Account, privacy, and operation
Sign in, recover access, and secure your account
Understand passwords, recovery codes, multifactor authentication, and device sessions.
Account security protects access to the plan, not just the password
Your YARCalc account can contain a detailed picture of household finances, so sign-in security deserves the same care as other sensitive online accounts. The Security area covers password changes, multifactor authentication, recovery, and active sessions. These controls protect access to YARCalc; they do not change a retirement scenario or any account held at a financial institution.
Most people should use a unique password and enable an authenticator when it is available. You do not need to change settings repeatedly, but you should review them after a lost device, email change, suspicious sign-in, or concern that another person knows the password.
Set up recovery before you need it
Create an account with an email address you control and complete the verification link before continuing to Plan Setup. Replace a temporary password when prompted. A standard signed-in session expires after twelve hours; Remember this device can keep it active for thirty days, so do not use that option on a shared or public device.
Multifactor authentication adds a time-changing code from a compatible authenticator app. It reduces the harm of a stolen password, but it also makes recovery preparation important. Save recovery information securely and separately from the device that generates codes.
Repeated failed sign-ins are temporarily limited. If the account remains locked after the protection period, contact YARCalc support without sending a password, authenticator code, or recovery secret.
Change one access method at a time and verify it
Use the password-reset email or an available recovery method when you cannot sign in. Recovery and verification links are single use and expire. If a link is old or has already been used, request a new one rather than forwarding it or trying to modify the address.
To enable multifactor authentication, scan or enter the setup information in the authenticator app and confirm a current code before leaving the page. To change a password, enter the required current or recovery information and choose a new unique password. A password change ends other signed-in sessions.
Use Sign out all devices when a phone, computer, or remembered session may no longer be safe. Closing a browser does not necessarily revoke a remembered session.
Confirm the new sign-in path before discarding the old one
After a password or authenticator change, sign in using the new method and verify that the Security page shows the intended status. Keep recovery information until that test succeeds. Review active-session controls after removing a device or changing credentials.
A successful security change should not alter Home, What-ifs, analyses, or balances. If planning data appears different, first confirm that you signed into the same account and selected the intended scenario.
If you believe someone else accessed the account, change the password, revoke other sessions, review the sign-in email and multifactor status, and contact support with a nonsensitive description of the concern.
Never send access secrets as part of a support request
YARCalc support does not need your password, authenticator secret, current code, recovery code, brokerage login, or complete financial documents. Anyone asking you to send those items should be treated with caution.
These controls secure YARCalc access only. They do not secure your email account, authenticator device, password manager, brokerage accounts, or copies of information stored elsewhere.