TotalApp Docs

Security & Privacy

Protect your account with two-factor authentication, manage active sessions, and control your privacy settings.

Overview

Settings — Security
Account
Appearance
Notifications
Security
Privacy
Integrations
Two-Factor Authentication
Authenticator app enabled
ON
Active Sessions
Chrome · Windows · Istanbul Current
Safari · iPhone · Istanbul

Two-Factor Authentication (2FA)

Two-factor authentication adds a second layer of protection to your account. Even if someone obtains your password, they cannot sign in without the second factor.

How to Enable 2FA

  1. Open TotalApp and click your profile avatar in the top-right corner.
  2. Navigate to Settings → Security.
  3. Locate the Two-Factor Authentication section and toggle it on.
  4. Choose your preferred method: Authenticator App (recommended) or SMS.
  5. Follow the on-screen steps to link your authenticator app (Google Authenticator, Authy, etc.) by scanning the QR code.
  6. Enter the 6-digit code displayed in your authenticator app to confirm and activate 2FA.
  7. Save your backup codes in a secure place — these let you recover access if you lose your device.
Recommended: Use an authenticator app rather than SMS. Authenticator apps are not vulnerable to SIM-swapping attacks and work without a mobile signal.

How to Disable 2FA

  1. Go to Settings → Security → Two-Factor Authentication.
  2. Toggle 2FA off.
  3. Confirm your identity by entering your current password.
Warning: Disabling 2FA reduces your account security. We strongly recommend keeping it enabled, especially if your account is connected to team workspaces or business data.

Password Management

A strong, unique password is your first line of defence. TotalApp enforces a minimum password complexity and never stores your password in plain text.

Changing Your Password

  1. Go to Settings → Security → Password.
  2. Enter your current password.
  3. Enter and confirm your new password (minimum 8 characters, mix of letters, numbers, and symbols recommended).
  4. Click Save Password.

Password Best Practices

  • Use a unique password not shared with any other service.
  • Use a password manager (Bitwarden, 1Password, etc.) to generate and store strong passwords.
  • Change your password immediately if you suspect it has been compromised.
  • Never share your password with anyone, including TotalApp support.

Active Sessions

TotalApp shows you every device and location where your account is currently signed in. You can review and revoke any session you do not recognise.

Reviewing Active Sessions

  1. Go to Settings → Security → Active Sessions.
  2. You will see a list of all active sessions including device type, browser, IP address, and approximate location.
  3. Click Sign Out next to any session you want to terminate.
  4. To sign out of all other devices at once, click Sign Out All Other Sessions.
Tip: If you see a session from an unfamiliar location, sign it out immediately and change your password.

Login Activity & Alerts

TotalApp can notify you whenever a new sign-in occurs on your account, so you are always informed of activity even when you are not using the app.

Enabling Login Alerts

  1. Go to Settings → Security → Login Notifications.
  2. Enable Email alerts on new sign-in.
  3. Optionally enable In-app notifications for sign-in activity.

Privacy Controls

TotalApp gives you control over what data is collected and how it is used.

Profile Visibility

Control who can see your profile, name, and activity. Set to Private, Team, or Public in Settings → Privacy.

Usage Analytics

Opt in or out of anonymous usage analytics that help us improve TotalApp. Found in Settings → Privacy → Data & Analytics.

Cookie Preferences

Manage essential, functional, and tracking cookies via the Cookie Preferences panel, accessible from the footer or Settings → Privacy.

Data Export

Download a copy of all your TotalApp data at any time from Settings → Privacy → Export My Data.

Trusted Devices

When you sign in with 2FA enabled, you can mark a device as Trusted. Trusted devices skip the 2FA prompt for 30 days, balancing security with convenience for devices only you use.

  • To trust a device, check "Trust this device for 30 days" during the 2FA step at sign-in.
  • To revoke a trusted device, go to Settings → Security → Trusted Devices and click Remove.

Security Recommendations

Recommendation Priority Where to set it
Enable Two-Factor Authentication High Settings → Security → 2FA
Use a strong, unique password High Settings → Security → Password
Enable login email alerts Medium Settings → Security → Login Notifications
Review active sessions regularly Medium Settings → Security → Active Sessions
Set profile visibility to Private or Team Medium Settings → Privacy
Opt out of tracking cookies if preferred Low Settings → Privacy → Cookies

Reporting a Security Issue

If you discover a vulnerability or suspect your account has been compromised, please contact us immediately:

  • Email: security@totalapp.ai
  • In-app: Help → Report a Security Issue

We investigate all reports within 24 hours. Do not disclose vulnerabilities publicly before we have had the opportunity to address them.

Related pages: Security FAQ  ·  Account Settings  ·  Account Deletion

Frequently Asked Questions

If I lose my phone, will I be locked out of my account because of 2FA?
No — as long as you saved your backup codes when you first enabled Two-Factor Authentication, you can use one of them to sign in from any device and then re-link a new authenticator app. If you did not save your backup codes and lose access to your authenticator device, contact security@totalapp.ai with your account details so our team can verify your identity and restore access.
What's the difference between "Trust this device" and staying signed in?
Staying signed in keeps your existing session active on that browser. "Trust this device for 30 days" is specific to 2FA — it tells TotalApp to skip the second-factor prompt on that device for the next 30 days, even if you sign out and back in again. It only applies to devices you personally use regularly; never enable it on a shared or public computer.
Will signing out a session in "Active Sessions" log that device out immediately?
Yes. Clicking "Sign Out" next to a session invalidates that device's session token right away — the next action taken on that device will require signing in again. Use "Sign Out All Other Sessions" if you want to keep only your current device active, for example after suspecting unauthorized access.
Does setting my profile visibility to "Private" hide my data from my own team's admins?
No. Profile visibility (Private, Team, or Public) controls what other end users can see about you across TotalApp — not what your tenant's administrators can access. TenantAdmins and SystemAdmins retain the access their role grants regardless of your personal privacy setting, since that data is necessary for account and workspace management.