Skip to content
MirrorFill ← Back to home

Home / Help / Billing & your account / Account security

Billing & your account · updated 2026

On this page

  • Passwords
  • Password reset
  • E-mail verification
  • Sessions and devices
  • Broker credentials

Account security

What protects your MirrorFill account, exactly what each security action does, and the one rule that matters most: we never ask for your broker password by e-mail.

Passwords

Passwords are at least 10 characters. Change yours under Settings → Security → Change password.

Changing your password signs out every other device — your current session survives, so a security action does not bounce you to the login screen. You also get a password-changed e-mail, so a change you did not make never goes unnoticed. Accounts that sign in with Google have no password to change here; the Security tab says so.

Password reset

Forgot the password? The reset link that lands in your inbox:

  • Expires in one hour.
  • Is cancelled by any newer link. Requesting a second reset kills the first — always use the most recent e-mail.
  • Requests are rate-limited to 3 per hour per e-mail address.

Completing a reset signs out all devices, including yours. That is deliberate: a reset is the recovery path after a suspected compromise, so nobody — including an attacker holding a stolen session — gets to keep one.

E-mail verification

Verification links expire in 3 days. You can resend from Settings → Account, limited to 3 resends per hour. If your link is dead, just resend — a new link replaces the old one.

Sessions and devices

Settings → Security → Signed-in devices lists every active session with its device and last-active time. Sign out everywhere revokes all of them at once, including the one you are on. Sessions also expire on their own after 14 days of inactivity.

If a device you do not recognise appears in the list, use Sign out everywhere, then change your password.

Broker credentials

Your Rithmic, Tradovate, and Volumetrica credentials are encrypted at rest and write-only: the app never displays a stored password, and the API never returns one. When you edit a connection, leaving the password field blank keeps the stored one — you are never shown it to re-copy.

MirrorFill will never ask for your broker password by e-mail. Any message that does is phishing — delete it and report it via contact. Broker credentials go in exactly one place: the Accounts page, inside the app.

Quick answers

I changed my password. Why is my phone logged out?

Changing a password signs out every other device on purpose. Sign back in on the phone with the new password.

My reset link says it's invalid. Why?

Reset links expire after one hour, and requesting a new one cancels the old. Use the newest e-mail, or request a fresh link.

Can support read my broker password?

No. Stored credentials are encrypted and write-only — nothing in the app or API can display them.

Next steps

Login problems and rate limits · Notifications and alerts · Managing multiple connections

← Back to the help center

MirrorFill
Help center FAQ Contact Terms Privacy Refunds Risk Disclosure

© 2026 MirrorFill. Operated from the European Union. Trading futures involves substantial risk of loss and is not suitable for every investor. MirrorFill is a trade-copying tool, not a broker, financial adviser, or signal provider.