> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.mythos.new/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mythos.new/_mcp/server.

# Privacy and security settings

> Protect your account and manage access within your workspace.

Personal two-factor authentication is available on every plan. Workspace policy controls
are included in **Business** and are managed by a workspace owner or administrator.

## Two-factor authentication

Open **Account → Security** and choose **Enable**. Add the setup code to an authenticator
app and enter its current six-digit code to verify the device. Future sign-ins ask for a
code before opening private product areas.

Add and verify a backup authenticator on another device before replacing the first one.
You can choose a verified backup on the sign-in verification screen. Removing a factor
requires a fresh verification. Administrative accounts must keep a verified factor.

Mythos does not currently issue recovery codes. If you lose all verified authenticators,
contact [support](/reference/support-policy) so the account-access issue can be reviewed.

## Workspace privacy and security

Open **Settings → Privacy & security** for the workspace you want to manage.

| Control                        | Effect                                                                                                                                             |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| Default project access         | Choose workspace access or Restricted access for new projects. Existing projects keep their current access.                                        |
| Restrict workspace invitations | Limit new workspace email invitations to owners and administrators. Previously sent email invitations remain valid.                                |
| Invite links                   | Allow or block creating, renewing and joining through workspace invite links. A completed join is not undone.                                      |
| Publishing access              | Allow project editors to publish, or require a workspace owner or administrator. An already admitted publish can finish.                           |
| Share Preview links            | Allow or block new shared-preview access. Private workspace preview and already published websites remain available to their authorized audiences. |

Choose **Save** to apply the selected rules. If another administrator saves first,
reload the current settings before trying again. Members without management permission can
view the settings but cannot change them.

A saved restriction remains enforced if the workspace later loses Business access. Managing
these paid controls requires an active Business plan. A new Restricted team project also
requires Business; a personal project can remain private on Free.

Turning Share Preview off stops new shared-preview access. A signed artifact link already
issued can remain usable for up to five minutes. Anyone who has a valid share link can view
the preview while sharing is permitted, so only send links to the intended audience.

These controls do not make an already public website private. Manage a published site's
availability through its publishing controls.

## Profile activity

Your contribution graph covers the last 365 UTC calendar days and counts successfully
delivered edit Builds. It does not count a failed Build, an ordinary message or a new-project
Build as an edit contribution. The graph can be scrolled horizontally on a narrow screen.

Activity counters survive the separate 90-day generation-log lifecycle. Older dates whose
history was already unavailable are marked as unavailable. Counts and summaries for an
incomplete period are known minimums.

## Your data

**Account → Export data** prepares a portable JSON archive. Every included category must
complete successfully before a download is offered. A failed or oversized request is
reported as an error. Authenticator secrets, OAuth credentials and other secrets are excluded.

**Account → Delete account** starts account closure and removal of associated projects
and stored data. It is a deliberate account action; inactivity alone does not start it.
For data rights or information outside the automated export, contact
[privacy@mythos.new](mailto:privacy@mythos.new).

See the [Privacy Policy](/legal/privacy) for retention and the
[Security page](/legal/security) to report a vulnerability.