Groundbase

Password

Change at Settings → Account & Billing → Change password. Requires your current password (so a stolen session can't lock you out).

If you forget your password, hit Forgot password on the login screen — we email you a one-time reset link valid for 1 hour.

Sessions

Every time you sign in on a new device, we create a session row server-side. The active sessions list at Settings → Account & Billing → Sessions shows device, browser, last activity, and a Revoke button for each one.

Revoking a session signs that device out immediately on next request.

Email verification

You can't sign in until your email is verified. The verification link in the welcome email expires after 24 hours; if it expires, request a new one from the sign-in screen.

Two-factor authentication (TOTP)

Turn on at Settings → Account & Billing → Security → Two-factor authentication → Enable. Walk through three steps:

  1. Scan the QR code with any authenticator app — Google Authenticator, 1Password, Authy, Microsoft Authenticator, Bitwarden, etc. (No QR-code scanner? Tap the otpauth:// URI on your phone, or paste the base32 secret into the app manually.)
  2. Enter the 6-digit code from your authenticator to confirm pairing.
  3. Save your 10 one-time recovery codes — they're displayed once. Each can be used exactly once to sign in if you lose the authenticator. Print them or paste them in your password manager.

After it's on, sign-in adds a second step asking for the current 6-digit code. Recovery codes work in place of the code if you ever get locked out (one-shot — they don't repeat).

To disable: same Security screen → Disable. Asks for either your current 6-digit code OR your account password — so if you've lost the authenticator AND your recovery codes, your account password is still a way out.

To rotate recovery codes (e.g. after using a few): Regenerate codes. Old codes stop working immediately; you get a fresh 10.

MFA is the same across web, desktop, and mobile — set up once, every app asks for the second factor on sign-in.

Data export

Anything we have, you can take. Settings → Backup & Export → Export all data produces a JSON file with every contact, company, deal, task, note, tag, SMS, email, call, and recording reference. Imports from this file are also supported — see Importing data.