Reset your password
It takes three steps. This page shows only the step you can complete now; a valid, single-use link in the email is required before a new password can be set.
Enter your registered email
Email only. We do not ask for your date of birth, a secret question, or your display name — every extra field is another way for a stranger to work out who has an account here.
What you see next
If that email has an account, we have just sent a reset link to it.
The link lasts 30 minutes and works once. If nothing has arrived in 10 minutes, check your junk mail.
That is the whole message. There is no version that says the email does not exist, no version that says an account is locked, and no hint that you might have signed up with a different address.
The same screen comes back after the same delay whether the address is registered or not.
Set a new password (opened from the link in the email)
This link has 26 minutes left before it expires.
Saving this signs you out of every other device, and the link you just used stops working straight away.
Changing your password does not lift a cooldown
If your account is in a cooldown week, resetting your password still lands you on the cooldown screen. The end time is stored against the account and checked on the server. It has nothing to do with your sign-in session. This is spelled out here because "forgotten password" is one of the detours people try during a cooldown.
Why the confirmation stays vague
In most products, "that email is not registered" is a small inconvenience. Not here. tibbi is a tool about gambling behaviour, so confirming that an address has an account is already disclosing something sensitive about whoever owns that address.
Anyone typing someone else's email into the box above gets exactly one answer, identical every time. That is structural, not a preference.
How the reset links work
- Randomly generated, stored hashed, valid for 30 minutes.
- Single use; asking for a new one kills the old one.
- At most 3 requests per email per hour, counted on the server.
- No email address or user id is embedded in the link.
- Every use is logged for audit, never with the password itself.
Not available: one-tap sign-in links, SMS codes (which would mean storing your phone number), and security questions. Adding any of them would go through its own privacy review, the same as social sign-in.
Looking for a phone number?
The support centre is public. No account needed, and no password to remember.