Account
Security & Privacy
Two-factor authentication, session management, and data privacy.
Two-Factor Authentication (2FA)
Add an extra layer of security with TOTP-based 2FA.
Setting Up 2FA
- Go to Settings → Security
- Click Setup 2FA
- Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password)
- Enter the 6-digit code to verify
- 2FA is now active. You'll need your authenticator on each login
Brute-Force Protection
After 5 failed 2FA attempts, your account is locked for 15 minutes.
Backup codes
When you enrol in 2FA we generate ten one-time backup codes. Save them somewhere safe. A password manager is ideal. Each code works exactly once and lets you sign in if you lose access to your authenticator. There is no separate regenerate button. To get a fresh set, disable 2FA at Settings → Security and enrol again. That issues ten new codes and invalidates the old ones. Do this before you run low, not after: if you lose both your authenticator and your codes, we cannot restore access from the app and you will need to contact support.
Lost authenticator + lost backup codes
Use one of the 10 backup codes you saved when you enrolled: on the two-factor prompt, choose to enter a backup code instead of an authenticator code. Each code works once. If you've lost your codes as well as your device, contact support from the email address on the account.
Password reset
Forgotten password? Click Forgot password? on the login page (or visit /forgot-password directly) and we'll email a one-time reset link. The link expires in 60 minutes; request a new one if it does. Active sessions are signed out the moment you set a new password.
Session Management
View and control active sessions in Settings → Security:
- See all devices currently logged in (device type, browser, IP, last active)
- Revoke individual sessions
- Revoke All Others to sign out everywhere except your current device
New Device Alerts
When a login is detected from a new device or IP address, ReachSurge sends an email alert. If it wasn't you, secure your account immediately.
Data Privacy (GDPR)
In Settings → Privacy:
- Download your data: export all your data as JSON or CSV
- Request account deletion: when you submit a deletion request you enter a 30-day grace period. During that window the data is preserved and you can cancel the request from the same page. We also automatically stop your next subscription renewal so you aren't billed during the grace window. If you cancel the deletion request, you'll need to reactivate the subscription from Billing to keep paying. After 30 days the cron job purges your account permanently, satisfying GDPR Article 17.
Audit Log (Enterprise)
Enterprise plans include a full audit log in Settings → Audit Log:
- Track all account activity (logins, settings changes, team modifications)
- Browse the full history and export it as CSV
- Export as CSV
FAQ
Is my data encrypted? Yes, all data is encrypted at rest and in transit via Supabase's built-in encryption.
Can I disable 2FA? Yes, go to Settings → Security and click disable. You'll need to enter a code to confirm.
What data is included in the GDPR export? Profile, websites, generated pages, citations, backlinks, notifications, achievements, and integration settings (excluding API secrets).