Ringhum.

Account & security

Security, privacy and your data

How to protect your login with two-factor authentication, see and end your sessions, control who can hear recordings, set how long transcripts and audio are kept, and export or delete your data.

5 min read Updated 24 September 2026

On this page

Your calls contain your customers' names, numbers and conversations, so it matters who can see them and how long they are kept. This article covers the controls you have: protecting your login, deciding who in your team sees what, choosing how long transcripts and recordings are stored, and exporting or deleting your data.

Turn on two-factor authentication

Two-factor authentication adds a second step at login: after your password, you enter a 6-digit code from an authenticator app on your phone. We recommend it for owners and admins.

  1. Open Settings and select the Security tab.
  2. Under Two-factor authentication, press Set up two-factor.
  3. Open an authenticator app such as Google Authenticator, 1Password or Authy.
  4. Scan the QR code, or enter the key shown.
  5. Enter the 6-digit code from the app and press Confirm and enable.
  6. Save the Recovery codes somewhere safe.

Each recovery code works once, if you lose your phone. You can create New recovery codes at any time; the old ones then stop working. To switch two-factor off, press Turn off and confirm with your password.

Two-factor also applies when you sign in with a social login. You get an email whenever two-factor is switched on or off, or new recovery codes are made.

Your password and sign-ins

  • Change your password under Settings → Security → Password. It needs at least 8 characters, with letters and numbers. You get an email when it changes.
  • Changing your email under Settings → Profile takes effect only after you open the confirmation link sent to the new address.
  • After several wrong passwords in a row, sign-in is paused briefly.

Tip: We email you when your account signs in from a browser or device it has not used before. If you do not recognise it, change your password and sign out everywhere else.

See and end sessions

Under Settings → Security:

  • Signed-in devices lists the browsers your account has signed in from, with when each was last used. Forget removes one from the list, so signing in from it alerts you again.
  • Sign out everywhere else ends every other session and keeps only the browser you are using. Confirm with your password.
  • Browser sessions → Sign out other sessions does the same for other devices where you are logged in.

Who can see calls and recordings

Access follows the roles in your workspace. Everyone in the workspace, including viewers, can see calls, transcripts and recordings. Only owners and admins can delete calls, manage phone numbers, create API keys and connect integrations. Give people the lowest role they need. See Invite your team and set roles.

Owners and admins can see Recent activity on the Members page: changes to members, assistants, numbers and API keys, and who made them.

Call recording

Recording is off for a new assistant. You switch it on per assistant under Assistants → Edit → Call settings → Recording, with Record calls. Tell callers the call is recorded is on by default and says so at the start of the greeting, in the caller's language. Many places require it. See Recording and consent.

How long data is kept

By default transcripts and recordings are kept for as long as the workspace exists. On the Scale plan, owners and admins can set a limit:

  1. Open Settings and select the Workspace tab.
  2. Under Keep transcripts and recordings for, choose 1 year, 6 months, 90 days, 30 days, 7 days, or Zero retention — never store transcripts or audio.
  3. Press Save workspace.

Older transcripts, recordings and voicemails are deleted every night. Call summaries and outcomes are kept. With zero retention, the transcript and audio are deleted as soon as the call summary is written.

Delete data

What Where Who
A single call and its transcript Open the call, Delete call Owners and admins
A contact Open the contact, Delete contact (calls and appointments are kept) Anyone who can manage contacts
An assistant with its calls, transcripts and recordings Assistants, row menu, Delete Owners and admins
A whole workspace Settings → Workspace → Delete workspace, typing its name to confirm The owner
Your account Settings → Profile → Delete account, with your password You

Deleting a workspace permanently removes all its assistants, numbers, calls and members. Its phone numbers go back to the phone company, live calls end and its subscription stops. Every member gets an email.

Deleting your account schedules it for deletion in 30 days. Subscriptions stop renewing straight away, and phone numbers are released at their next renewal and cannot be recovered. Signing in again within the 30 days cancels the deletion. If you own a workspace with other members, transfer ownership first.

Export your data

  • Download my data (Settings → Profile → Your data): everything we store about you as a person, as a JSON file.
  • Export workspace data (Settings → Workspace → Export workspace): members, assistants, numbers, webhooks and every call with its transcript, as one JSON file. Only the owner can export.
  • Single calls: download the transcript (text or JSON) or the recording from the call page.
  • Lists: calls, contacts, appointments, orders, reservations, inbox items and members can be exported as CSV from their pages.

How we handle sensitive details

  • API keys are shown once when you create them and stored only as a fingerprint, so nobody can read them back. See API keys and scopes.
  • The login details you enter for connected apps are stored encrypted.
  • The account number and PIN you enter to move a number to us are stored encrypted.
  • Documents for phone numbers and number moves go straight to the phone company for review. We do not keep them.

If we ever ask you to verify your identity, the photos of your ID are deleted 30 days after our decision.

For the full details, read the Privacy policy and the Data processing agreement at /legal/privacy and /legal/dpa.

Still stuck?

Email [email protected] or send us a message. Team and Scale plans get priority support.

Contact support