---
title: Accounts and sign-in
group: Start here
order: 3
summary: How sign-in works, how long you stay signed in on each device, two-step verification, and how to leave.
updated: 2026-10-07
---
## Signing in

You can sign in with Google or with an email. The same account works on the website, the desktop app and the phone app. Sign-in in the apps happens in your browser and returns to the app with a one-time code, so the app never sees your Google password.

## How long you stay signed in

| Where | How long |
|---|---|
| **Phone app** and **desktop app** | Your session renews itself while you use the app, until you sign out or it is revoked. |
| **Website** | Your session renews itself for a limited time; after that, or if it is revoked, you sign in again. |

A longer-lived refresh token renews the short-lived access token. If a session cannot be renewed (you signed out elsewhere, or it was revoked), the app takes you to the sign-in screen instead of failing quietly.

> **Note** If the apps ever sign you out when you did not ask, update to the latest version and sign in once more.

## Seeing and ending sessions

Open **Settings > Sessions and devices** on the website to see where you are signed in. You can sign out one session or **sign out everywhere else**. Signing out of the phone app also removes the paired computers from that phone (you can pair them again at any time; nothing on the computers is changed).

## Two-step verification

Turn it on in **Settings > Security**. After that, signing in asks for a code from your authenticator app. Keep your recovery codes somewhere safe: they are the way back in if you lose the device.

## Deleting your account

Open **Settings > Privacy & data > Delete account** and type your account email to confirm (plus a two-step verification code if you have it on). You are signed out everywhere and every key stops working at once. Your account is deleted after 7 days; to keep it, sign in before then and choose **Keep my account**. If you have a paid plan, cancel it first in **Settings > Billing** so you are not charged again; see [Plans and billing](/docs/billing). What is deleted and what is kept is listed on [Delete your account](/delete-account).

## Recover without losing a working session

A connection timeout or busy service is different from a refused refresh token. Retry connectivity first; do not repeatedly clear app data to fix a transient request failure. If the server rejects renewal, sign in again through the normal flow. Check Sessions and devices for an unexpected session and revoke it deliberately.

If an app login callback does not return, keep the browser and app open, confirm that the link handler is registered, and restart sign-in to obtain a new one-time code. Do not share callback URLs or recovery codes. Resolve two-step verification and authorization failures through their normal recovery paths; do not turn protection off.

Session/device revocation, provider disconnection, MCP key revocation and removing a paired machine are separate actions. Review each credential or connection you intend to remove. See [API and keys](/docs/api-and-keys) and [Phone pairing](/docs/computers-pairing).
