Account & profile
Everything available at /app/profile — identity, security, notifications, and linked sign-in methods.
Identity
- Display name — shown next to your activity in audit logs and comments.
- Avatar — drag-drop or click to upload. We sign every URL so private avatars stay private.
- Email — changing your email triggers a confirmation message to the new address before the change applies.
Security
Password
Update your password from Profile → Security. You'll be asked to re-enter your current password; sessions on other devices stay signed in unless you also click Sign out everywhere.
Multi-factor authentication (TOTP)
- Click Enroll, scan the QR code with an authenticator app (1Password, Authy, Google Authenticator), and enter the 6-digit code.
- Disabling MFA also requires a valid code — we never let the page disable it without proof of possession.
- Your workspace admin may enforce MFA from the Security Center — see Security Center.
Active sessions
"Sign out everywhere" revokes refresh tokens for every device except the one you're using. Use it after losing a laptop or rotating a shared password.
Sign-in methods
- Email + password — always available.
- Google — link or unlink at any time. You need at least one sign-in method to keep your account.
- SSO — used automatically when your email domain is provisioned by a workspace admin (see Enterprise SSO).
Notifications
Four toggles, stored in the user_notification_prefs table:
- Product updates — major releases.
- Weekly digest — what shipped and what's happening across your workspaces.
- Security alerts — new sign-in, password changes, MFA enrollment. Cannot be fully disabled — critical events are always sent.
- Mentions & comments — when someone tags you in a project comment.
Workspaces & danger zone
The Workspaces card lists every workspace you belong to with your role. Use the danger zone to Sign out everywhere. To delete your account, email support — we run a 30-day soft-delete grace period.
Account deletion grace period
Deleted accounts are recoverable for 30 days. After that, your personal data is purged from operational stores; aggregated, anonymized usage metrics may persist.
Was this page helpful?Send feedback →