Change your password and turn on two-factor authentication

Secure your Relatable account with a strong password and an authenticator app.

2 min readLast checked Aug 26, 2026

Your Relatable account holds your whole network: notes, histories, and how to reach everyone who matters to you. It's worth locking down properly.

Why it matters

A password alone is one weak link away from someone else getting into your relationships and your history with people. Two-factor authentication closes that gap: even if your password leaks, nobody gets in without the code on your phone too.

How it works

Relatable's two-factor authentication uses an authenticator app on your phone, like Google Authenticator or any similar app that generates time-based codes. You scan a QR code once to link your account, and from then on you enter a fresh six-digit code alongside your password each time you log in. There are no backup codes: the authenticator app is the only way in, so keeping your phone (or wherever you keep that app) safe matters.

How to use it

  1. On the web: go to Account settings → Two-Factor Auth.
  2. To turn on two-factor authentication, scan the QR code with your authenticator app, then enter the six-digit code it shows you to confirm setup.
  3. From then on, every login asks for your password and the current code from your app.
  4. To turn it off, you'll need to confirm your password first.
  5. To change your password, go to Account settings and update it there.

Good to know

  • There are no backup codes. If you lose access to your authenticator app, you lose your only way to generate a login code, so keep that device backed up or protected.
  • If you do lose access, contact support: Relatable can turn off two-factor authentication on your account so you can log back in and set it up again.
  • Your login session automatically expires after about a week, so you'll be asked to log in again periodically even if you never explicitly sign out.
  • Two-factor authentication is available to every user, not gated by plan.
  • If someone else regularly manages your account through delegated access, keeping two-factor authentication on your own login is still worth doing.

Related