Signing up and signing in
Sign up with an email address and a password of twelve characters or more, or with Google. A verification email arrives; the account works fully once it is verified. Passwords that appear in known breaches are refused at sign up and at every change, with a plain message.
Sign in with the same. A wrong email and a wrong password get the same answer, so nothing here tells anyone whether an address has an account. After too many tries from one place, sign in pauses for a while and says how long.
Two factor authentication. On the account page, set up an authenticator app. You get recovery codes once; save them. With it on, sign in asks for the six digit code every time.
Sensitive changes ask for your password again: changing the email, the password, two factor, deleting the account, connecting or disconnecting a calendar or mail account, changing the AI key, and opening the billing portal. If you sign in with Google and have no password, you confirm with Google instead.
Sessions. "Sign out everywhere" ends every session including this one. Changing your password does the same for every other session.
Recent activity on the account page lists sign ins, failed sign ins, changes and everything R2 did on your behalf, with times.