FGID Account Security and Identity Verification Rules
Applicable Service: FGID (FurryGoods Identity)
Version: First Edition
Publication Date: May 28, 2026
Effective Date: June 7, 2026
Last Updated: May 28, 2026
These Rules are intended to protect FGID Accounts, user data, and the security of Integrated Services and form part of the FGID User Agreement.
Article 1 Passwordless Security Principles
FGID is a passwordless account system. It does not set an FGID Account password and does not support login using a verification code sent by email or SMS. Users may log in only through Steam, Google, X.com, or a Passkey.
FGID implements account-security measures in accordance with the principles of proportionality to risk, data minimization, necessary verification, and the user's right to appeal.
Article 2 User Security Obligations
Users shall:
- properly protect their linked Steam, Google, and X.com accounts;
- properly protect their devices, Passkeys, recovery credentials, and login sessions;
- not provide any person with a third-party account password, Passkey private key, recovery code, or session token;
- link two or more login methods where practicable;
- periodically review login devices, sessions, linked methods, and authorised applications;
- immediately terminate sessions, revoke affected links or Passkeys, and report the matter to FGID after discovering an anomaly;
- not use any client, plug-in, script, or login page from an unknown source; and
- not assist another person in circumventing identity verification or risk controls.
Official FGID customer service personnel will not request a third-party account password, Passkey private key, complete recovery code, or complete access token.
Article 3 Supported Login and Security Methods
FGID supports only:
- Steam;
- Google;
- X.com; and
- Passkeys.
FGID may additionally use trusted-device confirmation, session reconfirmation, a security holding period, manual review, or identity verification proportionate to risk. These measures do not constitute a new password-based login method.
Article 4 Risk Identification
We may identify risk based on an anomalous IP address, region, device, browser, failed login, automated attack, sensitive operation from a new device, change in linked relationships, token anomaly, security report, or lawful request from a competent authority. A risk signal does not by itself establish unlawful conduct, and users may appeal in accordance with these Rules.
Article 5 Tiered Identity Verification
5.1 Basic Verification
Basic verification may include logging in again through a linked Steam, Google, X.com account, or Passkey, confirming a trusted device, or verifying the current session.
5.2 Enhanced Verification
For account recovery, unlinking all login methods, changing key data, closing an account, or responding to an anomalous login, FGID may require verification through multiple linked factors, historical login records, authorised Integrated Services, trusted devices, or other data proportionate to the risk.
5.3 Identity or Organisation Verification
For organisation verification, developer verification, a material dispute, a legal requirement, or a high-risk business scenario, FGID may require a government-issued identity document, proof of organisation, or authorisation document and will endeavor to collect only the necessary fields.
5.4 Biometrics
FGID will not use facial, voiceprint, fingerprint, or other biometric data without providing a specific notice. If such use becomes necessary in the future, FGID will disclose the purpose, provider, retention period, deletion rules, and alternatives and will obtain express consent where applicable.
Article 6 High-Risk Operations
The following operations may trigger re-authentication, a waiting period, notice, or manual review:
- linking or unlinking Steam, Google, or X.com;
- adding, deleting, or replacing a Passkey;
- removing the last valid login method;
- changing a public nickname, avatar, or key contact data;
- revoking authorisations for a large number of Integrated Services;
- changing an organisation administrator;
- creating or rotating developer credentials;
- applying to close an account; or
- any other operation that may result in a transfer of account control.
Article 7 Security Measures
FGID may require re-authentication, terminate sessions, revoke access tokens or Passkeys, suspend third-party login, restrict changes to key data, temporarily freeze an account, block a malicious device or application, communicate risk status to necessary Integrated Services, and retain evidence or make reports in accordance with law. Where a risk is urgent, FGID may take measures before notifying the user.
Article 8 Account Recovery
A user who cannot log in may request account recovery or submit an appeal through [email protected]. We may consider the following evidence in determining account ownership:
- continued control of a Steam, Google, X.com account, or Passkey;
- usual devices, regions, and login history;
- historical third-party account-linking records;
- the FGID ID, account-creation data, and historical public profile data;
- authorised Integrated Services and related business records;
- proof of identity or organisation; and
- other data that reasonably demonstrates control.
No single item of evidence is guaranteed to be sufficient to recover an account.
Article 9 Public FGID ID and Nickname
The FGID ID is a public, unique, and generally persistent account identifier. Users may change their nicknames, but a nickname change does not change the FGID ID. To prevent impersonation, fraud, or harassment, FGID may restrict the frequency of nickname changes or require corrective action.
Article 10 Security Incidents and Vulnerability Reports
Please report an unauthorised login or link, a leaked Passkey or token, a phishing page, an account-takeover vulnerability, or abnormal registration at scale to [email protected].
Article 11 Data Protection
Identity-verification and security data is processed in accordance with the FGID Privacy Policy. FGID does not sell such data, use it for cross-context behavioural advertising, or display advertising based on user profiling.
Article 12 Notices, Appeals, and Contact Details
After imposing a restriction, we will, to the extent permitted by security considerations and law, explain the category of reason and the means of appeal. The original security measure may remain in effect while an appeal is pending.
- Operator: 香港福瑞谷國際貿易有限公司 / HONG KONG FURRYGOODS INTERNATIONAL TRADE LIMITED
- Company Registration Number: 80485674
- Official FGID Website: https://id.furrygoods.cc
- Security, Account Appeals, and Customer Service: [email protected]
- Customer Service Notice: Telephone support is not provided and fixed customer service hours are not published. We generally provide an initial response within seven (7) business days after receiving complete information.
香港福瑞谷國際貿易有限公司
HONG KONG FURRYGOODS INTERNATIONAL TRADE LIMITED

