Account Settings

Manage your personal account settings, profile, and security preferences.

Profile Information

Update Your Name

  1. Navigate to Profile from the user menu
  2. In the Profile Information section, update your name
  3. Click Save

Update Your Email

  1. Go to Profile
  2. In the Profile Information section, enter your new email
  3. Click Save, then confirm it's you when asked
  4. Verify your new email address via the confirmation email

Note: Your old email will remain active until you verify the new one. Once you do, we send a notice to the old address, so a change you didn't make can't go unnoticed.

Profile Photo

Upload a profile photo to personalize your account:

  1. Go to Profile
  2. Click Select A New Photo
  3. Choose an image from your computer
  4. Click Save

Supported formats: JPG, PNG, GIF (max 2MB)

Security Settings

Confirm it's you

Before a change that adds a way into your account or your team's resources, or weakens how your account is protected, we ask you to confirm it's you, even if you're already signed in. That covers:

  • adding or removing a passkey, creating or editing an API token, and authorizing the CLI
  • turning two-factor authentication on or off, and viewing or regenerating your recovery codes
  • setting a password, and changing your email address
  • setting, changing or removing your support PIN
  • creating an S3 access key or widening what one reaches, creating a container registry key, an SFTP user or an SSH key
  • inviting a team member or changing a member's role
  • connecting the Storage Share mobile app, saving your team's webhook address or regenerating its secret, and rotating a database password
  • signing out a browser session, changing your session security settings, removing a linked Google or GitHub sign-in, and deleting your account

A session left signed in on a shared or lost device can't be used to add a way in.

Confirm with whichever of these your account has:

  • Your password
  • A passkey you've already added
  • A code from your authenticator app, if two-factor authentication is on
  • A 6-digit code we email you, if you sign in with Google or GitHub and haven't set a password

A confirmation lasts 15 minutes, so several changes in a row only ask once. After five wrong attempts, confirming is paused for 15 minutes.

Security emails

We email your account's address whenever a way into your account or your team's resources is added, widened or removed, so a change you didn't make can't go unnoticed: a passkey, an API token or the CLI, an S3 access key, a registry key, SFTP access, an SSH key, a team invitation, an app password for a Storage Share, a new webhook address or secret, a database password rotation, two-factor authentication turned on or off, new recovery codes, a password change, a linked Google or GitHub sign-in, and a change of email address (sent to the old address). Each email says when and from which IP address and browser it happened, and what to do if it wasn't you. You can't turn these emails off.

Change Password

Update your password regularly for security:

  1. Navigate to Profile
  2. Go to the Update Password section
  3. Enter your current password
  4. Enter your new password
  5. Confirm your new password
  6. Click Save

After five wrong current passwords, changing it is paused for 15 minutes. We email you whenever your password changes, and your other browser sessions are signed out.

Password Requirements:

  • Minimum 8 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one number
  • At least one special character recommended

Two-Factor Authentication (2FA)

Add an extra layer of security to your account:

Enable 2FA

  1. Go to Profile
  2. Find the Two Factor Authentication section
  3. Click Enable
  4. Scan the QR code with your authenticator app:
    • Google Authenticator
    • Authy
    • 1Password
    • LastPass Authenticator
  5. Enter the 6-digit code from your app
  6. Click Confirm
  7. Save your recovery codes in a safe place

We email you when two-factor authentication is turned on or off, and when new recovery codes are created.

Recovery Codes

Recovery codes let you access your account if you lose your phone:

  • Each code can be used once
  • Store them securely (password manager recommended)
  • Generate new codes if you use them all
  • Keep them offline for maximum security

Disable 2FA

  1. Go to Profile
  2. Find the Two Factor Authentication section
  3. Click Disable
  4. Confirm it's you

Passkeys

Passkeys (WebAuthn) let you sign in without a password, using your device's biometrics or a security key:

  1. Go to Profile
  2. Find the Passkeys section
  3. Give the passkey a recognizable name (e.g., "MacBook Touch ID", "YubiKey")
  4. Click Add Passkey, confirm it's you, and follow your browser or device prompt

You can register several passkeys and remove any you no longer use. We email you whenever a passkey is added or removed.

A passkey as the second step after your password

A passkey also works as the second step when you sign in with your password, or with Google or GitHub. If your account has a passkey and no authenticator app, a correct password is not enough: before you're signed in, we ask for one of your passkeys. Signing in with a passkey on its own needs no second step.

If your passkey is out of reach (a lost device, or a security key you left at home), choose Email me a code instead on that page. We send a 6-digit code to the email address on your account, and say in the email when and from where it was asked for. The code works once, in the browser that asked for it, for 10 minutes, and allows five tries. You can ask for another after a minute, and we send an account up to ten an hour. After five wrong codes, the emailed code is paused for 15 minutes and we email you to say so. Your passkeys keep working.

An emailed code is weaker than a passkey or an authenticator app: anyone who can read your email can use it, and someone who tricks you into reading it out gets in. Never read it out to anyone: we will never ask for it. Keep your email account secure, and add an authenticator app as well. It is the only second step that also protects you when someone can read your email or talks you into reading out a code, and its recovery codes cover you when you lose the device that holds your passkey. If your account has an authenticator app, signing in asks for its code (or a recovery code) as before, and does not offer the emailed code.

If your account has neither two-factor authentication nor a passkey, the console shows a reminder to add one, and the Sign-in and security tab of your profile says so too. Choose Remind me in a week to hide the reminder for seven days; it comes back after that until you add a passkey or turn on two-factor authentication. A passkey needs no phone: it uses Touch ID, Windows Hello or a security key.

Connected Accounts (Google & GitHub)

Sign in with your Google or GitHub account instead of a password:

  • Use Sign in with Google or Sign in with GitHub on the login and registration pages
  • Signing in with a Google or GitHub account that uses your account's email address links it to your account. Google has to confirm it verified that address. We email you whenever a sign-in is linked
  • See your linked sign-ins under Profile > Sign-in and security > Google and GitHub, and remove any you no longer use. Removing one asks you to confirm it's you. You can't remove the only way you can sign in: set a password or add a passkey first
  • If an account link ever gets out of sync, it repairs itself automatically the next time you sign in

Browser Sessions

Manage active sessions across all your devices:

View Active Sessions

See where you're logged in:

  • Device type (Desktop, Mobile, Tablet)
  • IP address
  • Last active time
  • Current session marked

Log Out Other Sessions

If you suspect unauthorized access:

  1. Go to Profile
  2. Find the Browser Sessions section
  3. Click Log Out Other Browser Sessions
  4. Enter your password, or confirm it's you if your account has no password
  5. Click Log Out Other Browser Sessions

This logs you out from all other devices but keeps your current session active. To sign out a single device instead, click Sign out next to it and confirm it's you.

Session Security

Control how long you stay signed in when you step away:

  1. Go to Profile > Session Security
  2. Choose your idle timeout: 24 hours (the default) or 3 hours
  3. Pick the shorter 3-hour window on shared or less-trusted devices for tighter security

Saving a change asks you to confirm it's you. Your session clock resets with every action, so you're only signed out after genuine inactivity. Leave it on the default and your sessions behave exactly as before.

Customer number and support PIN

Every project has a customer number, such as DD-4827-1934. Your invoices show one too: the number of the project that pays them, which is the project itself unless it is billed through another organization. You also set a support PIN. When you contact us any way other than a console ticket, we ask for both before we change anything or share any account data.

Find your customer number

  • Profile > Sign-in and security > Your customer numbers lists the number of every project you belong to, each with a copy button.
  • Billing shows the number of the project you're working in, at the top of the page.
  • Project settings shows it under the project's owner.

Each project has its own number. Give us the one for the project your request is about.

Set a support PIN

  1. Go to Profile > Sign-in and security
  2. In the Support PIN section, enter a PIN of 8 to 12 digits, then enter it again
  3. Click Set PIN, then confirm it's you when asked

Pick a PIN you'll remember. We keep only a scrambled copy of it, so nobody can read it back to you, and we can't either. A PIN that is one digit repeated (00000000), a straight run of digits (12345678, 87654321) or a block of digits said again (12341234) is refused.

The PIN is yours, not a project's: it goes with the customer number of any project you belong to. To change it, enter a new one and click Change PIN. To remove it, click Remove PIN. We email you whenever your PIN is set, changed or removed, so a change you didn't make can't go unnoticed.

When we ask for them

  • You open a ticket from the console: we already know it's you, so we ask for nothing.
  • A script or an agent opens a ticket, or replies to one, with an API token: a token proves that someone holds a credential, not who is asking, so we treat it like an email. The ticket or reply is marked as sent with an API token, and we ask for your customer number, your support PIN and the email address of your account before we change anything or share any account data. See the Support Tickets API.
  • You write by email, phone or any other way: before we change anything or share any account data, we ask for your customer number, your support PIN and the email address of your account. If they don't match, we don't act on the request, and we ask you to open a ticket from the console instead.
  • You haven't set a PIN: we can't act on a request that comes by email, by phone or with an API token. Open a ticket from the console.

We email you when our support team confirms it's you with your PIN, and when repeated wrong PINs with your customer number lock verification for an hour, so a request that wasn't yours can't go unnoticed. Each check, and each one that failed, also appears in your project's Activity Log as an action by DanubeData Support, with the request it was made for.

We never ask for your password. If someone asks for it in our name, don't share it.

API Tokens

Manage API tokens for programmatic access:

Create an API Token

  1. Open Security from the account menu, then the API tokens tab
  2. Click Create token
  3. Enter a descriptive name (e.g., "CI/CD Pipeline", "Mobile App")
  4. Choose the token's project access:
    • This project only (default): the token can only touch resources in your current project
    • All your projects: account-wide access across every project you belong to
  5. Select permissions, grouped by resource:
    • Read: View resources
    • Write: Create, change and act on resources
    • Delete: Remove resources
    • Credentials and Diagnostics: read passwords, and read what resources print to their logs (see API Authentication)
  6. Click Create token, then confirm it's you when asked
  7. Copy your token immediately - it won't be shown again!

We email you whenever an API token is created, including the one the CLI gets when you authorize it.

New tokens default to This project only, and the list's Project column shows what each token reaches. A project-locked token is refused with a clear message if used against any other project. Existing tokens keep their account-wide access unless you recreate them.

Token Security

  • Treat tokens like passwords
  • Never commit tokens to version control
  • Use environment variables
  • Rotate tokens regularly
  • Delete unused tokens

Revoke a Token

  1. Open the token on Security, API tokens
  2. Click Delete
  3. Confirm deletion

The token becomes invalid immediately.

Notification Preferences

Choose which notifications you receive, and whether they arrive by email, in-app (the Notification Center), or both. Preferences save per category:

  • Account Activity: Password changes and profile updates
  • Security: New sign-in alerts and suspicious-activity alerts (see below)
  • Billing: Invoices, receipts, payment failures, budget alerts
  • Service Alerts: Maintenance and incidents
  • Marketing: Product updates, tips, newsletters

Update them:

  1. Go to Profile > Notification Preferences
  2. Toggle each category on or off, per channel
  3. Click Save

Sign-In Alerts

Get notified whenever your account signs in from a new device. Turn the email and in-app alerts on or off independently under Notification Preferences.

Suspicious Activity Alerts

If we block a burst of failed sign-in attempts on your account, we alert you by email and in-app. Each alert names the IP address the attempts came from and confirms your account was not accessed. Repeated attempts from the same source are grouped, so a sustained attack won't flood your inbox. Control these with the Suspicious Activity toggle in Notification Preferences.

Unsubscribe from Marketing

Click the unsubscribe link at the bottom of any marketing email.

Note: You'll still receive critical account and billing emails.

Privacy & Data

Data Export

Request a copy of your data:

  1. Contact support via the dashboard
  2. Request a data export
  3. Receive a download link within 48 hours

Exported data includes:

  • Account information
  • Resource configurations
  • Billing history
  • Support tickets

Account Deletion

Warning: This action is permanent and irreversible!

Before deleting your account:

  1. Delete all resources
  2. Download any needed data
  3. Export invoices for records

To delete your account:

  1. Go to Profile > Delete Account
  2. If anything still blocks deletion (for example, active resources or an unpaid balance), you'll see exactly what to resolve first
  3. Type your email address, then confirm it's you when asked

Once the checks pass, your account and data are removed. We may ask for brief feedback on why you're leaving.

Account Limits

View your current resource limits:

  1. Open Account limits in the console sidebar, or go to console.danubedata.ro/account-limits
  2. See your tier, the instance sizes you can choose, and your usage against each instance limit:
    • VPS Instances
    • Database Instances
    • Cache Instances
    • Serverless Containers
    • Storage Share (Nextcloud) Instances

Request Limit Increases

Need higher limits?

  1. Open Account limits in the console sidebar, or go to console.danubedata.ro/account-limits
  2. Click Request an increase
  3. Explain what you need the resources for (at least 50 characters)
  4. Raise the limits you need
  5. Click Send request

Requests are typically reviewed within 24-48 hours.

Billing Information

Manage billing separately for each project:

  • Payment methods
  • Billing address
  • Tax information
  • Invoices

See Billing & Payments for details.

Account Security Best Practices

Strong Authentication

  1. Use a strong, unique password
  2. Enable two-factor authentication
  3. Use a password manager
  4. Don't share your password

Session Management

  1. Log out from shared devices
  2. Review active sessions regularly
  3. Log out unused sessions
  4. Use secure networks

API Security

  1. Use API tokens instead of passwords
  2. Give minimum necessary permissions
  3. Rotate tokens regularly
  4. Monitor API usage
  5. Revoke suspicious tokens

Account Monitoring

  1. Review account activity regularly
  2. Check login notifications
  3. Monitor resource changes
  4. Review billing for unusual charges
  5. Keep contact email current

Troubleshooting

Can't Log In

Forgot password?

  1. Click Forgot Password on login page
  2. Enter your email
  3. Check your email for reset link
  4. Create a new password

Lost 2FA device?

  1. Click Use Recovery Code on 2FA page
  2. Enter one of your recovery codes
  3. Disable 2FA and re-enable with new device

Account locked?

  • Too many failed login attempts lock accounts for 15 minutes
  • Contact support if you need immediate access

Email Not Received

Check:

  1. Spam/junk folder
  2. Email filters
  3. Email address is correct
  4. Wait a few minutes (delays can happen)

Still nothing? Contact support.

Can't Enable 2FA

  1. Ensure your device clock is synchronized
  2. Try a different authenticator app
  3. Clear browser cache
  4. Try a different browser
  5. Contact support if issues persist

Support

Need help with your account?

  • Support tickets: Through the dashboard — the fastest route
  • Email: support@danubedata.ro. We'll ask for your customer number and support PIN before we change anything or share account data.

Next Steps