GUIDE
Account and sign-in
Four ways to sign in, how trial data comes with you, verification, and session controls.
Using it without signing in
You can start without an account. The native app does not split the experience into trial and production screens: Today, Library, Plan, Progress, and Account remain in the same bottom tab bar before and after sign-in. Anything added before sign-in is stored on this device.
When you want to sign in, open Account at the bottom and continue with a passkey, Apple, Google, or X. The same screens then gain cross-device sync and account features.
In the native app, Account lets you switch the display language under Language to System, 日本語, or English, even before you sign in.
While you are on a trial, another device cannot see any of it. Clearing browser data removes a browser trial; clearing the app's local data removes a native trial.
Four ways to sign in
Register and sign in with a passkey, Google, Apple, or X. More than one method can sit on the same account. In Sign-in methods, provider connections are shown after passkeys in the order Apple, Google, X.
A passkey uses Face ID, Touch ID, your device PIN or a security key. There is no password to remember, and the key that is created works only on that device. An email address is not required; when supplied, a verification email follows registration.
Google carries on with the Google account you already have.
Apple uses Sign in with Apple. If you choose Hide My Email, CurveMora accepts Apple's private relay address.
X carries on with the X account you already have. CurveMora asks only for permission to read the profile information used to sign you in.
Connecting Google, Apple, or X to an existing account later does not replace the display name, email address, or profile image you set in CurveMora. Add or remove them under Sign-in methods in settings.
Managing passkeys
Sign-in methods in settings adds, renames and removes passkeys. Registering one per device means any of them gets you in.
Each passkey shows when it was added and when it was last used. Remove anything you do not recognise.
The final sign-in method cannot be removed. If Google, Apple, or X remains connected, the final passkey can be removed. Conversely, if there is no passkey and only one OAuth connection remains, that connection cannot be removed.
When you are asked to verify
Anything that changes how you sign in asks you to verify there and then with a registered sign-in method. Being signed in already does not skip it. When several methods are registered, Choose how to verify opens and offers the registered methods in the order passkey, Apple, Google, X.
When OAuth verifies a connect or remove action, CurveMora returns to that action automatically. For actions that carry form input, such as changing an email address, verification returns to Settings with fresh proof; choosing the action again continues without another verification prompt.
- Adding or removing a passkey
- Connecting or removing a Google account
- Connecting or removing an Apple account
- Connecting or removing an X account
- Adding, changing, removing, or verifying an email address
- Deleting the account
It exists so that a screen left signed in cannot be used to rewrite how you get in. If the verification does not complete, nothing changes.
Sessions, signing out, and a lost device
Active devices in Settings lists every currently valid CurveMora session. The browser you are using is marked This device, and every other row can be signed out individually. Device labels are derived coarsely from the browser and operating system; location and the raw user-agent string are not stored in the session registry.
Sessions in Settings separates Sign out on the current device from Sign out on all devices. The latter ends every session for the account, including the one you are using.
Recent sign-ins in the same card shows up to six recent successful sign-ins with their method and time. The IP-address and user-agent digests kept for incident review are not exposed in the interface.
If a device is lost, first sign out that specific row under Active devices. If you cannot identify it confidently, sign out on all devices and then remove the passkey registered on the lost device.
Deleting the account
At the bottom of settings, type delete and verify with two different methods from passkey, Apple, Google, and X to schedule deletion in 30 days. Scheduling signs out every current device and stops any paid plan.
Before the 30-day deadline, a normal sign-in with a passkey, Apple, Google, or X credential that already existed when deletion was requested restores the same account. A sign-in method added after the deletion request cannot restore it.
A Recovery Email that was already verified when deletion was requested can also restore account access. After following its recovery link into a restricted Recovery session, explicitly choose Restore this account to cancel deletion. This route does not immediately grant full Security Ownership; the Recovery restrictions and Security Hold remain in effect.
Restoration is unavailable once the 30-day deadline passes. After the retention period, CurveMora permanently removes the account, sources, learning items, repetition history, breaks, and AI capture records.
About exporting your data