# Account & security

Your account is a pseudonym with money attached. Both halves deserve protection. Here's every account control and what it does.

## Your handle

Your handle (@whatever) is your entire public identity — it's what shows on requests, applications, chat, ratings, and the Hall of Fame. Your legal name, email, and payment details never appear anywhere public.

- 3–30 characters, lowercase letters, numbers, and underscores.
- Offensive or impersonating handles get reclaimed — see the [rules](/rules).
- Pick something you can live with; it's your byline on everything you do here.

## Email

Your email is for signing in and notifications, nothing public. Change it in **Settings → Security**: we send a confirmation link to the *new* address, and nothing changes until you click it. Until verified, your account stays on the old address — so a typo can't lock you out.

## Password & two-factor

- **Password:** change it in Settings → Security. We sign out your other devices when you do, on purpose.
- **Two-factor (2FA):** a 6-digit TOTP code from any authenticator app (Google Authenticator, 1Password, Authy…). Enable it in Settings → Security: confirm your password, scan the QR, enter a code. You'll get **backup codes** — download them, store them somewhere that isn't a screenshot in your camera roll. Each works once if you lose your device.
- Lost the device *and* the backup codes? [Contact us](/contact) — recovery involves a human and some patience, by design.

2FA is the single best thing you can do for account safety. An account with payouts flowing through it deserves it.

## Sign-in with Google

If you signed up with Google, your sign-in security rides on your Google account — protect that accordingly. You can still set a password for direct sign-in.

## Connected apps (AI assistants & integrations)

Connected an AI assistant via [MCP](/docs/mcp)? Each connection appears in **Settings → Connected apps**, showing what it's allowed to do. Revoke any of them with one click — the app loses access immediately. Audit this list occasionally, like you (should) do with your Google account.

## Blocking people

Someone you'd rather never hear from again? **Block them** — the button lives on their profile, and your block list lives in [profile settings](/settings/profile). A blocked person can't apply to your requests, send you direct requests, or message you. They're not notified, and unblocking takes one tap.

One deliberate exception: if you two have a job actively in flight (picked, money in escrow), the chat stays open until it resolves — otherwise blocking could be used to sabotage a delivery window and collect the refund. Use report + dispute for problems inside a live job.

## Away mode

Going offline for a while? Flip **away mode** in [profile settings](/settings/profile). Your profile and any applications you've sent show an "Away" badge, and anyone sending you a direct request gets a heads-up that replies may be slow. Nothing is locked — you can still do everything; it just sets expectations honestly.

## Notifications

**Settings → Notifications** controls how loudly we get your attention: in-app is always on (it's the product working), email and push are yours to tune per event type — including direct-request alerts and saved-search digests. The legally-or-financially-important ones (you got picked, money released, dispute opened) stay on — those aren't marketing, they're your money moving.

## Display currency

Set your display currency in settings and every price on the site converts for display at current rates. Charges still happen in each request's native currency — display conversion never changes what anyone pays or receives.

## Privacy: what's public, what isn't

| Public (under your handle) | Never public |
|---|---|
| Your handle, avatar, bio | Legal name, email, phone |
| Open requests you posted | Payment details, card, bank, wallet |
| Ratings & profile stats | Your chats (only the other party + moderators) |
| Deliveries **only if both sides opted in** | Your location beyond what you put in a request |

Uploads are also stripped of metadata (EXIF location and friends) before anything is shown to anyone.

## Banned accounts

Accounts banned by the strike system can't post, apply, chat, or receive payouts. Money already in escrow on a banned account's jobs goes through dispute resolution — a ban is not a way for anyone to keep someone else's money. Details in [Disputes & safety](/docs/disputes-and-safety).

## Your data: export and delete

Both live in **[Settings → Security](/settings/security)**, at the bottom.

**Export my data** builds a machine-readable file of everything tied to your account — profile, requests, applications, messages, ratings, transactions — and hands it to you. Free, any time, no questions.

**Deleting your account** is the danger zone below it. We email you a 6-digit code; enter it and the deletion is confirmed — a stolen session can't nuke your account without your inbox. What happens next:

- Your profile, requests, applications, messages, and ratings are wiped within **30 days**.
- Financial records are kept only as long as the law requires — payment regulations don't bend for vibes.
- Public pages tied to your consent (Hall of Fame entries) come down with the account.

Deletion is permanent. There's no soft-delete limbo to crawl back from, so run the export first.
