Verifying high-risk actions
Why some changes ask you to re-verify, what counts as high-risk, and how the quick check keeps your account safe.
Reviewed regularly to match the current app.
Overview
Some actions on GS Poetry are sensitive enough that we ask you to re-prove it’s really you before they run — even if you’re already signed in. We call these high-risk actions. They’re the kind of change that, if someone else slipped onto your account, could lock you out, take over your identity, or wipe something you can’t get back.
The check itself is quick — one six-digit code or one password — and the action runs the moment you pass it.
What counts as a high-risk action
Anything in the four groups below will ask for a fresh verification before it goes through:
Account & identity
- Change your password
- Change your email address
- Change your username
- Change your birthday (only when the date itself is actually changing — saving the rest of your profile doesn’t trigger it)
- Pause your account
- Close your account
Two-factor authentication
- Turn off two-factor authentication
- Add or remove a phone number, or turn SMS two-factor on or off
- Add or remove a passkey
- Regenerate your backup codes
Sessions
- Sign out a specific device
- Sign out every other session at once
Data management
- Start a data export
- Delete a poem
Deleting a poem is permanent. The poem comes down right away, and the comments, likes, shares, and read counts attached to it are not kept — even if you re-post the same text later.
How the verification works
Whichever high-risk action you start, the flow is the same:
- Click/tap the button for the action you want (e.g. Change Password, Disable 2FA, Delete Poem).
- A small verification window appears.
- Enter your six-digit 2FA code — or, if you don’t have 2FA turned on, your current password.
- Click/tap Verify. The original action runs immediately and you’ll see the result.
One verification covers one action
Verifying once does not give you a free pass on the next high-risk action. The check is consumed the moment your action finishes, so the next sensitive change — even if you do it seconds later — will ask you to verify again.
If your account is ever signed in on a device you don’t control — a borrowed laptop, a phone you forgot in a coffee shop — this is what stops someone from cascading through your settings and rewriting your password, email, and 2FA in a single sitting. They’d have to clear a fresh check for every one of those steps.
If you don’t have 2FA turned on
You can still do every high-risk action. The verification window will simply ask for your current password instead of a six-digit code — the same rule applies: one password per action, no carry-over.
That said, if you make sensitive changes often, turning on 2FA is faster and noticeably more secure. See Setting up two-factor authentication for the walkthrough.
If you can’t get a code
If your authenticator app is unavailable or your email isn’t arriving, you can enter a backup code at the verification step instead. Each backup code works exactly once, so cross it off your list after you use it. You can generate a fresh set any time from Settings → Account → Security (that’s itself a high-risk action, so it’ll ask you to verify first).
If your authenticator app and your backup codes are both gone, don’t keep retrying — follow the dedicated recovery guide so the right path opens for you.
Where to go next
If you haven’t enabled 2FA yet, start with Setting up two-factor authentication. If you can’t get a code from your app and your backup codes aren’t handy, see Lost access to your two-factor authentication for the three ways back into your account.
