> For the complete documentation index, see [llms.txt](https://docs.limecall.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.limecall.com/account/security.md).

# Security

Passwords, two-step sign-in, sessions and closing your account.

Open **Settings → Security**.

## Password

Change your password here. Use a long, unique one from a password manager rather than something memorable — LimeCall holds your call recordings, customer data and the ability to spend money on calls.

## Two-step sign-in

Enable a second sign-in step if it is available on your account. It is the single most effective protection against a stolen password, and takes a minute to set up.

Store your recovery codes somewhere you can reach without being signed in.

## Sessions

See where your account is signed in, and sign out of sessions you do not recognise.

Sign out everywhere after:

* changing your password,
* losing a device,
* someone leaving with shared access.

Signing out everywhere invalidates existing sessions, so anyone holding one must sign in again.

## API keys

Keys are managed under **Settings → API keys**. Two scopes are available:

* **Read** — list calls, leads and analytics.
* **Write** — place calls, send messages and update records.

Grant read-only unless the integration genuinely needs to write. See [API keys](/developers/api-keys.md).

Revoke keys you no longer use, and any key created by someone who has left.

## Device and SIP credentials

SIP credentials let a device place calls billed to your account. Treat them as passwords: never share them, and regenerate them if a device is lost or a person leaves. See [Devices](/virtual-numbers/devices.md).

## Who can see what

Access to recordings, transcripts and customer data follows roles. Review them periodically — access granted for a one-off task tends to stay. See [Team & roles](/account/team-and-roles.md).

## Personal data

LimeCall holds personal data about your customers: numbers, recordings, transcripts and enrichment results.

If you are subject to GDPR or similar rules:

* have a lawful basis for recording, and disclose it — see [Recording, consent & AI disclosure](/ai-receptionist/recording-consent-and-disclosure.md),
* be able to honour access and erasure requests — deleting a contact removes its associated history,
* cover enrichment in your privacy notice, since it obtains data from third parties,
* contact support for a data processing agreement or sub-processor details.

## Closing your account

Closing is different from cancelling a plan. Cancelling stops billing; closing deletes your data.

Before closing:

* **Port out any numbers you want to keep.** Closing releases them permanently.
* **Export anything you need** — call records, transcripts, contacts.
* **Disconnect integrations** so they do not fail noisily elsewhere.

{% hint style="warning" %}
Closing is irreversible. Recordings, transcripts, contacts and call history are deleted and cannot be recovered.
{% endhint %}
