Account and Security
Profile management, two-factor authentication, and session security.
Account settings
Your account settings are organized into three tabs, accessible from the user menu under Settings.
Profile
Manage your personal information:
- Avatar — Upload a profile picture with drag-and-drop. Images are cropped to a square before saving.
- Display name — Update the name shown across PaperAI.
- Email address — Change your login email. A confirmation link is sent to your current email before the change takes effect.
- Delete account — Permanently delete your account and all organizations you own. This action requires confirmation and cannot be undone.
Security
Protect your account with additional security measures:
Password management
- Change password — Enter your current password and choose a new one. You can optionally revoke all other active sessions when changing your password.
- Set password — If you signed up with Google OAuth and don't have a password yet, you can set one to enable email/password login.
Two-factor authentication (2FA)
Add a second layer of security with a TOTP authenticator app (such as Google Authenticator, Authy, or 1Password):
Enable 2FA
Navigate to Settings → Security and click Set up a new Factor. Scan the QR code with your authenticator app and enter the verification code to confirm.
Sign in with 2FA
After entering your email and password, you will be prompted for a code from your authenticator app.
Disable 2FA
Return to Settings → Security and click the disable button. You may need to verify with a code from your authenticator app.
Two-factor authentication is available for email/password accounts. If you sign in exclusively with Google OAuth, 2FA is managed by Google.
Connected accounts
Link or unlink social login providers:
- Google — Connect your Google account for one-click sign-in. You can disconnect it as long as you have another authentication method (password or another connected account).
Sessions
View and manage all active sessions:
- See every device and browser where you are signed in, including user agent and IP address.
- Your current session is clearly labeled.
- Revoke any session except your current one to sign out that device immediately.