Skip to content

The mobile app

Device security

A phone gets lent, lost, stolen. The app plans for each of those.

Updated on August 14, 2026

The biometric lock

The app can lock itself behind your phone's fingerprint or face recognition. The setting is off by default and is switched on in the app's security settings. Once active, React Box asks for your biometric identity when you come back to it after leaving.

Note

The lock protects the open app on that device; it replaces neither your password nor two-factor authentication, which protect the account itself.

The re-lock delay

You choose the balance between convenience and protection.

  • Immediate — the lock re-arms as soon as you leave the app. The strictest setting, suited to a phone that gets passed around.
  • After one minute — the default: stepping into the camera or answering a message does not send you back to the unlock screen.
  • After five or fifteen minutes — for heavy use where you juggle several apps.

Staying signed in

The mobile session is deliberately long: nobody should have to retype a password every morning just to photograph an invoice. It extends itself while you keep using the app, and it is the biometric lock — not a forced sign-out — that protects the device day to day.

Note

A failure to read the phone's keychain does not sign you out: the app tells a technical problem apart from a session that genuinely expired.

Phone lost or stolen

Three moves, in this order.

  1. 1

    Sign the device out

    From the Security tab of your account, on any other device: the session list lets you cut off the phone in question.

  2. 2

    Change your password

    Ticking the option that signs out all other devices, so nothing is left behind.

  3. 3

    Check your linked accounts

    If you signed in through a social account, secure that too: it is the door in.

Tip

The biometric lock buys you the time to act: without your fingerprint or your face, the app stays shut even on an unlocked phone.