Account & billing
Security & privacy
Your career identity is worth protecting. Here's how to lock down your account and what we do on our side.
Two-factor authentication (TOTP)
- 1
Open Settings → Security
Choose "Set up two-factor authentication".
- 2
Scan the QR code
Use any authenticator app (Google Authenticator, Authy, 1Password). The app starts generating 6-digit codes.
- 3
Confirm with a code
Enter the current 6-digit code to enable. From then on, sign-ins require your password plus a code.
Passkeys
Passkeys let you sign in with your device's fingerprint, face unlock, or PIN — no password typed, nothing phishable. Add one under Settings → Security → Add Passkey; your browser handles the rest. You can register multiple devices.
Sessions and sign-out
- Sign-ins use short-lived access credentials that rotate automatically; a stolen token expires in minutes.
- Long-lived sessions are device-bound and revocable — signing out revokes the device.
- If we detect a session credential being reused suspiciously, the whole session family is revoked and you're asked to sign in again.
Connected apps and links you create
- AI assistants — connecting Claude or ChatGPT over MCP requires your explicit approval, is limited to a fixed set of read-oriented tools, and can be disconnected at any time.
- Share links — Vault links and published resumes are the only ways your files leave your account. Each can carry an expiry, a view cap, and a passcode, and revoking one cuts access immediately.
What we do with your data
- Passwords are stored only as strong one-way hashes.
- Resumes and uploads live in private storage — never on public URLs.
- Coach conversations are private to you; employers see only your public card, and only if it's enabled.
- The full policy: growthcharters.com/privacy.
Think your account is compromised?
Change your password immediately (Settings → Security), which revokes existing sessions, then email support@growthcharters.com so we can review recent activity with you.