What the second factor protects
Both actions under Your data in Settings → Data & privacy are gated:
If either is missing, the action refuses rather than half-running, and the product says
Confirm two-factor authentication, then try again. There is no way to skip the second factor on export or deletion.
A confirmation lasts fifteen minutes and is bound to your account and to the session that asked for it. A code you confirmed in another tab on another machine does not unlock this one. Guests never meet the gate, because a guest has no account to export or delete, and the row reads Two-factor authentication is available after you sign in.
Enrol an authenticator
You need an authenticator app on a phone or a computer. The enrolment challenge is valid for ten minutes, so finish it in one sitting.1
Open the row
Go to Settings → Data & privacy → Two-factor authentication. Before enrolment the row reads
Not set up yet. Add an authenticator app before you export or delete this account.2
Choose Add authenticator
Select Add authenticator. Cortex draws an
Authenticator QR code.3
Scan, or type the key
Scan the code in your authenticator app. The screen says
Scan this code in your authenticator app. Cortex never shows the secret as text. If your device cannot scan, use Cannot scan? Enter this key: and type the key by hand.4
Confirm the code
Type the six digits your app shows into Authenticator code and choose Confirm code. The code refreshes every thirty seconds, so use the current one.
5
Check the result
The row then reads
An authenticator app is already linked to this account.Confirm an export or a deletion
Once an authenticator is linked, the two destructive actions ask for a code the first time you use them, and then stay unlocked for fifteen minutes.1
Start the action
Choose Export my data or Delete all data under Your data.
2
Confirm to continue
When Cortex needs a fresh confirmation it shows Confirm to continue with an
Authenticator code field. Enter the current code and choose Confirm code.3
Finish the action
Export assembles the file while you wait and confirms
Download started — a JSON copy of what we hold for this account. Deletion asks once more in its own dialog, then reports Deletion requested — your data will be permanently erased within 30 days. Signing in again during that time cancels it.Confirm two-factor authentication, then try again. Nothing is exported and nothing is scheduled. See Data and privacy for what the export contains and how the deletion grace period works.
If you lose the authenticator
Losing the device does not lock you out of Cortex. Sign-in does not ask for a second factor, so you can still open Chat, Code and Bot exactly as before. What you lose is the ability to export or delete your data until you can produce a code again. Cortex has no self-service fallback for this today: Show recovery codes answersRecovery codes are not available on this deployment., and there is no control that removes a linked authenticator. Practical consequence: use your authenticator app’s own backup or device-transfer feature, and keep it working before you need it.
What is not available yet
The two-factor row is drawn beside several controls that are not wired on this deployment. The product says so in place rather than failing when you press them.
SMS codes and hardware security keys are not offered at all. An authenticator app is the only second factor.
States you may see
A status that could not be read is never treated as “enrolled”: the gate stays closed and the action refuses.
Related
- Accounts and sign-in - sign-in methods, and why the dialog has no code field.
- Data and privacy - export, deletion, cookies, memory and retention.
- Settings - where the Data & privacy tab sits among the seven tabs.
- Security and privacy reference - what Cortex stores and what it does not claim.
- Troubleshooting - other gates and refusals across the product.