Your account holds your work, your credits and a payment method. Two settings protect it properly, and both take a couple of minutes.
Turn on two-step sign-in
The single most effective thing you can do.
With it on, signing in needs your password and a short code from an app on your phone. Someone who has your password still cannot get in, which matters because the usual way accounts are lost is a password reused somewhere that was later breached — not anything that happened here.
Turn it on in your security settings, and keep any recovery codes you are given somewhere other than the phone that generates the codes. A recovery code stored only on the lost phone is not a recovery code.
A recovery code is long — around 39 characters of letters, numbers and hyphens, not the six digits the app asks for day to day. Capital or lower case does not matter. Enter one in the same box that normally takes the six-digit code, either to sign in without your phone or to switch two-step off once you are back in. If the box seems to reject it, check you have pasted the whole thing: it is much longer than the field looks.
Your password
If you sign in with an email address and password:
- Do not reuse a password from anywhere else. Reuse is how most accounts are taken.
- Long beats complicated. Four unrelated words are stronger and easier to remember than one word with symbols in it.
- Use a password manager if you can. Your browser has one built in.
Change your password from the security settings. You need the current one, which is why someone who wanders up to an unlocked computer cannot simply change it.
If you signed up through Google, there is no password on the account. That is fine — the security of the account is the security of your Google account, so put two-step sign-in on that instead.
Active sessions
Your security settings list where you are signed in.
Look at it occasionally. If something is there you do not recognise — a place you have never been, a device you do not own — sign it out and change your password immediately.
Sign out of devices you no longer have. A phone sold with a session still on it is a real risk and an easy one to remove.
Recent activity
Alongside sessions is a record of security-relevant events: sign-ins, password changes, and similar.
It is worth a look after anything odd. Unfamiliar entries are the earliest signal you get.
If you think someone else is in your account
In this order:
- Change your password. This ends the immediate problem.
- Sign out all other sessions.
- Turn on two-step sign-in, if it was not already on.
- Check your email address in settings is still yours — changing it is a common next move for whoever took the account.
- Check payment methods and credit history for anything you did not do.
- Contact support, from the email address on the account if you still can.
Things we will never do
Worth knowing so you can recognise the opposite:
- We will never ask for your password. Not by email, not in a support ticket, not on a call.
- We will never ask for card details in a message. Payment details are entered in the app, on the payment screen, and nowhere else.
- We will never ask you to move a conversation to another platform to resolve an account problem.
Anything doing those things is not us, no matter what it looks like. If you are unsure, ignore the message and start a fresh support ticket from inside the app — a ticket you started is one you know reached the right place.
Signing out
Sign out from the account menu. On a shared or public computer, do it every time — closing the tab is not the same thing.