Loading…
A password can be guessed, reused or stolen. A six-digit code that changes every 30 seconds cannot — it lives only on your phone.
Open your authenticator app (Google Authenticator, 1Password, Authy — any of them) and scan this:
Can't scan? Type this key into the app instead:
✓ Two-factor authentication is on. From now on you'll be asked for a code every time you log in.
If you lose your phone there is no backup code to fall back on — write to [email protected] from the address of your account and we turn it off after checking who you are. We say this now, not the day it happens.
Everything in it goes with it. We take 7 days, so a wrong click can be undone.
What goes: your account, the sites you registered and their keys, the packages we
build for them, drafts, AI-bot visit counts and tracked prompts.
What stays, without pointing at you any more: the audits you ran, kept as
measurements; invoices, for as long as tax law requires; and the record of sensitive
actions, which keeps what happened, never who.
If you connected a site through Cloudflare, remove the haAplo Worker from your Cloudflare account too: once your account is gone we can't switch it off for you.