Account security is shared work. On our side: your password is stored only as a secure hash, every sign-in attempt is logged, and every emailed link is one-time and short-lived. On your side: a long password that is unique to this account, kept confidential, and a quick word to us if anything looks wrong.
Choosing a strong password
- Use at least 8 characters, and longer is better. Length is what makes a password hard to guess.
- We deliberately do not force symbols, digits, or capitals. Those rules push people toward predictable passwords written on sticky notes.
- Your password cannot be your email address.
- Use a password you use nowhere else. A password manager makes that easy.
What we do on our side
- Your password is stored only as a secure hash, never as plain text. Nobody here can read it.
- Every sign-in attempt, successful or failed, is logged with the IP address and browser used, for security and fraud prevention. Sign-in security logs are kept up to 12 months, per the Privacy Policy.
- Password reset links expire after one hour and work once. The moment a password is set, every outstanding link for your address is cancelled.
- A suspended account cannot sign in by any method, including Google, Apple, and Microsoft.
Your responsibilities
Section 20 of the Terms of Use puts it plainly: keep your password confidential, you are responsible for activity under your account, and tell us promptly if you suspect unauthorized use.
Everyday habits that matter
- Sign out on shared computers. A session can last up to 30 days on a device.
- Keep the email address on your account current, and use one you actually read. It is where your invoices, renewal notices, and legal notices go.
- If anything looks off, reset your password immediately: Forgot Your Password takes about a minute.
If you suspect unauthorized use, reset your password first, then contact us right away. A person reads it and acts on it.
Was this helpful?