# Account settings

> What the Settings page and Account security page let you do: view your profile, pick a default currency, set up two-factor authentication, review sessions, and request account deletion, with what happens to your keys, balance and records.

Your account controls are in two places: [Settings](/dashboard/settings) and Account security (`/account/security`), both under Account in the dashboard sidebar. This page walks through every control, says what is not there, and explains what happens to your API keys, wallet balance and records when you ask for your account to be deleted.

## What is on the Settings page

The page is titled **Settings**, and it has five tabs.

| Tab              | What it does                                                                         |
| ---------------- | ------------------------------------------------------------------------------------ |
| Profile          | Shows your name, email, user ID and role. Nothing on it can be edited.               |
| Default Currency | Saves your preferred currency: BDT or USD.                                           |
| Notifications    | A summary of your email alerts, with a link to the Notifications page.              |
| Security & MFA   | The same two-factor and session controls as the Account security page.               |
| Danger Zone      | Where you request account deletion.                                                  |

## Profile

The Profile tab, headed **Profile Information**, shows four read-only items:

- **Full Name**: the name on your account, or "Not provided" if none was set.
- **Email Address**: the address you sign in with and where alerts are sent.
- **Account Identifier (User ID)**: your account's ID, with a button to copy it. Quote it when you write to [support](/docs/support).
- **Role & Status**: a badge with your role (`user` for customers) and the date you joined.

There is no form to change the name or email. To correct either, ask [support](/docs/support) and say which one you want changed. Email also matters for verification: you need a verified email address before you can create an API key (see [API keys](/docs/api-keys)).

## Password

The Settings page has no change-password form. To set a new password:

1. On the sign-in page, choose **Forgot your password?**.
2. Enter your email address. You get an email with a **Reset password** button.
3. Open the link and enter a new password on the **Set a new password** screen.

The email says to ignore it if you did not ask for it, and your password stays unchanged. If you sign in with Google or GitHub, your account password is managed by that provider.

After changing a password, use **Sign out everywhere** (below) to end sessions you do not recognise.

## Connected accounts

There is no screen to link or unlink accounts. The sign-in and sign-up pages show **Continue with Google** and **Continue with GitHub** buttons when the platform has turned those providers on. If you only see the email and password form, they are off.

## Default Currency

The **Default Currency** tab ("Default Billing & Display Currency") offers a card for each currency enabled on the platform:

- **৳ BDT**: Bangladeshi taka, for local checkout, mobile wallets and regional settlement.
- **$ USD**: US dollars, for card and cryptocurrency billing.

Click a card to choose it. The choice is saved at once ("Currency preference saved to your profile.") and any currency switch open on the page follows it. If an administrator has turned a currency off, its card is not shown, and saving it is refused with "Currency ... is currently disabled."

The setting is your preferred pricing and checkout currency for subscriptions and wallet top-ups. It does not move money between wallets. Your USD and BDT balances stay separate; see [plans, credits and wallet](/docs/plans-and-wallet).

## Notifications

The **Notifications** tab lists receipts, quota warnings, renewal reminders and low wallet balance alerts, each with an "Enabled" badge. The badges are fixed text, not live switches. The real switches, the thresholds and the delivery log are on the [Notifications page](/dashboard/notifications); see [notifications](/docs/notifications).

## Two-factor authentication

Open the **Security & MFA** tab, or Account security (`/account/security`) directly. The **Two-Factor Authentication** card protects sign-in with a time-based code from an authenticator app (TOTP), such as Google Authenticator, 1Password or Authy. The badge on the card says:

- **Active**: you have a verified authenticator.
- **Optional**: you have none, and two-factor is not enforced on this platform.
- **Required for Admin**: you have none, and staff accounts must have one.

To turn it on:

1. Press **Set Up Authenticator App**.
2. Scan the QR code with your app. If you cannot scan, copy the secret key shown below the code and type it into the app.
3. Enter the 6-digit code from the app and press **Verify and Enable 2FA**.

From then on sign-in asks for your password and a current code. **Remove** next to the authenticator turns it off. Tokens supports authenticator apps only; the page offers no SMS codes or recovery codes. Keep the app on a phone you will not lose.

The [security and privacy](/docs/security-and-privacy) page explains why this is worth doing: your key and billing sit behind your sign-in.

## Active sessions

The **Active Sessions** card, "Devices and sessions currently signed in to your account", shows the number of sessions and, for each:

- the browser or device description,
- the IP address, and
- when it was last used.

It lists three sessions and shows the rest under **View all N sessions...**. Use:

- **Revoke** to end one session. That browser has to sign in again.
- **Sign out everywhere** to end all your sessions, including the one you are using. You will need to sign in again.

If you see a session you do not recognise, revoke it, change your password with the reset steps above, then check [your API keys](/dashboard/keys) for any you did not create.

## Theme and language

- **Theme.** The dashboard header has a button that switches between light and dark. On a first visit the site follows your operating system's setting. When you press the button, your choice is stored in that browser, so it is per browser and device, not part of your account.
- **Language.** There is no language setting. The dashboard is in English. These docs also exist in Bengali at `/bn/docs`.

## Delete your account

You cannot delete the account with one click. Deletion is a request that the Tokens team carries out.

1. Open the **Danger Zone** tab and press **Delete Account**.
2. Read the **Request Account Deletion** dialog. It states that all active API keys will be immediately revoked, that refunds of any remaining prepaid balance must be requested before closure, and that this cannot be reversed.
3. Press **Confirm & Email Support**. This opens an email to the support address, with a subject like "Account Deletion Request - User ID ..." and your email and user ID already in the message. Nothing is deleted yet. If no email program opens, open a ticket in [support](/dashboard/support) from the account you want deleted and include the same details.

The team then checks the account before closing it. No time frame is stated in the product.

### What has to be true first

Deletion is refused until both of these hold:

- **Every wallet balance is zero.** Wallets are per currency, so both USD and BDT must be at zero. If you have a balance, ask for a refund or an adjustment first; see the [refund policy](/refund-policy). Deleting the account does not refund anything.
- **No wallet reservations are pending.** A reservation is money held for a request that is still being settled. They clear on their own, so stop your tools and try again shortly.

Stop any agent that uses your keys before you ask, and save any data you want to keep, such as a [usage export](/docs/usage-and-alerts).

### What happens to your data

When the team deletes an account, in this order:

1. The account's upstream model key, if one exists, is revoked.
2. The sign-in record is removed, so the account can no longer sign in.
3. The account record is anonymized in place: the email becomes a random address of the form `deleted-<random id>@tombstone.invalid`, the name becomes "Deleted user", the role is reset to `user`, and the verified-email date is cleared.
4. Every API key on the account is set to revoked ("Account deleted") and stops working at once.
5. An entry is written to the audit log with the reason.

What stays: payment records, subscriptions, the wallet ledger, usage records and audit logs are not deleted, because they are financial and audit records. They remain attached to the same internal ID, but without your name or email. The account's email address is freed, so it can be used to register a new account later. The new account starts empty; it does not inherit the old keys, balance or history.

What is not stored in the first place: Tokens does not keep the content of your prompts and responses. See [security and privacy](/docs/security-and-privacy).

The action cannot be undone. A tombstoned account cannot be restored.

## Related

- [Notifications and email alerts](/docs/notifications)
- [Security and data privacy](/docs/security-and-privacy)
- [API keys](/docs/api-keys)
- [Getting help](/docs/support)

---
Page: https://tokens.bd/docs/account-settings
