Account Security
Keep your account safe with two-factor authentication (MFA). This guide covers setting up, using, and managing MFA on your account.
- 1
Extra layer of security
Two-factor authentication (MFA) requires both your password and a verification code to sign in. Even if someone learns your password, they can't access your account without the code.
- 2
How it works
After entering your password, you'll be asked for a 6-digit code. This code changes every 30 seconds and comes from an authenticator app on your phone.
- 3
Who should enable it
MFA is optional but recommended for all users. It's especially important if your account has access to billing information or student records.
- 1
Install an authenticator app
Download Google Authenticator, Authy, or Microsoft Authenticator from your phone's app store. Any TOTP-compatible app will work.
- 2
Go to Settings
In the portal sidebar, click 'Settings'. Find the 'Two-Factor Authentication' card.
- 3
Click 'Set Up Two-Factor Authentication'
A QR code will appear on screen. If you can't scan QR codes, there's also a text code you can enter manually.
- 4
Scan the QR code
Open your authenticator app and scan the QR code. A new entry for 'MyDojang' will appear in your app with a 6-digit code that refreshes every 30 seconds.
- 5
Enter the verification code
Type the 6-digit code from your authenticator app into the verification field and click 'Verify & Enable'. This confirms your app is set up correctly.
- 6
Save your backup codes
You'll receive 10 one-time backup codes. Copy or download these and store them somewhere safe (not on your phone). You'll need these if you lose access to your authenticator app.
Keep Your Backup Codes Safe
- 1
Enter your password as usual
Log in with your email and password like normal. If MFA is enabled, you'll see a verification screen instead of going straight to the portal.
- 2
Choose your verification method
You can verify using your Authenticator App (default), a Backup Code, or Email (if you've enabled it). Use the tabs to switch between methods.
- 3
Enter the code
Type the 6-digit code from your authenticator app. The code auto-submits when you enter all 6 digits. If using a backup code, enter the 8-character code instead.
- 4
Remember this device
When verifying with MFA, you can check 'Remember this device for 30 days' to skip MFA on future logins from the same browser. You can revoke trusted devices from Account Settings at any time.
- 5
Access your account
After successful verification, you'll be redirected to the portal as usual. Your session stays active until you sign out.
- 1
Enable email codes
In Settings, toggle on 'Email verification code' in the MFA card. This gives you an additional way to verify besides your authenticator app.
- 2
How to use it
On the MFA verification screen during login, click the 'Email' tab, then 'Send Code'. A 6-digit code will be emailed to you.
- 3
Enter the email code
Check your email inbox (and spam folder) for the code. Enter it within 10 minutes before it expires.
- 1
Regenerate backup codes
If you've used some backup codes or want new ones, go to Settings > Two-Factor Authentication and click 'Regenerate Backup Codes'. You'll need to enter your password. This invalidates all previous codes.
- 2
Disable MFA
To turn off MFA, go to Settings > Two-Factor Authentication and click 'Disable MFA'. Enter your password to confirm. You can always re-enable it later.
- 3
Lost your authenticator device
Use a backup code to sign in. If you don't have any backup codes left, contact your studio — owners and administrators can reset MFA on your account.
- 4
After an MFA reset
If your studio resets your MFA, you'll be able to log in with just your password. You can then set up MFA again from Settings whenever you're ready.
MFA Prompt Banner
Having Trouble?
- 1
Sign-in is protected against guessing
To stop someone trying passwords against your account, repeated wrong passwords are counted and throttled. This protects every account automatically — there is nothing to switch on.
- 2
What you'll see
You'll get the same 'Invalid email or password' message you'd get from a typo. The message is intentionally identical so that nobody probing the login page can tell which email addresses belong to real accounts.
- 3
What to do
The pause applies to the device and network the wrong guesses came from, so nobody else can get you locked out of your own account. Wait about 15 minutes, or sign in from your usual device — a successful sign-in clears the count immediately. If you have forgotten your password, use the 'Forgot password?' link.
- 1
Go to Settings
In the portal or dashboard sidebar, click 'Settings'. Scroll to the 'Delete My Account' section near the bottom of the page.
- 2
Click 'Delete My Account'
A confirmation dialog will appear explaining what happens when you request account deletion.
- 3
Enter your password to confirm
Type your current password to confirm the request. This prevents accidental deletions.
- 4
30-day grace period begins
After confirming, a 30-day countdown begins. A warning banner will appear at the top of your screen reminding you of the pending deletion date. Your studio owner will also be notified.
- 5
What happens after 30 days
After the grace period ends, your account is automatically anonymized: your name, email, phone number, and password are removed. Any active billing subscriptions are cancelled. Your check-in history may remain for studio record-keeping, but it will no longer be linked to your identity.
- 6
Cancelling the deletion
Changed your mind? Click 'Cancel Deletion' in the warning banner that appears at the top of your screen. You can cancel at any time before the 30-day period ends. Your studio owner can also cancel on your behalf.
Account Deletion is Permanent
Studio Owners Cannot Delete Their Own Account This Way
- 1
Go to Settings
In the portal sidebar, click 'Settings'. Your children's cards are shown in the My Children section.
- 2
Tap the camera icon
Tap the camera icon on a child's photo to open a file picker. Select a JPEG, PNG, or WebP image (max 2MB).
- 3
Photo updates immediately
The avatar updates right away after you select a file — no page reload needed.
- 4
Remove a photo
Tap 'Remove photo' below the avatar to clear it. The silhouette placeholder will be shown instead.
- 5
Where photos appear
Photos appear on your child's profile and are included in printed reports and certificates issued by the studio.