🔐 You Stay Signed In Until You Logout
Logging in plants a stay-signed-in token in this browser that lasts about a
year and renews itself on every visit — closing the browser doesn't end it,
and your next visit to this page signs you in silently.
⚠ On a shared or borrowed computer, always use Logout — that
removes the token from that browser. Already left one behind somewhere?
Sign Out Everywhere on Update
Credentials ends every session at once.
📧 The Emailed Code on a New Browser
If qFIT doesn't recognize this browser, the login is held while a 6-digit
code is emailed to the address on the account. The code lasts
15 minutes and allows only a few wrong entries before you have to start
the login over. Google sign-ins go through the same check.
Entering the code marks this browser trusted indefinitely — you won't be
asked again here until you clear cookies or remove the device on
Preferences, which is also where the
check itself can be turned off.
🚫 Wrong Passwords Lock the Account
Several wrong tries in a short window lock the account temporarily — while it's
locked, even the correct password is refused. The "attempts remaining"
warning under the error is an exact count, not a scare line.
Locked out? Reset Password on Forgot
Login clears the lock along with sending a temporary password — and
Sign in with Google is deliberately unaffected by a password lockout.
🔗 What Sign in with Google Actually Does
The first Google sign-in whose Google email matches the email on an existing
qFIT account links Google to that account (you'll get a courtesy email).
From then on either method works — your username and password are untouched.
No matching account? You're taken to sign-up with your name and email prefilled —
every account still gets its own password. Google can be disconnected later on
Update Credentials.