Account settings
Account Settings
Section titled “Account Settings”Manage your personal profile, security settings, two-factor authentication, personal plan, privacy/data requests, and API access tokens in Account Settings.
Profile
Section titled “Profile”Basic information
Section titled “Basic information”-
Go to My Account → Profile
-
Edit:
- First name and Last name
- Email — primary contact email
- Phone — optional
- Job title — your role
- Profile picture — avatar
-
Click Save changes
Address and location
Section titled “Address and location”-
In Address, fill in:
- Street address
- City
- ZIP code
- Country
-
Save
This information is used for billing and communication.
Security
Section titled “Security”Password
Section titled “Password”-
Go to My Account → Security
-
In Password, click Change password
-
Fill in:
- Old password
- New password — minimum 8 characters
- Confirm new password
-
Click Update password
Two-factor authentication (2FA)
Section titled “Two-factor authentication (2FA)”Add an extra security layer.
Two-factor authentication is managed by Keycloak, Sencai’s identity provider — not by a custom application flow. When you activate or deactivate TOTP, you’re taken through Keycloak’s own account-console screens, so the exact wording and steps may differ slightly from a native Sencai form.
Activate TOTP
Section titled “Activate TOTP”- In Two-Factor Authentication, click Activate
- You’re redirected to the Keycloak account console TOTP setup page
- Use an authenticator app (Google Authenticator, Authy, Microsoft Authenticator)
- Scan the QR code
- Enter the 6-digit code from the app
- Confirm — Keycloak generates your recovery (backup) codes at this step
You’ll now need the 2FA code when signing in.
Save your recovery codes. Keycloak issues them once during setup — you’ll need them if you lose access to your authenticator app.
Deactivate 2FA
Section titled “Deactivate 2FA”- In Two-Factor Authentication, click Deactivate
- You’re redirected to Keycloak to confirm removal of the TOTP credential
- Enter the 6-digit code from your authenticator app
- Confirm deactivation
Sessions (Sign-ins)
Section titled “Sessions (Sign-ins)”View all your active sign-ins:
-
In Active Sessions, see your sign-in list
-
Each session shows:
- Device — device type and browser
- IP address — where you signed in from
- Location — approximate location
- Last activity — when you were last active
-
Click a session for more details
-
Click Sign Out to sign out from that device
Notifications
Section titled “Notifications”Email notifications
Section titled “Email notifications”Choose which emails you want to receive:
-
Go to My Account → Notifications
-
Toggle:
- Security alerts — new sign-in, password changes
- News and updates — new features
- Billing alerts — high cost warnings
- Team invitations — when invited to an organization
-
Save settings
My Plan
Section titled “My Plan”Your User Plan is a personal subscription tier, completely independent from any Organisation’s billing. It controls things like how many organisations you can own for free and whether personal AI features are enabled — it has no effect on, and is not affected by, the plan of any organisation you belong to.
Plan tiers
Section titled “Plan tiers”- Go to My Account → My Plan
- See your current tier and its limits:
- Free — default tier, limited organisations owned and free members per org
- Plus — higher organisation/member limits
- AI — adds personal AI features
- Unlimited — no organisation/member caps, priority support
Upgrading your plan
Section titled “Upgrading your plan”- In My Plan, click Upgrade
- Choose the tier you want
- You’re redirected to a Stripe Checkout session for payment
- On success, your plan updates automatically once Stripe confirms the subscription
Sponsorship
Section titled “Sponsorship”A paying user (on a paid tier) can sponsor another user’s plan — the sponsor pays, and the beneficiary gets the sponsored tier’s features without needing their own payment method.
- To sponsor someone, go to My Plan → Sponsorship → Invite
- Enter the beneficiary’s email and choose the tier to sponsor
- The beneficiary receives an invitation link; once they accept, the subscription item is added to the sponsor’s existing billing and the beneficiary’s plan becomes active
Integrations and API tokens
Section titled “Integrations and API tokens”Generating an API token
Section titled “Generating an API token”To access Sencai API:
-
Go to My Account → API tokens
-
Click New Token
-
Fill in:
- Name — token description (e.g., “CI/CD pipeline”)
- Scope — what the token can do (read, write, admin)
- Expires in — when it should expire (optional)
-
Click Create Token
The token appears once. Copy it to a safe place.
Managing tokens
Section titled “Managing tokens”- Regenerate — Creates a new token, old one stops working
- Delete — Immediately revoke the token
Never share your API token. It’s like a password.
Privacy & Data
Section titled “Privacy & Data”Request data export
Section titled “Request data export”You can request a full export of your personal data at any time, in line with GDPR data portability rights.
- Go to My Account → Privacy
- Click Request data export
- Confirm the request
Your export is prepared as an archive and delivered to your registered email address once it’s ready. You can check the status of a pending request from the same Privacy screen.
RoPA register (organizations)
Section titled “RoPA register (organizations)”For organizations, My Account → Privacy also provides access to the RoPA (Record of Processing Activities) register — the compliance record of what personal data is processed, why, and how, used as evidence for regulatory frameworks like NIS2.
- Go to My Account → Privacy → RoPA register
- Review the recorded processing activities for your organization
- Click Export CSV to download the register for audits or compliance reporting
Delete account
Section titled “Delete account”To delete your account:
- Go to My Account → Delete Account
- Read the warning
- Click Delete Account
- Confirm with your password
Your account and all associated data will be permanently deleted. This action cannot be undone.