Email Is Not Login
StatelessID does not store your email address, does not use email as a login credential, and does not send login codes to your inbox. Your access key is your only way in.
How the login model works
Every account on StatelessID is identified by a 32-character access key and nothing else. There is no separate username. There is no password field and no email field on the login form. Submit the key, and if it matches an account, you are in.
We do not copy payer contact details from checkout into our billing database. The payment processor may keep its own payer record for receipts and renewals; we store subscription status, a one-way payer handle for rekey, and your access-key hash — not email, name, or phone.
What this means for account recovery
There is no forgot-password or magic-link flow. If you lose your access key, use Verify subscription on the login page after two failed attempts — that proves payer identity through the processor and issues a new key once.
We do not email keys or recovery links. Anyone who can read an inbox cannot use that alone to open your dashboard. You are responsible for storing the key; recovery friction is the tradeoff for not keeping operator contact fields on our side.
What StatelessID does not send by email
We do not send login links, verification codes, password resets, quota notices, or key-rotation notices from a StatelessID mail server. Receipts and renewal mail, if any, come only from the payment processor under its own terms.
If you receive mail claiming to be from StatelessID with a login link or a code, treat it as phishing. The dashboard never uses email as a factor.
No verification email after signup
Your account becomes active the moment checkout completes and the access key page displays. There is no pending state waiting for email confirmation.
If you completed checkout and reached the access key page, your account is live. Log in immediately with the key shown on that page.
Why we chose key-only access
Email login ties every dashboard session to a durable contact field we would have to store, protect, and disclose in a breach. StatelessID is built so a database leak cannot hand an attacker a mailing list or inbox recovery path.
A 32-character access key is a single secret you control. Store it like any other high-value credential. If it is lost, payer rekey through checkout identity is the supported recovery — not an operator reading your inbox on your behalf.
This model is intentional, not an unfinished signup flow. There will never be a username field, password reset mail, or “verify your email” step added later.
Troubleshooting
If you enter an email address in the login field, the form clears silently — the field expects your access key, not email. Find the key in your password manager.
If you need a receipt, check the payment processor account you used at checkout. Missing receipt mail does not block dashboard access.
Knowing your email does not grant dashboard access. Only the access key or a successful payer rekey does.