← Help centre

Signing up, passwords, passkeys and account security

Signed in? Ask Lovelio this question inside the app - it answers from this same page.

Signing up

Choose Continue with Google for Google Workspace, or Continue with Microsoft for a Microsoft 365 work account. The provider confirms your work email. Confirm your name and agency name, then create your workspace. No Lovelio password is required. Signing up does not connect your mailbox or calendar.

Personal and free email accounts cannot create a workspace. A Google account must belong to a managed Workspace organisation. Microsoft consumer accounts, including personal accounts invited into a work tenant, are refused. A company-looking address alone is not enough.

If you have an active invitation, confirm your name to join that agency with the role your admin assigned. An existing member opens their workspace. An agency with single sign-on must use its organisation's sign-in route.

Continue with work email keeps the email and password option:

  1. Your details. First name, last name, agency name and work email. No password on this screen. Free email addresses (gmail, hotmail, outlook and the rest) are refused: Lovelio needs a work address because your account is keyed to your agency's domain.
  2. Check your email. Lovelio sends one email with a confirmation link and a six-digit code. Either one works. The link is one click; the code is there because some corporate mail systems rewrite or strip links, and you can always retype six digits. The link and code both last 24 hours and each works once. "Send it again" issues a fresh link and code, which cancels the previous ones, and there is a one-minute wait between sends.
  3. Choose your password. Once the email is confirmed you set a password and your workspace opens.

Neither option creates a workspace until you confirm the final screen. A provider confirmation is kept briefly so you can complete signup. If workspace creation is interrupted, return with the same account to finish without creating another workspace.

This is why the email step is not optional: your agency's email domain is reserved by the first account on it. Without confirming the address, anybody could take a workspace on a domain they do not own and lock out the people who do.

If your domain already has a Lovelio account, signup tells you so at step 1 and asks you to contact your team admin to be added, rather than making you wait for an email first.

Password rules

One rule: at least 12 characters. There is no requirement for a capital letter, a number or a symbol.

Two other checks run when you submit:

  • Is it easy to guess? Lovelio scores the pattern, not just the length. "Recruitment2026" is refused even though it is 15 characters, because a word followed by a year is one of the first shapes an attacker tries. Three unrelated words together score well and are easy to remember.
  • Has it leaked before? The password is checked against a public list of passwords that have appeared in known data breaches. This catches passwords the guessing check cannot: "correcthorsebatterystaple" looks strong by any pattern measure and appears in the breach list over four thousand times, so it is refused. Your password is never sent anywhere to do this. Only the first five characters of a one-way hash leave Lovelio, which is not enough to identify the password.

A password cannot contain your name, your email address or your agency name.

There are no character rules on purpose. Forcing a capital and a symbol does not make passwords harder to guess, it makes everybody pick the same predictable shape. Length plus a breach check blocks far more real passwords. Lovelio also never makes you change your password on a schedule, for the same reason: forced rotation produces "Summer1", "Summer2", "Summer3".

You can show what you have typed while setting a password, and pasting is allowed, so a password manager works normally.

Ways to sign in

The sign-in page asks for your email first, then shows only the ways in that can work for that address. Nobody has to know which region their account lives in: if your agency's data is held in another region, the page sends you there with your email already filled in.

  • Passkey. Click into the email box and your browser offers your passkey there, the same way it offers a saved password. There is also a "Sign in with a passkey" line under the card. No email needed: the passkey identifies your account by itself.
  • Google. "Continue with Google" opens your existing account when you use a Google Workspace or Gmail address. The sign-in page does not create a new account; use the signup page to register.
  • Microsoft. "Continue with Microsoft" does the same for a Microsoft 365 or Entra work account. Your IT admin's domain must be verified in Microsoft, so a personal Outlook, Hotmail or Live address is not offered this door and signs in with a password.
  • Password. Always there underneath, with "Forgot password?". A Gmail address sees Google and the password; a company address sees Google, Microsoft and the password.
  • Single sign-on. If your agency's domain is on SSO, the page shows "Continue with SSO" and nothing else: your identity provider is the only door.

Google and Microsoft sign-in only open accounts that already exist, in whichever region holds them. If Lovelio cannot find one anywhere for that address, ask your admin to invite it, or sign in with your password.

Passkeys

A passkey signs you in with your fingerprint, face or device PIN instead of a password. It is the primary way to sign in, not an extra step on top of one.

  • Adding one. Settings, You, Security, "Add a passkey". Your device asks you to confirm and that is the whole setup. You can also add one from the prompt that appears at the top of the dashboard the first time.
  • Using one. On the sign-in page, click into the email box and pick your passkey from the list your browser shows, or click "Sign in with a passkey" under the card. You do not type your email first: the passkey identifies your account by itself.
  • What is stored. Only a public key. The private half never leaves your phone, laptop or hardware key, so there is nothing on Lovelio's side that could be stolen and used to sign in as you.
  • More than one. Add a passkey on each device you use. Passkeys saved to iCloud Keychain, Google Password Manager or 1Password sync to your other devices automatically; the Security page marks a passkey "only on this device" when it does not sync, so you know to add a second one.
  • Removing one. Settings, You, Security, then the bin icon on the passkey. Do this if you lose a device.

Your existing sign-in methods keep working after you add a passkey. If your account has no Lovelio password, use Google or Microsoft on a device without your passkey.

Too many failed sign-ins

After 10 failed attempts on one account within 15 minutes, that account stops accepting sign-ins for the rest of the window. The same applies after 30 failed attempts from one internet connection, across any number of accounts.

Nothing is locked permanently and nobody has to contact support: the window expires on its own. A permanent lockout would let anybody who knows your email address lock you out of your own account.

Sign-in never tells you whether an email address has an account. A wrong password and an unknown address produce the same message.

Changing your password

Settings, You, Security, "Change password". If you already have a password, enter the current password first. If you signed up without one, "Add a password" sends a link to your work email. Open that link to verify your address before choosing the optional password.

That is deliberate. Without it, anybody who reached an unlocked laptop or a session left open on a shared computer could set a new password and lock the real owner out for good. With it, a borrowed session is a nuisance rather than a takeover.

Lovelio emails you whenever your password changes, whether it was changed in settings or through a reset link. That email deliberately contains no links: a security warning that asks you to click something looks exactly like a phishing attempt. If a password change was not you, email support@lovelio.ai.

Forgotten password

"Forgot password?" on the sign-in page emails a reset link. It works from any Lovelio sign-in page - you never need to know or care which Lovelio domain your account lives on. The page never says whether an address has an account, so it cannot be used to find out who uses Lovelio.

The link lasts one hour and is used up when you submit the new password, not when the link is opened. That matters because corporate email scanners open links before you do; a scanner cannot burn your reset link.

Signing out of every device

Settings, You, Security, "Sign out everywhere". This ends every session you have on every device, including the one you are using. Use it if you lose a laptop or forget to sign out on a shared computer.

It signs you out here too, on purpose. Somebody using this because they think they have been compromised should not be left holding the one session they cannot be sure about.

Single sign-on

If your agency uses SSO, it is set up under Settings, Integrations, "Single Sign on". SSO is in addition to passwords and passkeys, never instead of them.