# Account settings: profile, password, 2FA and SSH keys

> Manage your Vimonto Deploy account: name, email, language, password, sign-in codes by email, notifications, SSH keys, API tokens, your data and deletion.

Your account is personal: it belongs to you, not to an organization. It holds your name, email address, language, password, two-step verification, notification settings, your own SSH keys and your API tokens. The same account gives you access to every organization you are a member of.

Open your account through the account menu at the top right (your initial and name) and choose **Account settings**. The account has seven pages in the left rail: **General**, **Security**, **Privacy**, **Notifications**, **SSH keys**, **API tokens** and **Legal**.

![The account settings with personal details, email address and language](https://ops.vimonto.com/docs-media/en/account.webp?v=161e760d "Account settings")

## Change your name and language

1. Open **Account settings** → **General**.
2. Change your **Name**. This is how your colleagues see you, for example in the members list and on tasks you start.
3. Choose a **Language**: English, Nederlands, Deutsch, Français or Italiano. It sets the language of the interface and of the emails we send you.
4. Click **Save changes**.

When you change the language, the page reloads in the new language.

## Change your email address

Your email address is never changed directly. We first check that you can receive email at the new address:

1. Open **Account settings** → **General**.
2. Enter the new **Email address** and click **Save changes**.
3. We email a 6-digit code to the new address, and a notice about the change to your current address.
4. Enter the code under **Confirmation code** and click **Confirm email address**.

Until you enter the code, your account keeps using your current address. A banner on the **General** page shows the pending change, with buttons to **Enter code**, **Send a new code** or **Cancel change**.

- A code is valid for 10 minutes.
- You can request a new code once a minute.
- The new address can't already be in use by another account.

After the change, you sign in with the new address. Invitations sent to your old address can no longer be accepted by your account, because an invitation only works for the address it was sent to.

## Change your password

1. Open **Account settings** → **Security**.
2. Enter a **New password** and repeat it under **Confirm new password**.
3. Click **Change password**.

You stay signed in in the browser tab where you changed it. Choose a long password you don't use anywhere else.

If you forgot your password, click **Forgot your password?** on the sign-in page to get a reset link by email.

## Turn on two-step verification

Two-step verification with **email verification codes** adds a second step to signing in: after your password, you enter a code we email you. Someone who knows your password can then still not sign in without access to your inbox.

To turn it on:

1. Open **Account settings** → **Security**.
2. Under **Two-step verification**, click **Set up**.
3. We email you a code. Enter it under **Verification code** and click **Enable**.

From then on, every time you sign in, you enter your password and then the code from the email, and click **Confirm and sign in**. Codes are valid for 10 minutes; click **Resend code** if one doesn't arrive.

To turn it off, click **Disable** under **Two-step verification**, enter the code we email you and confirm with **Disable**. Signing in then only needs your password again.

## Add your personal SSH keys

Your personal SSH keys are public keys of the computers you use. You can put them on servers so you can log in over SSH from your own computer.

1. Open **Account settings** → **SSH keys**.
2. Under **Add key**, enter a **Name**, for example "Sam's laptop".
3. Paste the contents of your public key under **Public key**, for example the contents of `~/.ssh/id_ed25519.pub`.
4. Click **Add key**.

No key yet? Create one on your computer with:

```bash
ssh-keygen -t ed25519
```

Paste the public key (the file ending in `.pub`), never the private key.

![The personal SSH keys page with a form to add a key and the list of keys](https://ops.vimonto.com/docs-media/en/account-ssh-keys.webp?v=161e760d "Your personal SSH keys")

### Where are personal keys used?

- When you [create a server](https://ops.vimonto.com/docs/servers/create-a-server), you can select your keys under **Your SSH keys**. They are added to the new server.
- On an existing server, open **SSH keys** in the server's sidebar, click **Add key** and pick one of your keys instead of pasting it again.

Personal keys are yours only: other members don't see them and they are not added to servers automatically. Keys that the whole team needs on every new server belong in the organization's [SSH keys](https://ops.vimonto.com/docs/connections/ssh-keys).

Deleting a personal key only removes it from your account: it is no longer offered for new servers. Servers that already have the key keep it until you remove it on the server's **SSH keys** page.

## Choose your notifications

Under **Account settings** → **Notifications** you choose what Vimonto Deploy tells you about (failed deploys, monitor alerts, servers that are ready and more) and whether it reaches you by **Email**, **In-app** in the bell at the top of every page, or both. You can also mute servers. These settings are personal and apply to every organization you are in. See [notifications](https://ops.vimonto.com/docs/more/notifications).

## Create API tokens

Under **Account settings** → **API tokens** you make tokens for scripts and CI pipelines that use the Vimonto Deploy API, for example to deploy from GitHub Actions. A token can do what you can do, limited to the scopes you give it, and it is shown only once. See [the API](https://ops.vimonto.com/docs/more/api).

Under **Command line** on the same page you find the command that downloads the [Vimonto Deploy CLI](https://ops.vimonto.com/docs/more/cli) and installs it, with **Copy**, and the **Download the CLI** link.

## Choose a light or dark theme

Open the account menu at the top right. The theme switch has three options: **Light**, **Dark** and **System**, which follows the setting of your operating system. The choice is saved in your browser.

## See which legal documents you accepted

The [legal documents](/legal) of Vimonto Deploy each have a version. The agreements (the terms of service, the data processing agreement, the acceptable use policy, the refund and cancellation policy and the data export and switching policy) are what you accept. The notices (the privacy policy, the cookie policy, the subprocessors, the consumer withdrawal information and the company information) are there to read: there is nothing to accept, and **Legal** marks them **Notice**. You accept the agreements by creating your account, as the sign-up form says under **Create account**. The documents are in English only, and Vimonto Deploy is a product of Vimonto: the documents are an agreement between you and Vimonto.

When a document gets a new version, the next page you open shows **We updated our legal documents**, with each changed document, its new version and what changed. Open a document with **Read** to see it in full, then choose **Accept and continue**. Until you accept, the dialog stays in front of every page; **Sign out** is the way out without accepting. An account that never accepted the documents, for example one an administrator created for you, sees **Please accept our legal documents** the first time it signs in.

**Account settings** → **Legal** shows each document with its current version and whether you accepted it, with the date. **History** lists every version you accepted, newest first, with the date and the IP address it was accepted from. Older acceptances are kept when you accept a new version.

## Download your data

You can download everything Vimonto Deploy keeps about you as one JSON file, for example to keep a copy or to take your data elsewhere.

![The privacy page with the data download and the account deletion](https://ops.vimonto.com/docs-media/en/account-privacy.webp?v=161e760d "Download your data or delete your account")

1. Open **Account settings** → **Privacy**.
2. Under **Download your data**, click **Download my data**.

The file is called `vimonto-deploy-data-` followed by the date, and contains:

- your profile: name, email address, language, when you signed up and verified your address, when you last signed in, and whether email verification codes are on;
- your organizations, with your role and when you joined;
- your personal SSH keys (name, fingerprint and public key);
- your API tokens: name, permissions, last use and expiry;
- the invitations you sent and the ones sent to your address;
- your entries in the audit logs of your organizations, with IP address and browser;
- the terminal sessions you opened, the tasks you started and the deployments you triggered;
- your notifications and your notification settings;
- the versions of the legal documents you accepted, with the date, IP address and browser.

Passwords, tokens, private keys and server credentials are never included.

## Delete your account

Deleting your account removes it and your personal data for good.

1. Open **Account settings** → **Privacy**.
2. Under **Delete account**, check **Your organizations**: it shows what happens to each of them.
3. Enter **Your password**. An account without a password (one an administrator created) clicks **Email me a code** and enters the **Verification code** from the email instead.
4. Click **Delete account**.
5. Type your email address to confirm and click **Delete account**.

You are signed out right away, and we email a confirmation to your address.

After five wrong passwords or codes you have to wait a minute before you can try again.

> [!WARNING]
> Your account can't be restored. Download your data first if you want to keep a copy.

### What happens to your organizations?

- An organization you're the only member of is deleted with your account. It shows **Deleted with your account**, with its number of servers. Its servers at a cloud provider are deleted there first, just like when you [delete an organization](https://ops.vimonto.com/docs/organization/organizations#delete-an-organization). In the confirmation you can switch off **Also delete its servers at their providers** to keep them running. If deleting them at the providers takes a while, your account stays until that has finished: then delete your account again.
- An organization you're the only owner of while others are still members stops the deletion. Under **You can't delete your account yet**, each one has a link to its **Members** page: make someone else an owner there first, or remove the other members.
- From every other organization you simply leave (**You leave it**).

### What is kept, and what is removed?

Removed with your account: your profile and password, your sessions on every device, your API tokens, your personal SSH keys, your notifications, your memberships and any pending email address change.

Kept, without your name: the tasks you started, the deployments you triggered, the terminal sessions you opened and the invitations you sent. Your entries in the audit logs stay as well, so organizations can still see what happened on their servers; they then show **Deleted user** instead of your name. The IP address and browser stored with those entries are removed with the entry after 365 days. Organization SSH keys you added stay in the organization, because the team uses them on its servers.

## Frequently asked questions

### Is my account linked to one organization?

No. One account can be a member of many organizations, with a different role in each. Switch between them with the organization menu at the top left. See [organizations](https://ops.vimonto.com/docs/organization/organizations).

### I didn't receive the email code. What can I do?

Check your spam folder, then use **Send a new code** or **Resend code**. You can request a new code once a minute, and each code is valid for 10 minutes.

### Does Vimonto Deploy support authenticator apps?

Two-step verification works with codes sent by email.

### Why do I see a different language than my colleague?

The language is a personal setting. Each person chooses their own under **Account settings** → **General**, and emails follow that choice too.
