> ## Documentation Index
> Fetch the complete documentation index at: https://docs.guito.pt/llms.txt
> Use this file to discover all available pages before exploring further.

# Account security

> Change your password, see and end sessions on your devices, and confirm your identity for sensitive actions.

The **Security** tab in preferences brings together what you need to keep your account safe: change your password, see which devices have an open session and end them, and confirm your identity before sensitive actions. Find it from the user menu, under `Preferences (/overview#preferences:security)`, in the **Security** tab.

## Change your password

<Steps>
  <Step title="Open Preferences -> Security">
    Click your avatar in the sidebar, go to **Preferences** and open the **Security** tab.
  </Step>

  <Step title="Choose a new password">
    Enter the new password. It must be at least 8 characters; guito rejects passwords that have appeared in known data breaches.
  </Step>

  <Step title="Confirm your identity">
    For security, you're asked to confirm who you are before saving. If you sign in with a password, enter your current password. If you sign in with Google, guito emails you a code to enter here.
  </Step>
</Steps>

<Note>
  If you created your account with Google and never set a password, you can set one here for the first time by confirming your identity with the emailed code. You'll then be able to sign in with either a password or Google.
</Note>

## See and end active sessions

On the same page, the **Active sessions** list shows the devices where your account has an open session. Each row shows the device type, when it was last seen, and the approximate location the session was started from. The device you're using right now is marked as **This device**.

<Steps>
  <Step title="Sign out a device">
    Click **Sign out** on the row for the device you want to disconnect and confirm.
  </Step>

  <Step title="Sign out other devices">
    To disconnect all the others at once without affecting your current device, use **Sign out other devices**.
  </Step>
</Steps>

<Note>
  Ending a session can take up to about 30 minutes to take effect on the affected device. If you suspect unauthorized access, change your password as well.
</Note>

## New-device access alert

When your account is accessed from a device guito doesn't yet recognize, you get an email letting you know, with the device type, the approximate location, the date, and the network area the access came from. If it was you, there's nothing to do. If you don't recognize the access, the email tells you how to react: open **Preferences -> Security**, sign out other devices, and change your password.

<Info>
  The alert is only sent for new devices, not on every sign-in. The first device you use after creating your account doesn't trigger an alert.
</Info>

## Confirm your identity for sensitive actions

Some actions ask you to confirm who you are before continuing, even with a session already open. This applies to changing your password and deleting your account. The confirmation uses your current password or, for Google sign-in, a code emailed to you. It's a safeguard against someone acting on your account if you leave a session open.

## FAQ

<AccordionGroup>
  <Accordion title="I forgot my password. What do I do?">
    On the sign-in page, use the password-recovery option to get a link by email. The **Security** tab is for changing your password when you're already signed in.
  </Accordion>

  <Accordion title="I sign in with Google. Do I need a password?">
    No. You can keep signing in with Google only. If you want, you can set a password in the **Security** tab by confirming your identity with the emailed code.
  </Accordion>

  <Accordion title="I ended a session but the other device still shows my data.">
    Revocation can take up to about 30 minutes to take effect. After that, the device is forced to sign in again.
  </Accordion>

  <Accordion title="I got a new-device alert and it wasn't me.">
    Open **Preferences -> Security**, use **Sign out other devices**, and change your password. Once the password changes, any unauthorized access can no longer get in.
  </Accordion>
</AccordionGroup>

## Related pages

<CardGroup cols={2}>
  <Card title="Security and privacy" icon="https://mintcdn.com/guito/Z2-mKthyIORVPFl5/icons/shield.svg?fit=max&auto=format&n=Z2-mKthyIORVPFl5&q=85&s=aa86e6b8d2ce3e22e3eb68020c3ca0b0" href="/en/concepts/security-and-privacy" width="24" height="24" data-path="icons/shield.svg">
    How guito protects your data and what control you have over it.
  </Card>

  <Card title="Your data" icon="https://mintcdn.com/guito/Z2-mKthyIORVPFl5/icons/database.svg?fit=max&auto=format&n=Z2-mKthyIORVPFl5&q=85&s=2a6e05eb19e91e523e66df55f10acd06" href="/en/account/your-data" width="24" height="24" data-path="icons/database.svg">
    Download invoices, delete your account, and contact support.
  </Card>
</CardGroup>
