Skip to guide

Start here

Accounts and sign-in

How sign-in works, how long you stay signed in on each device, two-step verification, and how to leave.

Last updated

On this page

Signing in

You can sign in with Google or with an email. The same account works on the website, the desktop app and the phone app. Sign-in in the apps happens in your browser and returns to the app with a one-time code, so the app never sees your Google password.

How long you stay signed in

WhereHow long
Phone app and desktop appYour session renews itself while you use the app, until you sign out or it is revoked.
WebsiteYour session renews itself for a limited time; after that, or if it is revoked, you sign in again.

A longer-lived refresh token renews the short-lived access token. If a session cannot be renewed (you signed out elsewhere, or it was revoked), the app takes you to the sign-in screen instead of failing quietly.

Seeing and ending sessions

Open Settings > Sessions and devices on the website to see where you are signed in. You can sign out one session or sign out everywhere else. Signing out of the phone app also removes the paired computers from that phone (you can pair them again at any time; nothing on the computers is changed).

Two-step verification

Turn it on in Settings > Security. After that, signing in asks for a code from your authenticator app. Keep your recovery codes somewhere safe: they are the way back in if you lose the device.

Deleting your account

Open Settings > Privacy & data > Delete account and type your account email to confirm (plus a two-step verification code if you have it on). You are signed out everywhere and every key stops working at once. Your account is deleted after 7 days; to keep it, sign in before then and choose Keep my account. If you have a paid plan, cancel it first in Settings > Billing so you are not charged again; see Plans and billing. What is deleted and what is kept is listed on Delete your account.

Recover without losing a working session

A connection timeout or busy service is different from a refused refresh token. Retry connectivity first; do not repeatedly clear app data to fix a transient request failure. If the server rejects renewal, sign in again through the normal flow. Check Sessions and devices for an unexpected session and revoke it deliberately.

If an app login callback does not return, keep the browser and app open, confirm that the link handler is registered, and restart sign-in to obtain a new one-time code. Do not share callback URLs or recovery codes. Resolve two-step verification and authorization failures through their normal recovery paths; do not turn protection off.

Session/device revocation, provider disconnection, MCP key revocation and removing a paired machine are separate actions. Review each credential or connection you intend to remove. See API and keys and Phone pairing.

Need help? Contact support with a redacted error and the affected version.