What shipped on Realr.
Plain release notes. We write each entry the way we’d brief a teammate — what changed and why, not how excited we are to announce it.
05dffceBlock / unblock users
You can now block any profile from its footer. While a block is in place, the other side can’t see your Realr and neither of you can start a transaction with the other. Existing couple links break on block. Manage your blocked list any time from /me/privacy.
f3e5cceTwo-factor step-up on destructive actions
Deleting a user (admin), changing your sign-in email, signing out other devices, and deleting your account now all require a fresh second-factor verification within a 5-minute window. A stolen session cookie is no longer enough to weaponize any of these.
97abffbTOTP two-factor auth
Enroll from /me/security. Scan the QR with any authenticator, save the eight backup codes once, then verify with a 6-digit code. Backup codes are one-shot. Admin accounts get a calm nudge banner until they enroll.
2647300Every admin action is now on the record
Approvals, rejections, deletions — every move an operator makes leaves a trail with who, what, and when. The log outlives the operator, so accountability for past decisions doesn’t walk out the door with them.
33af5acMobile review pass
Cookie banner now pushes the page padding up so the last paragraph on every marketing surface clears it. Widget studio embed code, snippet, and iframe all gain defensive width constraints so 375px viewports never gain a horizontal scrollbar.
dc38d01Hardened the front door
Sign-in, embeds, and every other request now ride on a tighter set of browser-level protections. Most users will never see the difference, which is the point — fewer doors left open for a session to leak through.
634df29Notifications now feel like Realr
Notification emails and the in-app inbox stopped reaching for stray emoji and switched to the same calm icon system as the rest of the product. Same content, less noise.