Security

Set up two-factor authentication

Tidy Orders holds your bank activity and your tax-season reports. Two-factor authentication adds a second step at sign-in, so a stolen password isn't enough to get in. Setup takes about two minutes with any authenticator app.

What you'll need: a TOTP authenticator app on your phone or password manager — Google Authenticator, 1Password, Authy, Bitwarden, Duo Mobile, or the built-in iOS Passwords app all work. No SMS, no phone number required.

How 2FA works here

Tidy Orders uses time-based one-time passwords (TOTP). Your authenticator app stores a secret and generates a fresh 6-digit code every 30 seconds. After you enter your password, we ask for that code. Because the secret never travels over email or text, TOTP avoids the SIM-swap and phishing-forward weaknesses of SMS codes.

You also get eight one-time recovery codes at setup. They're your way back in if your phone is lost, wiped, or replaced.

Turn on your authenticator app

  1. Open Settings and find the Security card.
  2. Click Enable authenticator app.
  3. Scan the QR code with your authenticator app. If you're on the same device as your app — or a camera isn't available — use Can't scan? Enter this key manually and copy the setup key instead.
  4. Your app now shows a 6-digit code for "Tidy Orders". Type it into the dialog.
  5. Click Verify & enable.
Code rejected? TOTP is time-sensitive. If the code keeps failing, check that your phone's clock is set to update automatically — a clock that's off by more than ~30 seconds will generate codes we can't match.

Save your recovery codes

Immediately after verification, Tidy Orders shows eight recovery codes formatted like A7K2-9QMD. This is the only time they're displayed. Copy or download them and store them somewhere you can reach without your phone:

  • Your password manager, as a secure note on the Tidy Orders entry.
  • Printed and filed with your business records.
  • Not in your phone's notes app — that's the device you're protecting against losing.

Each code works once. We store only a SHA-256 hash of each one, so we can verify a code you enter but can never show you the list again or recover it on your behalf.

Signing in from now on

After you enter your email and password (or sign in with Google), a Two-factor authentication screen appears. Open your authenticator app, read the current 6-digit code, and enter it. That's the whole flow — the session stays verified until you sign out.

If you lose your phone

On the two-factor screen, choose Use a recovery code and enter one of your saved codes. What happens next is deliberate: a valid recovery code removes your enrolled authenticator and clears the remaining codes, then lets you finish signing in with just your password.

That means recovery is a reset, not a bypass. Your next step should always be to open Settings → Security and enroll your new phone right away — until you do, your account is back to password-only.

Heads up: recovery-code attempts are rate limited to five per 15 minutes per account, so a leaked email address alone can't be brute-forced.

Regenerating codes or turning 2FA off

  • Regenerate recovery codes — use this if you think your saved list was exposed, or after you've used one. Generating a new set immediately invalidates the old set.
  • Disable two-factor — we require a current 6-digit code first. That proves you still hold the authenticator, so someone who only stole your password can't quietly strip the protection off your account.

Switching phones? The cleanest path is to disable and re-enable on the new device while you still have the old one in hand, rather than burning a recovery code.

A few habits worth adopting

  • Store the TOTP secret in a password manager that syncs, so a lost phone isn't a lockout.
  • Keep recovery codes somewhere physically separate from your laptop and phone.
  • Re-enroll promptly after any recovery — a half-finished reset is the most common way accounts drift back to password-only.