Signing in, and staying signed in
There are no passwords. How the sign-in link works, how long a session lasts, and why a tablet's lasts far longer than yours.
There are no passwords in Tavorly. The sign-in page asks only for your work email — “Sign in with your work email” — and mails you a link.
That is a deliberate security decision, not a convenience one. A brand with no passwords has nothing to leak in a breach, nothing to reuse from another site, nothing to reset, and no shared credential written on a note by the pass.
Signing in
- Enter your work email and press Email me a sign-in link.
- Open the link from your inbox.
- Confirm on the Confirm sign-in screen, which names the account you are about to sign in as.
The confirmation step exists so that following a link — from a mail preview, a scanner, or a forwarded message — cannot sign you in silently. A link is single-use, so a forwarded one is worth nothing once used.
If the link does not arrive, check that the address matches your invitation exactly. Only invited addresses receive links; a typo produces no error, because telling a stranger whether an address exists in your brand would be a leak in itself. Ask a brand admin to check your row on Users.
How long a session lasts
Different principals get very different lifetimes, and the differences are the point:
| you are | session lasts |
|---|---|
| Brand admin | 1 day |
| Viewer, Creator, Approver | 14 days |
| A recipe viewer on the line | 180 days |
A brand admin can change your palette, your locations and your team, so that session is the most valuable one to steal and expires soonest. A cook’s tablet can only read published recipes, so it stays signed in for six months — because a screen that logs itself out mid-service is a screen nobody trusts.
Sessions are rolling: using Tavorly extends yours, so an active session does not expire out from under you. It is inactivity that ends it.
⚠ If you are a brand admin, expect to sign in most days. That is working as designed, and it is the cost of the permissions you hold. If it is genuinely disruptive for someone who does not administer anything, they probably should not be a brand admin — see Inviting your team.
Signing out
Signing out ends the session immediately. Deactivating a user on Users does the same from the other side, and keeps all of their history.
⚠ One browser cannot hold both an admin and a device session
Signing a tablet in replaces whatever session that browser held, and signing back in as yourself ends the device session. On a real iPad that is exactly right — it is a separate device. On your own laptop it is a surprise.
So enrol devices from the device, and do your admin work from your own machine. See Enrolling a recipe viewer.
Manager PINs are not sign-ins
A manager PIN authorises a food-safety sign-off on a shared screen. It does not sign anyone in, does not create a session, and does not appear on Users. See Manager PINs.
Last checked against the product on August 18, 2026.