# How Heropost protects your account

What protects your Heropost login and your social accounts today, what isn't available (two-step sign-in, a list of your devices), and what to do if you think someone else used your account.

Last checked: Oct 8, 2026 on the live app. Source: https://heropost.ai/docs/account/security/

## What protects your account

- **Your email is confirmed.** Email sign-ups confirm their address with a code or link before they can sign in.
- **Password rules.** Passwords need at least 7 characters, with a letter, a number and a special character, and no spaces. See [Reset or change your password](/docs/account/password/#password-rules).
- **Too many wrong passwords lock the account.** After 5 wrong tries, sign-in is locked for 15 minutes.
- **Reset links are short-lived.** A password reset link works for 2 hours and only once. The reset page doesn't reveal whether an email has a Heropost account.
- **Connecting Google or Facebook is checked.** The first time someone uses Google or Facebook with an email that already has a Heropost account, Heropost may email that address a "Confirm it's you" link, valid for 30 minutes, before connecting them.
- **Changing your email cuts other ways in.** A new email removes Google and Facebook sign-in from the account. See [Profile settings](/docs/account/profile/#change-your-email).
- **Payments.** From the Privacy Policy: "We will not store or collect your payment card details." Card payments go through the payment processor.

## Your social accounts

- **You sign in on the network's own page** to connect most networks, so Heropost never sees those passwords. Bluesky asks for a password and Telegram for a bot token instead: see [Bluesky](/docs/networks/bluesky/) and [Telegram](/docs/networks/telegram/).
- **Clients don't share passwords with you.** With [Invite Profile](/docs/social-accounts/invite-a-client/) they connect their own accounts to your workspace.
- **Teammates get their own login.** Invite them with a role instead of sharing your password, and remove them when they leave. See [Invite your team](/docs/team/invite-your-team/).
- **AI tools get their own link,** with the permissions you choose, and you can remove a link at any time. See [Safety: what an AI tool can and can't do](/docs/ai-tools/safety/).
- **To withdraw Heropost's access to a social account,** delete it in Heropost and remove Heropost in the network's own settings. See [Your data](/docs/account/your-data/#stop-heroposts-access-at-a-network).

## What isn't available

- **Two-step sign-in** (a code from an app or text message) for Heropost logins.
- **A list of the devices or browsers you're signed in on**, and a way to sign out of all of them at once.

What you can do instead:

- **Sign in with Google or Facebook, and turn on two-step verification there.** If you never set a Heropost password, signing in always goes through Google or Facebook, including their second step.
- **Protect your email account.** Anyone who can read your email can reset your Heropost password, so give your email two-step verification too.
- **Use a password you don't use anywhere else,** and don't share it.
- **Log out on shared computers,** and untick **Remember me** there. See [Sign in, stay signed in and sign out](/docs/account/sign-in/).

## If you think someone else used your account

1. Change your password: your name at the bottom of the left menu → **Profile settings** → **Change Password**. Can't sign in? Use **Forgot your password?** on **Log In**.
2. In each workspace, open **Team → Members**. Remove anyone you don't recognize, and **Revoke** unknown invitations on **Team → Invite**.
3. On Home, open **Connect your AI tools** and remove any connection you don't recognize. See [Links, permissions and activity](/docs/ai-tools/links-permissions-activity/).
4. Check your posts, drafts and **Billing** for anything you didn't do.
5. Tell us: email support@heropost.ai from your account's email address, or [contact support](/docs/troubleshooting/get-help/). The Terms ask you to "notify Heropost immediately upon becoming aware of any security breach or unauthorized account use."

## Emails that ask for your password

Heropost never asks for your password by email. Heropost's sign-in pages are on **login.heropost.io**, and the app is on **app.heropost.io**. If an email asks for your password or sends you to another address to sign in, don't use it: forward it to support@heropost.ai.

## Your data

The [Privacy Policy](https://heropost.ai/privacy/) explains what Heropost keeps and why. On data from your social accounts, it says: "We never sell platform data, never use it for advertising, and never share it with third parties except the service providers needed to operate the Service." To delete data or your account, see [Your data](/docs/account/your-data/).

## If it doesn't work

| What you see | What it means | What to do |
|---|---|---|
| "Invalid email or password." even with the right password | After 5 wrong tries, the account is locked for 15 minutes, and the message stays the same. | Wait 15 minutes, or reset your password. |
| "Account has been deactivated. To activate your account, contact your administrator." | The account was switched off. | [Contact support](/docs/troubleshooting/get-help/). |
| A password reset email you didn't ask for | Someone typed your email on the reset page. | Ignore it: nothing changes unless the link is used. If they keep coming, change your password and tell us. |

## Questions

**Does Heropost have two-factor authentication?**

Not for Heropost logins. If you sign in with Google or Facebook, their two-step verification protects that sign-in.


**Can I see where my account is signed in?**

No. Heropost doesn't show a list of devices. Log out on browsers you no longer use.


**Will Heropost ever ask for my password?**

No. Heropost never asks for your password by email. To get back into your account, use **Forgot your password?** on **Log In**.


**Can I limit what a teammate can do?**

Yes, with their role: Viewers can't create or change posts, and Editors' posts need approval. See [Roles and permissions](/docs/team/roles-and-permissions/).
