๐ Account & Security
How signing in works on GalaxyGrails.io, what protects your account and your funds, and which parts of your profile other collectors can see.
Signing inโ
GalaxyGrails.io uses email and password. There is no "sign in with Google," Apple, or other social login โ if someone offers you one, it isn't us.
When you register, your account starts out unverified. Check your email and click the verification link before you can use the Platform. If the message doesn't arrive, you can request a new one from the sign-in screen.
Forgot your password? Use the Forgot password link to receive a reset email.
Password requirementsโ
Passwords must be:
- Between 12 and 128 characters
- Contain at least one uppercase letter, one lowercase letter, one number, and one special character
- Free of spaces and tabs
We also reject passwords that appear on a list of commonly-used and easily-guessed choices โ including obvious variations on "galaxygrails". If your password is refused, pick something less predictable rather than adding a character to the end.
Usernamesโ
Your username is what other collectors see in chat, on the leaderboard, and in pull history.
- 3 to 30 characters
- Letters, numbers, and underscores only
- Must be unique โ usernames are compared without regard to capitalization, so
Collectorandcollectorare the same name - Screened against a profanity filter
You can change your username later from your account settings, subject to the same rules.
๐ Two-factor authenticationโ
GalaxyGrails.io uses emailed one-time codes for two-factor authentication. There is no SMS option and no authenticator-app setup โ codes always arrive at your account email address.
A code is required for:
- Signing in
- Withdrawing funds
- Requesting a PSA Vault transfer
How codes work:
- Each code is valid for 10 minutes.
- You get five attempts per code. After that you'll need a fresh one.
Trusted devices. After a successful login you can mark a device as trusted for 30 days, which skips the code on subsequent sign-ins from that device. Two important limits:
- Changing your password immediately invalidates every trusted device, so a stolen session can't outlive a password reset.
- Withdrawals and vault transfers always require a fresh code. A trusted device never bypasses a money-out or card-out action, by design.
If you receive a code you didn't request, someone may have your password. Change it immediately โ that also revokes every trusted device.
๐ค Private profilesโ
Your profile is public by default. Turning on private profile in your account settings limits what other people can see.
What a private profile hides:
- Your total collection value and card count
- Your points balance and monthly leaderboard rank
- Your public card list, which becomes unavailable to others
- Your entry on the monthly leaderboard โ you're removed from it entirely, including from your own "your rank" panel
What a private profile does not hide:
- Your username in live chat and in @mentions
- Your username in the recent pulls feed
- Your username in break queues and buyer lists on event pages
- Your username in card ownership history and in public fairness reports for events you participated in
In short: private profile hides your collection and standing, not your presence. If you take part in a live event, your username is part of that event's public record. Turn the setting on or off at any time โ the change takes effect within about a minute for other viewers.
๐ผ๏ธ Profile picturesโ
You can upload an avatar from your account settings.
- Formats: JPG, PNG, GIF, or WebP
- Maximum size: 5 MB
Every uploaded image is automatically screened before it goes live, using a third-party content-moderation service. While a new picture is being reviewed it is held privately โ nobody else can see it โ and your existing avatar stays visible. Nothing changes on your profile until the new image is approved.
The screening looks at what an image contains. It does not identify people, doesn't compare your photo against any database, and doesn't build a faceprint. If an image is rejected or you cancel the upload, the file is deleted.
If an image is rejected, you'll be told it doesn't meet our community guidelines and can upload a different one. Review decisions apply to the image only; they do not affect your account standing.
Uploading a picture is entirely optional โ everything else on the Platform works the same without one. See Terms of Service Section 4 for the full terms.
Keeping your account safeโ
- Use a unique password that you don't reuse on other sites.
- Treat unexpected two-factor codes as a warning sign, not an annoyance.
- GalaxyGrails.io will never ask for your password, a two-factor code, or your Stripe login โ not by email, not in chat, not on a live stream. Anyone who does is impersonating us.
- Report suspicious accounts or messages to [email protected].
For identity verification, see KYC Process. For closing your account, see Account Management.