Only accounts enrolled in the admins table can do anything here — and every action additionally requires MFA (AAL2).
No authenticator is enrolled yet. Scan this with an authenticator app (Google Authenticator, 1Password, etc.), then enter the 6-digit code.
Can't scan? Enter this secret manually:
Enter the current 6-digit code from your authenticator app to step up to AAL2.
Loading current operational data…
Parent acquisition, account setup and first-practice conversion.
Completed attempts mirrored from local-first family devices.
Entitlements are not revenue. Use Stripe for financial reporting.
Consent, jurisdiction completeness and the 24-month retention rule.
Server-side item inventory and trusted-path activity.
Question reports and recent administrator activity.
New parent accounts
Completed practice attempts
Admin accounts are excluded. Search by all or part of a signup email, or click a row to open that family below.
Deletes practice history + child profile and anonymises the parent profile. The consents ledger is preserved (legal proof); the auth account is kept. Irreversible.
Internal tool. Serve behind Cloudflare Access; data access is additionally gated server-side (admin membership + MFA). No secrets are stored in this page.