Security Settings
Protect your BlaBlaNote account with robust security features. Manage your password, enable two-factor authentication, and control active sessions.
Accessing Security Settings
- Go to Settings
- Select Security
- Manage your security options
Password Management
Changing Your Password
If you signed up with email and password:
- Go to Settings > Security
- Click Change Password
- Enter your current password
- Enter your new password
- Confirm the new password
- Click Update Password
Password Requirements
Strong passwords should:
- Be at least 8 characters long
- Include uppercase and lowercase letters
- Include numbers
- Include special characters (!@#$%^&*)
- Not be a common password
- Not be reused from other sites
Password Best Practices
Create Strong Passwords
- Use a passphrase (e.g., "Purple-Elephant-Dances-42!")
- Use a password manager
- Never share your password
- Don't use personal information
Forgot Password
If you forget your password:
- Go to the login page
- Click Forgot Password
- Enter your email address
- Check your email for reset link
- Click the link and set new password
- Link expires in 60 minutes
Two-Factor Authentication (2FA)
What Is 2FA?
Two-factor authentication adds an extra layer of security by requiring:
- Something you know (password)
- Something you have (phone/authenticator)
Even if your password is compromised, attackers can't access your account without the second factor.
Enabling 2FA
- Go to Settings > Security
- Find Two-Factor Authentication
- Click Enable 2FA
- Download an authenticator app if needed
- Scan the QR code with your app
- Enter the verification code
- Save your backup codes
- 2FA is now active
Recommended Authenticator Apps
- Google Authenticator (iOS, Android)
- Authy (iOS, Android, Desktop)
- Microsoft Authenticator (iOS, Android)
- 1Password (with authenticator feature)
Backup Codes
When you enable 2FA, you receive backup codes:
- 10 single-use codes
- Use if you lose access to your authenticator
- Each code can only be used once
- Store securely (password manager, safe location)
- Generate new codes if you run out
To view/regenerate backup codes:
- Go to Settings > Security
- Find Two-Factor Authentication
- Click View Backup Codes or Regenerate Codes
- Verify with your password or current 2FA code
Using 2FA to Log In
After enabling 2FA:
- Enter your email and password
- You'll be prompted for 2FA code
- Open your authenticator app
- Enter the 6-digit code
- Code refreshes every 30 seconds
Disabling 2FA
WARNING
Only disable 2FA if absolutely necessary. Your account will be less secure.
- Go to Settings > Security
- Find Two-Factor Authentication
- Click Disable 2FA
- Enter your password
- Enter current 2FA code
- Confirm disabling
Lost Authenticator Access
If you can't access your authenticator:
- Use one of your backup codes
- If no backup codes, contact support
- Verification process required
- May need to verify identity
Connected Accounts
Viewing Connected Accounts
See which social accounts are linked:
- Go to Settings > Security
- Find Connected Accounts
- View Google, LinkedIn, or other connections
Benefits of Connected Accounts
- Alternative login - Sign in without password
- Account recovery - Backup access method
- Integration features - Calendar, contacts sync
Connecting an Account
- Go to Settings > Security
- Find the provider (Google, LinkedIn)
- Click Connect
- Sign in with that provider
- Grant permissions
- Account linked
Disconnecting an Account
- Go to Settings > Security
- Find the connected account
- Click Disconnect
- Confirm removal
Before Disconnecting
If you don't have a password set and only use social login, set a password first. Otherwise, you may be locked out of your account.
Session Management
What Are Sessions?
A session is created each time you log in. Sessions track:
- When you logged in
- Which device/browser
- Your location (approximate)
- Activity status
Viewing Active Sessions
- Go to Settings > Security
- Find Active Sessions
- See all your logged-in devices
Each session shows:
- Device type (Desktop, Mobile, Tablet)
- Browser name
- Operating system
- Last active time
- Location (city/country)
- Current session indicator
Ending a Session
To log out of a specific device:
- Find the session in the list
- Click End Session or the X icon
- That device is immediately logged out
End All Other Sessions
To log out everywhere except your current session:
- Go to Settings > Security
- Click End All Other Sessions
- Confirm the action
- All other devices logged out
Use this if:
- You suspect unauthorized access
- You're using a shared computer
- You want to start fresh
API Tokens
What Are API Tokens?
Personal API tokens allow:
- Programmatic access to your account
- Integration with other tools
- Automated workflows
- Developer access
Creating a Token
- Go to Settings > Security
- Find API Tokens
- Click Create Token
- Name your token (e.g., "Automation Script")
- Select permissions
- Click Create
- Copy and save the token immediately
Token Security
The token is shown only once. Copy it immediately and store it securely. Never share your API token publicly.
Token Permissions
Set granular permissions:
- Read interactions - View recordings and transcriptions
- Write interactions - Create new interactions
- Read contacts - View contact information
- Write contacts - Create/edit contacts
- Read tasks - View tasks
- Write tasks - Create/edit tasks
Managing Tokens
View tokens:
- See all your active tokens
- View creation date and last used
Revoke a token:
- Find the token in the list
- Click Revoke
- Token immediately stops working
Token Best Practices
- Create separate tokens for each use case
- Grant minimum necessary permissions
- Rotate tokens periodically
- Revoke unused tokens
- Never commit tokens to version control
Account Deletion
Deleting Your Account
Permanently delete your account and all data:
- Go to Settings > Security
- Scroll to Danger Zone
- Click Delete Account
- Enter your password
- Type "DELETE" to confirm
- Click Permanently Delete Account
What Gets Deleted
- All interactions and transcriptions
- All contacts
- All tasks
- All tags
- Account settings
- Subscription information
- All personal data
What Happens Next
- Immediate logout
- Data deletion begins
- Process completes within 30 days
- Confirmation email sent
- Deletion is irreversible
Before Deleting
- Export your data - Download anything you want to keep
- Cancel subscription - Avoid future charges
- Disconnect integrations - Clean up external connections
- Inform contacts - If using shared features
Security Best Practices
Account Security Checklist
- [ ] Use a strong, unique password
- [ ] Enable two-factor authentication
- [ ] Save backup codes securely
- [ ] Review active sessions regularly
- [ ] Connect a social account as backup
- [ ] Keep contact email current
Regular Security Reviews
Monthly:
- Check active sessions
- Review connected accounts
- Verify notification settings
Quarterly:
- Change password (optional but recommended)
- Regenerate backup codes if needed
- Review API token usage
- Audit integration permissions
Responding to Security Concerns
If you suspect unauthorized access:
- Immediately change your password
- End all other sessions
- Review recent activity for suspicious actions
- Enable 2FA if not already enabled
- Contact support if you see unauthorized changes
- Review connected accounts for unauthorized additions
Reporting Security Issues
If you discover a security vulnerability:
- Email security@blablanote.app
- Do not publicly disclose
- Include detailed description
- We'll respond within 24 hours
