# Security and privacy

> Sign-in options, two-factor authentication, who can see which calls, and how data is removed.

Source: https://app.activelens.ai/help/security-and-privacy

This article covers the controls you and your workspace admin have over
who gets in and who sees what.

## How people sign in

Three routes, and a workspace can use all of them at once:

- **Password**, with a **Forgot password** reset by email.
- **Email me a login code** — a one-time code sent to your address. Nothing to
  remember and nothing to leak.
- **Continue with Google**, for workspaces on Google accounts.

Admins can allow or disallow signing in with Google for the whole workspace on
the **Security & sign-in** page, and can require passwords to be changed after
a set number of days.

## Two-factor authentication

You can protect your account with an authenticator app (the six-digit code
kind). Set it up from your account settings; you will be asked for a code after
your password from then on.

Note that once an authenticator is enrolled, the **Email me a login code**
route no longer applies to your account — the authenticator becomes your second
factor.

## Roles

There are two roles inside a workspace:

- **Member** — records calls, works their own calls and tasks.
- **Admin** — everything a member can do, plus managing people and teams,
  connecting workspace-wide integrations, the plan, retention and security
  settings.

Admins can see all calls and tasks in their workspace. This is deliberate and
worth telling your team.

## Who can see which calls

By default, you see your own calls and nobody else's. An admin can widen that
for a particular person, on the **Users & teams** page, to:

- their own calls only,
- their team's calls,
- the calls of teams you pick,
- every call in the workspace.

Calls and tasks are set separately — someone can be given the whole
workspace's tasks without being given its calls.

Anything beyond that is per-call sharing, which the call's owner controls —
see [Share a call](/help/sharing-a-call).

## Removing access

- **Deactivating** a user stops them signing in straight away and ends any
  session they have open. Their calls and tasks stay in the workspace.
  Deactivation is reversible and frees the seat.
- **Deleting** a user removes their account.
- To have your own account removed, ask your workspace admin, or contact
  support at <support@activelens.ai>.

## Deleting data

- Deleting a call removes its transcript, summary, actions and audio. It cannot
  be undone.
- Admins can turn on **Data retention**, which automatically deletes calls and
  logs older than a period you choose. This is permanent, so the page asks you
  to confirm before it is switched on.

## The audit log

Admins have an **Audit log** showing who did what in the workspace — sign-ins,
changes to users and settings, and actions taken on calls.

## Recording responsibly

ActiveLens records conversations, and the law about that differs from place to
place. Telling people they are being recorded, and getting their agreement
where it is required, is the responsibility of whoever presses record. Your
phone system may also have its own recording rules and announcements — those
continue to apply.

## Related

- [Share a call](/help/sharing-a-call)
- [Plans and billing](/help/plans-and-billing)
