Your account security settings are found in Settings > Account from the sidebar. This is where you manage your password, two-factor authentication, active sessions, and account deletion.
Click your profile icon in the top right corner, then click Account Settings. Or go to Settings in the sidebar.
2
Find the Password section
Scroll down to the Change Password section.
3
Enter your current password
Type your existing password to verify it’s really you.
4
Enter your new password
Type a new password. It must be at least 8 characters. We recommend using a mix of letters, numbers, and symbols.
5
Confirm and save
Type the new password again to confirm. Click Change Password.
After changing your password, you’ll receive a confirmation email. All other sessions stay logged in — if you suspect someone else has access to your account, revoke all sessions (see below) after changing your password.
Two-factor authentication adds a second layer of security. After entering your password, you’ll also need a 6-digit code from an authenticator app on your phone.
1
Go to Account Settings
Navigate to Settings > Account.
2
Find the Two-Factor Authentication section
Click Enable 2FA.
3
Scan the QR code
Open your authenticator app (Google Authenticator, Authy, or Microsoft Authenticator) and scan the QR code shown on screen.
4
Enter the 6-digit code
Your authenticator app will show a 6-digit code. Enter it to verify the setup works.
5
Save your backup codes
You’ll be shown a set of one-time backup codes. Save these somewhere safe — a password manager, a printed sheet in a safe, or a secure note. If you lose your phone, these codes are the only way to get back into your account.
If you lose your phone and don’t have your backup codes, you will be locked out of your account. There is no way around this — it’s what makes 2FA secure. Save those backup codes.
Which authenticator apps work?
Any TOTP-based authenticator app works: Google Authenticator, Authy, Microsoft Authenticator, 1Password, Bitwarden. We recommend Authy because it backs up your codes to the cloud.
How do I disable 2FA?
Go to Settings > Account, find the Two-Factor Authentication section, and click Disable 2FA. You’ll need to enter a 6-digit code from your authenticator app to confirm.
Account deletion is permanent, but includes a 30-day grace period.
1
Go to Account Settings
Navigate to Settings > Account.
2
Scroll to the Danger Zone
At the bottom of the page, find the Delete Account section.
3
Click Delete Account
A confirmation dialog will appear.
4
Type DELETE to confirm
Type the word DELETE (in capitals) into the text field. This prevents accidental deletion.
5
Click Confirm Deletion
Your account enters a 30-day grace period.
During the 30-day grace period, your account is deactivated but not destroyed. Your AI receptionist stops answering calls immediately. If you change your mind, log back in within 30 days and your account will be reactivated with all data intact. After 30 days, everything is permanently deleted and cannot be recovered.
Use one of the backup codes you saved when you enabled 2FA. Each code can only be used once. Go to the login page, enter your email and password, then click “Use a backup code” instead of entering a 6-digit code. If you’ve used all your backup codes and lost your phone, contact support at support@closethecall.com with proof of identity — we’ll manually verify your account and help you regain access.
Can I require 2FA for all team members?
Not currently. Each team member enables 2FA on their own account independently. We recommend that all users with Manager or Owner roles enable 2FA, but it cannot be enforced at the account level. This is on our roadmap.
How do I change my email address?
Go to Settings > Account and update the Email field in the Profile section. You’ll receive a verification email at your new address. Click the link in that email to confirm the change. Your old email will no longer work for login after verification.
Is my data encrypted?
Yes. All data is encrypted in transit (TLS/HTTPS) and sensitive fields like API keys and tokens are encrypted at rest using AES-256 encryption. Passwords are hashed with bcrypt (12 rounds) and are never stored in plain text. Password reset tokens are hashed with SHA-256 before storage.