Security Settings

Protect your account with passwords and two-factor authentication.

Keep your Own New account secure with strong passwords and two-factor authentication.

Accessing Security Settings

  1. Go to SettingsSecurity
  2. Manage your password, 2FA, and sessions

Changing Your Password

To update your password:

  1. Go to SettingsSecurity
  2. Click Change Password
  3. Enter your current password
  4. Enter your new password
  5. Confirm the new password
  6. Click Update Password

Password Requirements

Your password must be:

  • At least 8 characters long
  • Include a mix of letters and numbers
  • Not be a commonly used password

Password Tips

  • Use a unique password for Own New
  • Don't reuse passwords from other sites
  • Consider using a password manager
  • Change your password if you suspect it's been compromised

Two-Factor Authentication (2FA)

Add an extra layer of security to your account by requiring a code from your phone when signing in.

Setting Up 2FA

  1. Go to SettingsSecurity
  2. Find the Two-Factor Authentication section
  3. Click Enable 2FA
  4. Open your authenticator app (Google Authenticator, Authy, etc.)
  5. Scan the QR code shown
  6. Enter the 6-digit code from your app
  7. Save your backup codes somewhere safe
  8. Click Confirm

Using 2FA

After enabling 2FA:

  1. Sign in with your email and password
  2. You'll be prompted for a code
  3. Open your authenticator app
  4. Enter the current 6-digit code
  5. You're signed in

Backup Codes

When you enable 2FA, you'll receive backup codes:

  • Save these somewhere safe (not on your phone)
  • Use a backup code if you can't access your authenticator
  • Each code can only be used once
  • Generate new codes if you run out

Disabling 2FA

If you need to turn off 2FA:

  1. Go to SettingsSecurity
  2. Click Disable 2FA
  3. Enter a code from your authenticator (or a backup code)
  4. Confirm the change

Note: We recommend keeping 2FA enabled for security.

Active Sessions

View and manage devices where you're signed in:

  1. Go to SettingsSecurity
  2. Scroll to Active Sessions
  3. See all devices with active sessions

Each session shows:

  • Device type (desktop, mobile)
  • Browser
  • Location (approximate)
  • Last activity

Signing Out Other Devices

If you see a session you don't recognise:

  1. Click Sign Out next to that session
  2. The device will be logged out immediately
  3. Consider changing your password if you didn't recognise the session

Sign Out Everywhere

To sign out all devices:

  1. Click Sign Out All Devices
  2. You'll be signed out everywhere except this device
  3. Other devices will need to sign in again

Account Recovery

Forgot Password

If you can't remember your password:

  1. Go to the sign-in page
  2. Click Forgot Password
  3. Enter your email address
  4. Check your email for a reset link
  5. Click the link and set a new password

Lost 2FA Access

If you can't access your authenticator:

  1. Use one of your backup codes
  2. Or contact support at [email protected]
  3. You'll need to verify your identity

Security Best Practices

  1. Enable 2FA — Adds crucial protection
  2. Use strong passwords — Long and unique
  3. Check sessions regularly — Look for unfamiliar devices
  4. Sign out on shared devices — Don't stay logged in
  5. Keep email secure — Your email is used for password resets
  6. Report suspicious activity — Contact support immediately

Deleting Your Account

If you need to delete your account:

  1. Go to SettingsSecurity
  2. Scroll to Delete Account
  3. Click Delete Account
  4. Confirm by entering your password or a code
  5. Your account will be permanently deleted

Warning: Account deletion is permanent and cannot be undone. All your data will be removed.

Note: You cannot delete your account if you're the only Owner of an organisation. Transfer ownership first.

Getting Help

For security concerns:

  • Contact support immediately at [email protected]
  • Report suspicious activity
  • Change your password if you suspect compromise