Your GamerFlick account holds two things worth protecting: your competitive history and your wallet. As tournament payouts scale up, so does the incentive for someone to try to get into your account. This update is about making that meaningfully harder.
Two-factor authentication
You can now require a second factor on login. We support authenticator apps (TOTP — Google Authenticator, Authy, and anything compatible) and, as a fallback, an OTP to your registered email. Authenticator apps are the stronger option because they do not depend on your inbox being secure.
Turn it on under Settings → Security. Do it before you have a balance worth stealing, not after.
Login and withdrawal alerts
Every new-device login and every withdrawal request now triggers a notification — in-app and by email — with the device, rough location, and time. If it was not you, there is a "this wasn't me" action that ends every session and locks the account pending a reset.
- New device sign-in
- Password or 2FA change
- Withdrawal initiated
- UPI ID added or changed
The security dashboard
One screen shows every active session, the devices your account has been used on, recent security events, and whether 2FA is on. You can revoke any session from here. If you play at a friend's place or a gaming cafe, check this occasionally and clear anything you do not recognise.
What we do on our side
Withdrawals to a newly added UPI ID have a short holding window. Unusual patterns — a login from a new country, a withdrawal right after a password change — trigger a step-up check. Passwords are hashed, never stored in plain text, and never sent to us in analytics or logs.
Three things to do now
- Enable authenticator-app 2FA in Settings → Security
- Confirm the email on your account is one you control and is itself secured
- Open the security dashboard once and revoke any session you do not recognise