys are switched on)? Click 'Use a passkey instead' and confirm with Touch ID, Face ID or your security key.
- Lost your phone? Click 'Lost your authenticator? Use a recovery code' and enter one of your backup codes instead.
- If you can't do either, click 'Sign out' to return to the sign-in screen.
Tips
- A recovery code used here is consumed — cross it off your saved list.
- If you've lost both your authenticator and every recovery code, you'll need to contact support to recover the account.
Common Pitfalls
- Typing an expired code. Codes rotate every 30 seconds; use the one showing right now.
Change your password
Update your sign-in password from the 'Email & Password' area. You can also end every other session at the same time — useful after a shared or lost device.
- Enter your current password.
- Enter a new password (at least 8 characters, with an uppercase letter, a number, and a special character). Strength feedback appears as you type.
- Confirm the new password.
- Optionally tick 'Sign out of all other devices'.
- If 2FA is on, enter your 6-digit code, then confirm with 'Change password'.
Tips
- Ticking 'Sign out of all other devices' is the fast way to lock out a device you no longer have.
- Forgot the current password? Sign out and use 'Forgot password?' on the sign-in screen instead.
Change your email address
Your email is your sign-in identity. Changing it needs your password (and your 2FA code, if enabled), then a confirmation click in your inbox.
- Enter the new email address.
- Enter your current password to confirm it's you.
- If 2FA is on, enter your 6-digit code.
- Click 'Update email'. A verification message is sent to the new address.
- Open that message and click the link to finalise the change.
Common Pitfalls
- Forgetting the verification step — the change only takes effect after you click the link in the new inbox.
- Mistyping the new address. The verification email goes to whatever you entered; if it never arrives, double-check the spelling.
Active sessions & devices
'Sessions & Devices' lists everywhere your account is currently signed in. Revoke anything you don't recognise. Your device ID is also here, handy when contacting support.
- Each entry shows the device, browser, and when it was last active. Your current device is badged.
- 'Revoke' signs out a single other device's cloud access immediately.
- 'Sign out all other devices' ends every session except the one you are using — this device stays signed in.
- Your device ID can be copied with one click for support diagnostics.
Tips
- Revoking ends cloud sync for that device; data already stored locally on it isn't wiped.
- An offline device stays listed until it reconnects and notices the session is gone.
Delete your account
Deleting is permanent and irreversible — it removes your profile, projects, gear lists, contacts, and your accounting records. Because German law requires you to keep invoices for ten years, the flow makes you download your tax records first.
- Open the 'Danger Zone' and click 'Delete account'.
- Click 'Download tax records (GoBD)' and let it finish — this is your legally required 10-year copy. Your invoices are encrypted, so this file is built on the device you are using: if that device has not synced all of them yet, the download stops and tells you how many are missing. Wait for sync to finish, or delete from a device that has them.
- Optionally click 'Download full backup' for everything else.
- Enter your current password, and your 6-digit code if 2FA is on.
- Type 'DELETE' in the confirmation field.
- Tick the box confirming you've downloaded your data, then click 'Permanently delete account'.
Tips
- The delete button stays disabled until every gate is met: backup acknowledged, 'DELETE' typed, password (and code) entered.
- After the account is deleted, the app also clears this device's local data and reloads — download everything you want to keep first.
Common Pitfalls
- Skipping the tax-records download. Once the account is gone, those invoices can't be recovered — and you're still legally required to retain them.
- Treating this as a pause. There is no undo and no soft-delete.
Two minutes of setup — an authenticator app plus saved recovery codes — is the single biggest thing you can do to protect your account. Do it once, store the codes somewhere safe, and keep your sessions list tidy.
Related Topics
See also
