Account access: sign in, password reset and the verification step behind the login
A practical walk-through of the sign-in flow on phone and web, what to do when the password does not work, and the verification step that sits behind every first login.
The standard sign-in flow
Open the app or the desktop site, enter the phone number or email registered at sign-up, type the password and confirm. On the mobile app, the first login is followed by a one-time device registration; on the desktop site, the first login is followed by an email confirmation. The two paths converge on the same account record.
When the password does not work
The "forgot password" link is the entry point. The platform sends a reset link to the registered email or a one-time password to the registered phone. Use the most recent link sent; older links expire within fifteen minutes. If neither email nor phone is reachable, the platform requires identity verification before a manual reset.
When the account is locked
Accounts lock after a small number of failed attempts. The lock is a security control, not a ban; it lifts automatically after fifteen minutes. If the lock persists, contact customer care with the registered phone or email; the platform will verify identity before unlocking.
The verification step behind the first login
Most platforms complete identity verification during sign-up, not at first login. If the platform asks for documents on first login, the request is usually because the sign-up flow was interrupted; complete the verification in the account settings under "verification" or "KYC". The safety page walks through the documents typically requested.
The mobile and desktop apps share one record
The same phone number or email logs in to the mobile app and the desktop site. Wallet balance, KYC status, responsible-play controls and history are shared across both. There is no separate desktop account.
What to do if you cannot reach the registered email or phone
If you no longer have access to the registered email and the registered phone is no longer active, the account recovery path is identity verification. The platform will ask for a PAN, an Aadhaar and a recent address proof; it will match the documents against the records it holds and unlock the account once the match is confirmed.
The customer-care escalation path
If the self-service flow does not work, file a support ticket. The customer-care guide on this site walks through what information to include and what to expect as a first response. Escalation to a supervisor is available when the first response is not useful.
The two-factor option
Most reputable rummy platforms offer a two-factor authentication option for the login flow. The second factor is usually an OTP sent to the registered phone or generated by an authenticator app. The two-factor option is independent of the password; even if the password is compromised, the account cannot be accessed without the second factor. Enable it.
How to enable two-factor
The two-factor option is in the account settings under "security" or "login". The setup is one screen: enter the registered phone to confirm an OTP, scan a QR code with an authenticator app or save a recovery code. Once enabled, the second factor is required at every login from a new device.
What to do if the second factor stops working
If the registered phone is lost or replaced, the second factor stops working. The recovery path is identity verification through customer care: the platform asks for a PAN, an Aadhaar and a recent address proof, matches the documents against the records it holds, and resets the second factor. The customer-care guide walks through what information to include in the support ticket.
The biometric option on mobile
On iOS and Android, the platform may offer a biometric login option (Face ID, Touch ID, fingerprint). The biometric option is a convenience; it does not replace the password or the second factor. Use it as a way to log in faster, not as a substitute for the security controls above.
The session timeout
Most reputable platforms enforce a session timeout: after a period of inactivity (commonly 15-30 minutes), the platform logs the player out and requires a fresh login. The timeout is a security control, not an inconvenience; it limits the window in which an unattended device can be used. If you find yourself logged out unexpectedly, the timeout is the reason.
How to extend the session
Most platforms offer a "keep me logged in" option at the login screen. The option extends the session by storing a long-lived authentication token on the device; the token is cleared when you explicitly log out or clear the browser cookies. The option is convenient; use it on devices you trust and avoid it on shared or public devices.
The device-management path
Most platforms offer a device-management path in the account settings: a list of currently-logged-in devices, with a "log out" option for each. The path is useful when you have logged in on a device you no longer use; clear the entry to log out the old session remotely. The customer-care guide walks through the support-ticket template for any device-management issue that the self-service path does not resolve.
The email-recovery path
If you have lost access to the registered phone but still have the registered email, the recovery path is straightforward: request a password reset to the registered email; the platform sends a reset link; the link expires in 15 minutes. The link directs you to a reset screen; enter the new password twice and confirm. The session tokens for any previously-logged-in devices are cleared.
What the email recovery does not do
The email recovery does not change the registered email; it only resets the password. To change the registered email, contact customer care with identity verification. The customer-care guide walks through the support-ticket template.
The phone-recovery path
If you have lost access to the registered phone but still have access to the registered email, the recovery path is the same as the email-recovery path above. If you have lost access to both, the recovery path is identity verification through customer care: the platform asks for a PAN, an Aadhaar and a recent address proof, matches the documents against the records it holds and resets both the registered phone and the password.
The session security checklist
A useful checklist for session security: enable two-factor authentication; set a strong password (12+ characters, mixed case, numbers and symbols); enable the session-timeout extension only on devices you trust; review the device-management path monthly and log out any device you no longer use; change the password every 90 days as a routine. Five checks; five minutes; a meaningful reduction in the risk of account compromise.
What the platform sees at login
At every login, the platform records: the registered phone or email; the device fingerprint (browser type, operating system, screen size); the IP address and the approximate geolocation; the timestamp; the previous login timestamp and geolocation. The platform uses this information to detect unusual login patterns (a login from a new device, a login from a new geolocation, a login shortly after a previous login from a different geolocation). If the pattern triggers a flag, the platform may require an additional verification step (an OTP, an authenticator code, an identity verification).
The unusual-login flag
If you log in from a new device or a new location, the platform may send a verification code to the registered phone or email. Enter the code at the verification screen; the login completes. If you do not receive the code within five minutes, request a resend. If the second code does not arrive, the platform may lock the login attempt; contact customer care with identity verification.
The social-login option
Some platforms offer a social-login option (Google, Facebook, Apple) for the login flow. The social-login option is a convenience; it does not replace the password or the two-factor option. Use it as a way to log in faster, not as a substitute for the security controls above. Note that social-login links your platform account to the social provider's identity; if you disable the social provider, you may lose access to the platform account.
The support-team escalation
If the self-service recovery paths above do not work, file a support ticket. The customer-care guide on this site walks through the support-ticket template: the registered phone or email, the platform and app version, a one-paragraph description, and a screenshot or transaction ID. For login-recovery tickets, the description should specify which recovery path you tried and what happened. The expected first-response window is 24 hours on weekdays.
The supervisor escalation
If the first response is a request for information you already provided, reply with the original ticket ID and a polite note that the information is attached. If the response is a deflection ("we cannot help with this"), ask for the path to escalation to a supervisor. If the response is a fix or a clarification, confirm in writing and close the ticket.
What the desk recommends
The desk recommends that readers enable two-factor authentication as soon as the account is created. The two-factor option is in the account settings under "security" or "login"; the setup is one screen. The two-factor option reduces the risk of account compromise to near zero; it is the single most valuable security control on the platform.