Privacy and security settings

View as Markdown

Personal two-factor authentication is available on every plan. Workspace policy controls are included in Business and are managed by a workspace owner or administrator.

Two-factor authentication

Open Account → Security and choose Enable. Add the setup code to an authenticator app and enter its current six-digit code to verify the device. Future sign-ins ask for a code before opening private product areas.

Add and verify a backup authenticator on another device before replacing the first one. You can choose a verified backup on the sign-in verification screen. Removing a factor requires a fresh verification. Administrative accounts must keep a verified factor.

Mythos does not currently issue recovery codes. If you lose all verified authenticators, contact support so the account-access issue can be reviewed.

Workspace privacy and security

Open Settings → Privacy & security for the workspace you want to manage.

ControlEffect
Default project accessChoose workspace access or Restricted access for new projects. Existing projects keep their current access.
Restrict workspace invitationsLimit new workspace email invitations to owners and administrators. Previously sent email invitations remain valid.
Invite linksAllow or block creating, renewing and joining through workspace invite links. A completed join is not undone.
Publishing accessAllow project editors to publish, or require a workspace owner or administrator. An already admitted publish can finish.
Share Preview linksAllow or block new shared-preview access. Private workspace preview and already published websites remain available to their authorized audiences.

Choose Save to apply the selected rules. If another administrator saves first, reload the current settings before trying again. Members without management permission can view the settings but cannot change them.

A saved restriction remains enforced if the workspace later loses Business access. Managing these paid controls requires an active Business plan. A new Restricted team project also requires Business; a personal project can remain private on Free.

Turning Share Preview off stops new shared-preview access. A signed artifact link already issued can remain usable for up to five minutes. Anyone who has a valid share link can view the preview while sharing is permitted, so only send links to the intended audience.

These controls do not make an already public website private. Manage a published site’s availability through its publishing controls.

Profile activity

Your contribution graph covers the last 365 UTC calendar days and counts successfully delivered edit Builds. It does not count a failed Build, an ordinary message or a new-project Build as an edit contribution. The graph can be scrolled horizontally on a narrow screen.

Activity counters survive the separate 90-day generation-log lifecycle. Older dates whose history was already unavailable are marked as unavailable. Counts and summaries for an incomplete period are known minimums.

Your data

Account → Export data prepares a portable JSON archive. Every included category must complete successfully before a download is offered. A failed or oversized request is reported as an error. Authenticator secrets, OAuth credentials and other secrets are excluded.

Account → Delete account starts account closure and removal of associated projects and stored data. It is a deliberate account action; inactivity alone does not start it. For data rights or information outside the automated export, contact privacy@mythos.new.

See the Privacy Policy for retention and the Security page to report a vulnerability.