When a user try to login with our App, a user receives an email saying there was suspicious login attempt.
The email asks either changing password if the login was not by a user or veryfing it was by a user by entering temporary code in the email.
A user can login with temporary code once, but when a user log out, a user is not able to login again with neither temporary code nor the user’s own password. And a user receives an email about suspicious login attempt again.
Access to Twiitter go through our proxy server in US but, a user can be in any country.