# Account security: getting in, taking everything, leaving.

Source: https://www.secondbrain.media/guide/account-security  
Language: en  
Spanish version: https://www.secondbrain.media/guide/account-security.es.md

---

The Security tab of your account settings holds three things: two-step verification, exporting all your data and deleting the account. This page explains how each one is set up and what exactly happens when you use it.

## Two-step verification

A code from your authenticator app on top of your password. If someone steals your password, it is not enough to get in.

1. **Open the tab** — Your name, top right → Account settings → Security, and hit Enable under two-step verification.
2. **Scan the code** — With Google Authenticator, 1Password, Authy or whichever you use. If you cannot scan, the key is written under the QR so you can paste it by hand.
3. **Confirm with the code** — Type the six digits your app is showing at that moment and confirm. Only then is it active.
4. **Save the recovery codes** — They are shown once, right after you enable it. Copy them into your password manager or onto paper — anywhere except the same phone that holds the authenticator app.

From then on, every sign-in asks for the code as well as the password. The tab shows how many unused recovery codes you have left, and from there you can generate new ones — which void the previous set — or turn verification off.

> **If you lose your phone**
>
> Each recovery code gets you in once, and is then spent. That is why where you saved them matters: if they live on the same phone as the authenticator app, they are worth nothing on the day you need them.
>
> Once you are back in with a code, the first move is to generate new codes and set verification up again on the new phone.

## Export all your data

The Export all my data button builds a ZIP on the spot and downloads it. No emailing support, no waiting for approval.

Inside there is one folder per workspace, with:

- Your documents in Markdown, which is the format that will still be readable anywhere.
- The data in JSON: daily notes, tasks, meetings and their action items, Atlas entities and their links, canvases, definitions, deliverables and the digests generated.
- The files inside the ZIP, not as links: up to 150 MB per workspace. Whatever does not fit is still listed, with a signed link that lasts seven days — the limit is disclosed, not hidden.
- A summary of what was included and what was left out.

Integration tokens and secrets never leave in the export.

## Delete the account

It sits last in the tab, and runs through four steps: it shows you what gets deleted, asks for a reason, makes you type a confirmation word and asks for your password.

On confirm it wipes, permanently and with no grace period: your account and profile, your daily notes, documents and tasks, your meetings and their recordings, your workspaces and the files you uploaded.

Two things do not share that fate:

- The spaces you share with other people are not deleted: they are transferred to the oldest member, so the team is not left without its content.
- If you have an active subscription, it cancels itself. There is nothing to cancel separately.

Download the export ZIP before you confirm: afterwards there is nothing left to ask us for.
