Your backup password
The one thing in this app you have to remember. Everything else can be recovered. This cannot — unless Face ID or fingerprint still unlocks the app on one of your devices, or you set up a recovery phrase ahead of time; in either case you can simply set a new one.
What it protects
Your backup password is the secret that unlocks your patient names and MRNs. The app uses it to scramble those values on your phone before they’re sent to the servers. The same lock covers your earnings figures, so if you use the finance features your money numbers are scrambled on your phone too, exactly like the names and MRNs.
Lose the password, and the scrambled values on the servers stay scrambled forever. No one can recover them for you.
What it does NOT protect
- The clinical content of your cases. Procedure, date, hospital, side, notes — these are saved on the servers in readable form. Losing your password does not lose those.
- Your account. Your email and account stay. You can sign in. You just can’t read the patient names attached to your cases.
The password is specifically the lock on the identifying part of your data.
How to pick one
- Make it memorable to you and unguessable to anyone else. Something distinctive that you’ll still remember in a year.
- Write it down somewhere safe. A piece of paper in a locked drawer, a password manager like 1Password or Bitwarden, your iPhone’s Keychain. We cannot recover this for you — that’s the point.
- Don’t reuse a password from email or banking. Different purpose, different threat.
Daily use: biometric unlock
After setting your backup password during onboarding, you’ll be asked to enrol Face ID or fingerprint unlock. Do it. Daily unlocking becomes instant — look at your phone, the vault unlocks. It’s also your safety net: on a device where biometric still works, you can set a new backup password if you ever forget yours (see below).
You’ll still need the backup password:
- When you sign in on a new device for the first time
- When biometric fails (the camera can’t see you, your finger is wet, you changed phones)
Biometric does not replace the password. It just stops you typing it constantly. If you ever cancel the Face/Touch ID prompt, the app simply shows you the backup-password field instead — no error, no fuss. And turning biometric back off in Settings → Security removes the key cleanly.
On a phone or browser that can’t offer quick unlock at all, the app just tells you plainly and keeps you on the backup password — nothing breaks and you’re never locked out. Your backup password is always enough to get in on its own.
If the vault has locked itself after a spell of inactivity, opening any screen — Insights included — brings up the unlock prompt, not an error. You’ll never be told “couldn’t reach the server” when the real reason is simply that the vault is locked; just unlock and the screen loads.
On a shared computer, the lock screen also says whose account is signed in (“Signed in as Dr …”) and offers Sign in as a different user — so if a colleague left their account signed in, you’ll see it’s not yours instead of wondering why your password isn’t working.
Set up a recovery phrase
A recovery phrase is your safety net for the day you forget your backup password on a device where Face ID or fingerprint also isn’t available — a borrowed laptop, a new phone you haven’t set up biometrics on yet. It’s 12 plain words, generated once, that can unlock your vault and let you set a fresh backup password.
Set one up under Settings → Security → Set up a recovery phrase. You’ll see the 12 words once. Save them somewhere safe — the easiest reliable way is to send them to yourself on WhatsApp, exactly like you’d keep a chat backup; a password manager or a photo in a private album works just as well. Then tap I’ve saved my recovery phrase to finish.
A few things worth knowing:
- It’s independent of your backup password. Changing your password never breaks your recovery phrase, and vice versa. You can hold both.
- You can set one up at any time — you don’t have to be a new user. If you’ve been using the app for a while, just open Settings and add one.
- You can regenerate it whenever you like. The moment you do, the old 12 words stop working — so update wherever you saved them.
- We never see it. The phrase is shown on your screen and nowhere else; it’s never sent to our servers and never stored on our side. That’s the same reason we can’t recover your backup password — and the same reason only you can use this phrase.
If you’d rather not, you don’t have to — the app will occasionally offer, and you can dismiss it. But it’s the one thing that turns “no password, no biometric” from a data-losing reset into a two-minute recovery, so it’s worth the two minutes now.
If you forget it
Try these in order. Only the last one loses anything.
If Face ID / fingerprint still works on one of your devices: nothing is lost. Open that device → Settings → Security → Change backup password → tap Forgot your backup password?. Type a new password, confirm with Face ID / fingerprint, and you’re done — no old password needed. All your patient names, MRNs, and earnings figures stay exactly as they are; your other devices just use the new password the next time they ask for one. If the vault is locked, the lock screen’s Can’t unlock? link offers the same thing: unlock with Face ID / fingerprint and set a new backup password.
If you have a device where the vault is unlocked and you remember the old password: open that device → Settings → Security → change your backup password the normal way. The app re-scrambles your existing key under the new password. Your patient names stay readable — no data is lost.
If you saved a recovery phrase: on the locked screen, tap Can’t unlock? → Use a recovery phrase, type your 12 words, and set a new backup password. Everything — patient names, MRNs, earnings figures — comes back exactly as it was. This is the rung that saves you when Face ID / fingerprint isn’t available on the device in your hand, which is exactly why it’s worth setting one up before you ever need it (see above).
Only if you have none of the above — no unlocked device, no biometric, no recovery phrase: you must reset your vault. This is the last resort.
Open the app → sign in → tap the reset option → type RESET to confirm. This:
- Wipes the secret key on the servers
- Wipes the working copy on your phone
- Sends you back through onboarding with a fresh key
- Leaves your previously-saved patient names as unreadable bytes on your case rows. The clinical content of those cases is untouched.
After a reset, affected cases show a Lost in reset label. Tap each one — either re-enter the name (it gets re-scrambled under your new key) or delete the case. If your phone still had a readable copy of the name in its working memory, the app fixes most of these on its own and you’ll only see the label on cases where both copies were lost.
The reset is destructive but doesn’t lose the case itself — only the patient identifier on it.
Why we can’t reset it for you
There’s no email us and we’ll reset it option, and there never will be. If we could reset your password from our side, someone who broke into our systems could too. The design choice is the same one Signal, ProtonMail, and WhatsApp’s encrypted backups make: stronger security in exchange for a password we can never touch.
That’s also why the Forgot your backup password? path above lives on your device, behind your Face ID or fingerprint — not on our servers. Your device already holds the key; your face or fingerprint proves it’s you; the servers are never asked and never able to help.
The surgeon, and only the surgeon, holds the key.