Help Center

Account Security

Keep your account safe with two-factor authentication (MFA). This guide covers setting up, using, and managing MFA on your account.

What is Two-Factor Authentication?
  1. 1

    Extra layer of security

    Two-factor authentication (MFA) requires both your password and a verification code to sign in. Even if someone learns your password, they can't access your account without the code.

  2. 2

    How it works

    After entering your password, you'll be asked for a 6-digit code. This code changes every 30 seconds and comes from an authenticator app on your phone.

  3. 3

    Who should enable it

    MFA is optional but recommended for all users. It's especially important if your account has access to billing information or student records.

Setting Up MFA
  1. 1

    Install an authenticator app

    Download Google Authenticator, Authy, or Microsoft Authenticator from your phone's app store. Any TOTP-compatible app will work.

  2. 2

    Go to Settings

    In the portal sidebar, click 'Settings'. Find the 'Two-Factor Authentication' card.

  3. 3

    Click 'Set Up Two-Factor Authentication'

    A QR code will appear on screen. If you can't scan QR codes, there's also a text code you can enter manually.

  4. 4

    Scan the QR code

    Open your authenticator app and scan the QR code. A new entry for 'MyDojang' will appear in your app with a 6-digit code that refreshes every 30 seconds.

  5. 5

    Enter the verification code

    Type the 6-digit code from your authenticator app into the verification field and click 'Verify & Enable'. This confirms your app is set up correctly.

  6. 6

    Save your backup codes

    You'll receive 10 one-time backup codes. Copy or download these and store them somewhere safe (not on your phone). You'll need these if you lose access to your authenticator app.

Signing In with MFA
  1. 1

    Enter your password as usual

    Log in with your email and password like normal. If MFA is enabled, you'll see a verification screen instead of going straight to the portal.

  2. 2

    Choose your verification method

    You can verify using your Authenticator App (default), a Backup Code, or Email (if you've enabled it). Use the tabs to switch between methods.

  3. 3

    Enter the code

    Type the 6-digit code from your authenticator app. The code auto-submits when you enter all 6 digits. If using a backup code, enter the 8-character code instead.

  4. 4

    Remember this device

    When verifying with MFA, you can check 'Remember this device for 30 days' to skip MFA on future logins from the same browser. You can revoke trusted devices from Account Settings at any time.

  5. 5

    Access your account

    After successful verification, you'll be redirected to the portal as usual. Your session stays active until you sign out.

Email Verification (Optional)
  1. 1

    Enable email codes

    In Settings, toggle on 'Email verification code' in the MFA card. This gives you an additional way to verify besides your authenticator app.

  2. 2

    How to use it

    On the MFA verification screen during login, click the 'Email' tab, then 'Send Code'. A 6-digit code will be emailed to you.

  3. 3

    Enter the email code

    Check your email inbox (and spam folder) for the code. Enter it within 10 minutes before it expires.

Managing & Disabling MFA
  1. 1

    Regenerate backup codes

    If you've used some backup codes or want new ones, go to Settings > Two-Factor Authentication and click 'Regenerate Backup Codes'. You'll need to enter your password. This invalidates all previous codes.

  2. 2

    Disable MFA

    To turn off MFA, go to Settings > Two-Factor Authentication and click 'Disable MFA'. Enter your password to confirm. You can always re-enable it later.

  3. 3

    Lost your authenticator device

    Use a backup code to sign in. If you don't have any backup codes left, contact your studio — owners and administrators can reset MFA on your account.

  4. 4

    After an MFA reset

    If your studio resets your MFA, you'll be able to log in with just your password. You can then set up MFA again from Settings whenever you're ready.

Too Many Failed Sign-In Attempts
  1. 1

    Sign-in is protected against guessing

    To stop someone trying passwords against your account, repeated wrong passwords are counted and throttled. This protects every account automatically — there is nothing to switch on.

  2. 2

    What you'll see

    You'll get the same 'Invalid email or password' message you'd get from a typo. The message is intentionally identical so that nobody probing the login page can tell which email addresses belong to real accounts.

  3. 3

    What to do

    The pause applies to the device and network the wrong guesses came from, so nobody else can get you locked out of your own account. Wait about 15 minutes, or sign in from your usual device — a successful sign-in clears the count immediately. If you have forgotten your password, use the 'Forgot password?' link.

Deleting Your Account
  1. 1

    Go to Settings

    In the portal or dashboard sidebar, click 'Settings'. Scroll to the 'Delete My Account' section near the bottom of the page.

  2. 2

    Click 'Delete My Account'

    A confirmation dialog will appear explaining what happens when you request account deletion.

  3. 3

    Enter your password to confirm

    Type your current password to confirm the request. This prevents accidental deletions.

  4. 4

    30-day grace period begins

    After confirming, a 30-day countdown begins. A warning banner will appear at the top of your screen reminding you of the pending deletion date. Your studio owner will also be notified.

  5. 5

    What happens after 30 days

    After the grace period ends, your account is automatically anonymized: your name, email, phone number, and password are removed. Any active billing subscriptions are cancelled. Your check-in history may remain for studio record-keeping, but it will no longer be linked to your identity.

  6. 6

    Cancelling the deletion

    Changed your mind? Click 'Cancel Deletion' in the warning banner that appears at the top of your screen. You can cancel at any time before the 30-day period ends. Your studio owner can also cancel on your behalf.

Your Child's Profile Photo
  1. 1

    Go to Settings

    In the portal sidebar, click 'Settings'. Your children's cards are shown in the My Children section.

  2. 2

    Tap the camera icon

    Tap the camera icon on a child's photo to open a file picker. Select a JPEG, PNG, or WebP image (max 2MB).

  3. 3

    Photo updates immediately

    The avatar updates right away after you select a file — no page reload needed.

  4. 4

    Remove a photo

    Tap 'Remove photo' below the avatar to clear it. The silhouette placeholder will be shown instead.

  5. 5

    Where photos appear

    Photos appear on your child's profile and are included in printed reports and certificates issued by the studio.

MyDojang