Making one
Create an account asks for your email and sends you a link. Open it, press "Continue", and you're in. The account is made the first time you use that link, so asking for one and not opening it leaves nothing behind. You can also start with Google or Discord instead of typing your address.
There's no password to choose at the start. Once you're in, you can add one, or a passkey, so you don't have to wait for an email every time.
Ways to sign in
All of these are under "Ways to sign in" in the account menu, and you can use any mix of them.
- A link by email. Always there, for every account. Type your address on Sign in and press "Email me a sign-in link". It works once, for 15 minutes. It's also how you get back in if you forget your password.
- A password. At least 12 characters, with no rules about numbers or symbols. A few ordinary words with spaces between them is easy to remember and hard to guess. We turn down the most common passwords, your email address, passwords with our name in them, and simple patterns like abcabcabcabc. Changing or removing it needs the current one, or "Email me a link to remove it" if you've forgotten it.
- A passkey. Your phone or computer signs you in with your face, fingerprint or screen lock, and there's nothing to type. "Add a passkey" saves one in your device's password manager, so if your phone and computer share one, like iCloud Keychain or Google Password Manager, one passkey works on both. "Use a passkey" on the sign-in page needs JavaScript switched on.
- Google or Discord. Connect it once, and its button signs you in from then on. If it tells us your email address is confirmed, it signs you in to the account with that address, and makes one if there isn't one yet. Google tells us that only for a Gmail address, or an address at your organization's own domain if it uses Google Workspace. If it doesn't, we email you a link to open in the same browser first. An account can have one of each kind connected; to switch to a different one, disconnect the first. Signing in with a second one that shows your address still signs you in, but doesn't connect it. And one that's connected to a Whenabouts account can't be added to another.
We email you whenever a way in is added, changed or removed, and whenever an API key, a webhook or a helper is added, so you'll know if somebody else did it.
Two-step verification
Two-step asks for a six-digit code from an app on your phone, like Google Authenticator, Microsoft Authenticator or 1Password, as well as your password or emailed link. Somebody who gets into your email still can't get into your account.
To set it up, press "Set it up" under "Ways to sign in". We email you a link first, to check it's you, and setup carries on wherever you open it. If you aren't signed in there, we ask you to sign in first. Scan the code with your app, type the six digits it shows, and you'll get 10 backup codes. Keep those somewhere away from your phone. Each works once, in place of a code from the app.
The code is asked for after an emailed link or a password, when you accept an invitation to help on somebody's account, and when you connect a new outside account. It's also asked for when you add a passkey, get new backup codes or turn two-step off. It isn't asked for when you sign in with a passkey, or with Google or Discord once it's connected, because those already need something only you have.
Lost your phone? Type a backup code instead. Lost your phone and your backup codes? Write to us from your account's address and we'll help you back in.
Staying signed in, and signing out
You stay signed in on a device for 90 days from the last time you used Whenabouts on it, and for 365 days at most from when you signed in on it, however often you use it. After that, sign in again. "Sign out" in the account menu signs out that device.
"Sign out everywhere", on the account page and on "Ways to sign in", signs out every device at once, this one included. Use it if you've left yourself signed in somewhere you can't get back to. Changing or removing your password, turning two-step on or off, and removing a passkey or an outside account all sign out your other devices too.
Your pages
Your pages lists everything you've made while signed in, and the pages of anybody you help, the most recently busy first. Each one opens its console, so you don't need the private links. It shows 100 at a time, and "Show older pages" at the bottom shows the next 100. Archive the ones you're done with to keep the list short. Buttons at the top lead to your lists of people, repeating things, shift schedules, and "Start something new".
Things you were sent and kept go to "Sent to you" instead (see Keeping track of what you're sent).
Saving a page you made without an account
Open the page's private link and press "Save this to your account". Signed in, press "Save it to my account" on the next page. Signed out, type your email and we'll send a link that signs you in and saves the page in one go. You need the private link to do this, signed in or not; it's what shows the page is yours.
The page then shows on your pages, and it's on your plan from then on: your plan's limits, and its paid features if you have them. The private link keeps working as before. A page that's already on somebody else's account can't be saved to yours.
People who can help
On a paid plan, you can add people to help run your pages: 1 on Pro, 4 on Group and 24 on Site. On the account page, "People who can help" takes their email address and writes to ask them. The link in that email works for 7 days; if it runs out first, "Ask again" sends a fresh one. An invitation waiting for a yes takes up a place. Each time one goes out, we email you too, so you'd know if somebody else sent it.
Once they say yes, your pages are on their dashboard alongside their own. They can see the answers, change the details, message people, close and open pages again. A page's link ending, PIN and look, which sites can show it, archiving, deleting and billing stay with you, and they can't add anybody else. Your lists of people, repeating things and shift schedules aren't shared.
"Take them off" stops their access right away, and anything they did stays. If your plan ends, or moves to one with fewer places, the people you asked first keep their places and the rest lose access until there's room. Nobody's work is deleted.
Your name and your address
"Your name" on the account page is used on the pages we make for you, like a repeating thing's or a shift schedule's, on your lists, and in the invitations you send helpers. A page you make yourself uses the name you type on it.
An account's email address can't be changed. To use a different one, sign out and sign in with it, and it becomes its own account.
Deleting your account
"Delete my account" is under "Your data" on the account page. It opens a list of exactly what goes: your pages and everybody's answers on them, your lists, repeating things and shift schedules, API keys and webhooks, your helpers, your places on other people's accounts, your usual week and calendars, what you've kept, and every way of signing in.
What stays: answers you gave on other people's pages, no longer linked to you, and any page you made without an account and never saved to it.
A paid plan has to be cancelled or closed first; the delete page says how for yours, or write to us. Then check the box and press "Delete my account", and we email you a link. Nothing is deleted until you open it, signed in, within 15 minutes. Your pages stop working at once and are erased for good 7 days later. The details are in How long things are kept.
Didn't find what you were after? The rest of the help pages might have it, or write to us and somebody will answer.