Keep your account secure
Protect your WelcomeFlo account, recognise what we will never ask for and know what to do if something looks wrong.
Updated
Your account controls every guide you publish, so it is worth a few minutes of care.
The basics
- Use a password you use nowhere else, ideally generated by a password manager
- Protect the email account you sign in with, since anyone controlling it can reset your password
- Sign out on shared or public computers
- Keep your recovery email current
What we will never do
WelcomeFlo will never ask for your password, by email, message or phone. Nobody at WelcomeFlo can read it — it is hashed by our authentication provider.
We will never ask you to send card details by email either. Payments go through Stripe, and card numbers never reach WelcomeFlo.
If a message asks for any of that, it is not from us.
Checking a suspicious email
Look at where links actually go before clicking. Genuine WelcomeFlo emails come from our own domain, and no legitimate message will ask you to sign in through a link in order to avoid your account being closed.
When in doubt, ignore the message and sign in through welcomeflo.com directly.
If you think your account is compromised
- Change your WelcomeFlo password immediately
- Change your email account password too, if that may also be affected
- Check your guides for changes you did not make
- Check your billing settings for unfamiliar activity
- Contact us with what you have noticed
Reporting a security problem
If you have found a vulnerability, please contact us before disclosing it publicly, with enough detail to reproduce it. We will not pursue anyone reporting a genuine issue in good faith.
