Account security

Passwords, two-factor authentication, sign-in methods, sessions and account deletion.

Sign-in methods

Email and password. Sign-ups are confirmed by email; the link must be clicked before the account is usable. Passwords are hashed by the authentication layer and never stored in readable form.

Google. Sign in with a Google account instead of a password.

Password reset. Request a reset from the sign-in page. A time-limited link is sent to the verified address on the account, and using it lets you set a new password.

Two-factor authentication

Two-factor authentication uses a time-based one-time code (TOTP) from an authenticator app. Enrol from your personal account settings:

  1. Choose to add a factor.
  2. Scan the QR code with your authenticator app.
  3. Enter the generated code to confirm enrolment.

From then on, sign-in requires the code as well as your password.

Enable it. A Geonimo workspace contains your competitive intelligence, your content strategy and your traffic data — an attractive target, and a password alone is a thin defence for it. Owners in particular should treat 2FA as mandatory: the owner role controls billing and membership.

Keep your recovery options with your other credentials. Losing an authenticator with no recovery path means contacting support and proving ownership.

Sessions

Sessions are managed with rotating refresh tokens and expire on inactivity. Signing out ends the session on that device.

If you suspect a session is compromised: change your password immediately, enrol 2FA if it is not already on, then review workspace members for anyone who should not be there.

Your profile

Personal account settings cover your name, email address and password. Changing your email requires confirming the new address.

Within a workspace you also have a profile — how you appear to teammates — separate from your personal account details.

Deleting your account

Account deletion is permanent. It removes your personal account and your access to workspaces.

Before deleting:

  • Transfer ownership of any workspace you own, or it is left without an owner.
  • Note that workspace data belongs to the workspace, not to you. Deleting your account does not delete the brand, its prompts or its history — a departing member's work stays with the team, which is usually the intent.

Deleting a workspace

Deleting a workspace removes it, its projects, and the derived data hanging off them. Cancel the subscription first if one is active, and export anything you want to keep — this is not reversible.

Good practice

  • A unique, generated password stored in a password manager
  • Two-factor on every account with an owner role
  • Invitations only to work addresses you can revoke
  • A membership review each quarter — contractors and departed colleagues are the most common stale access
  • No confidential information inside prompts; they are sent to third-party AI providers by design. See Security and privacy.