Account security

How to protect your McGesund account

Your McGesund account holds sensitive data — reviews, signals, care settings, billing information. So only you and the people you've invited can access it, we offer several secure sign-in methods and an optional second factor.

This page walks you through the options — you decide what fits your everyday life.

Sign-in options

You can sign in to McGesund in two ways:

With email address and password

The classic route: you choose a password and sign in with it. Your password is never stored in plain text — only as a mathematically irreversible fingerprint, which not even we can read back.

With an existing account (Single Sign-On)

You can also sign in via your existing Google, Microsoft or Apple account — no additional password required.

Preview — the real buttons live on the sign-in page.

Both routes can be combined: you can start with Google and add a password later — or the other way around. Your account stays the same.

Two-factor protection (2FA)

We recommend a second protective factor for every account. Even if someone knows your password or takes over your Google account, they can't get into your McGesund account without this second factor.

Authenticator app (recommended for most people)

A free app on your smartphone (for example Google Authenticator, Microsoft Authenticator, Authy or 1Password) generates a new six-digit code every 30 seconds. When signing in, you enter that code once.

Setup takes under two minutes: scan a QR code with the app, confirm once — done.

Passkey / hardware security key

The most modern protection: a passkey is a device-bound cryptographic key. When signing in, you confirm once via fingerprint, face recognition or a hardware security key — no code to type, no app needed.

Passkeys never leave your device. Following the current FIDO2/WebAuthn standard, they are immune to phishing: even a perfect phishing page cannot capture a passkey.

Emergency codes (backup)

When setting up 2FA you receive ten single-use emergency codes. Keep them safe (password manager, printed in a safe) — if you lose your smartphone or hardware key, you can use them to get back into your account at any time.

What the sign-in providers know about you

When you sign in with Google, Microsoft or Apple, there's a fair question: what does McGesund share with those providers? Answer:

What the provider sees

  • Your name (as stored with them)
  • Your email address
  • A unique account identifier
  • With Apple: optionally a random relay address instead of your real email (Apple's “Hide My Email” feature)
  • That you are currently signing in to McGesund

What the provider does not see

  • Your reviews and signals
  • Your care or company settings
  • What you look at or change inside McGesund
  • Your activity after sign-in — we don't report anything back

The sign-in provider only confirms to us: “Yes, this really is that person.” No further information flows — neither from us to the provider, nor regularly back the other way.

Our recommendation: Whether you sign in with a password or via a sign-in provider — also enable two-factor authentication. It is the single most effective step you can take to protect your account.