Account settings
Account settings apply to you, in every workspace you belong to. Company letterhead, billing, and who is on the team live under Workspace settings.
Account settings → Profile
desktop
When this area is the right place
Use Account settings to change how you appear, get notified, sign in, and export your data.
Use Workspace settings for logo, sales tax, users, roles, Xero, and subscription.
Section map
Open Account settings from the user menu. Sections use ?section= in the URL so you can bookmark one.
| Section | What it is for |
|---|---|
| Profile | Name, avatar, how teammates see you |
| Layout | Density and layout preferences for the app shell |
| Security | Password, Two-factor authentication, Active Sessions |
| Notifications | In-app, email, and push by category |
| Calendar sync | ICS export / webcal:// feed for external calendars. Not two-way Google or Outlook. |
| Privacy | Optional analytics, download your account data |
| API keys | Personal keys that act as you (if enabled) |
| Archived | Workspaces or memberships you have left, where shown |
| Danger zone | Leave or delete your account (workspace deletion is a different, admin action) |
Profile and notifications show a Save bar. Save before you leave those tabs.
Profile and layout
Name and avatar follow you into every workspace. Layout preferences are personal; they do not change how the rest of the team sees the app.
Notifications
Turn categories on or off for in-app, email, and push. Invites and items waiting on you still appear in-app even if you quiet email.
On a phone, the app may prompt you to enable push. You can also manage push here.
Security
- Two-factor authentication: Enable two-factor authentication, scan the QR, enter the 6-digit code, Confirm and enable, then store the backup codes. Workspace admins can require this under Settings → Security.
- Password: Current password, New password, Confirm new password, then Update Password.
- Active Sessions: each browser or device. This device is the current one. Revoke a row, or Sign out other devices.
Calendar sync
SiteHut can publish an ICS feed or webcal:// URL for tasks you care about. Subscribe from Apple Calendar, Google Calendar, or Outlook. This is one-way. SiteHut does not sync events back from Google or Microsoft. See Product limitations.
Privacy and personal export
- Optional product analytics (PostHog) is stored as a preference on this device until you change it.
- Download your account data returns JSON: profile, memberships, project access, API key metadata (not secrets), recent sessions. That is a personal export, not a dump of every job PDF and photo.
Personal API keys and account deletion
If your account allows it, create a user-scoped key for scripts that must act as you. Copy the secret once, store it well, rotate it if it leaks.
Workspace keys for Xero, exporters, and similar live under Integrations. Different scope, different permissions.
Danger zone is for leaving or deleting your account. Deleting a workspace is an admin action under workspace settings.
What done looks like
- Your name and avatar are correct on comments and the job team.
- Notifications match how you actually work (site vs office).
- Sessions you do not recognise are gone.
- You know the difference between personal export and a workspace export.
Common mistakes
- Looking for sales tax, logo, or users here. Those are workspace settings.
- Treating the ICS feed as two-way calendar sync.
- Creating a personal API key when the integration should use a workspace key.