Skip to content

Sessions and account security

Review active sessions, understand how staying signed in works, recover access, deactivate your account, and report security concerns.

Last updated

On this page

Your account's day-to-day security lives on two pages: Security (password, two-factor and sessions) and Profile (email, handle and the Danger zone). Both are in your account menu, top right.

Active sessions

The Active sessions card on the Security page lists every signed-in session. Each row shows "This device" or "Other device", the browser, the originating IP address and when the session started, with a Sign out button on every session except your current one.

Signing a session out takes effect immediately — every request is checked server-side, so a signed-out session cannot keep working.

How staying signed in works

Laya deliberately keeps you signed in for as long as it technically can — sessions can last up to a year and are not expired on a schedule. That is safe because revocation is instant: signing a session out (or being signed out everywhere) kills it straight away, regardless of the token's age. If a device is lost or shared, sign its session out from Active sessions.

Recovering access

Recovery is built on your email inbox. If you cannot sign in, request a magic link from the sign-in page (Email me a magic link instead, or Forgot password? on the password step), open it within 10 minutes, then set a new password from the Security page. If two-factor authentication is on, you will still be asked for a second factor — use a recovery code if you have lost your devices.

If you are locked out entirely, email support@laya.net from the address on your account.

Deactivating your account

The Danger zone on your Profile page offers Deactivate account. You confirm by typing your @handle. As the page puts it: "You'll be signed out everywhere and your account will be hidden. Your data is kept and a workspace admin can restore it."

Deleting your account and data

Deletion and erasure are by request: email privacy@laya.net and Laya responds within one month. Deleted accounts have a 30-day recovery window; after that the account is anonymised in place — the display name becomes "Former user", the email, handle and avatar are removed, and passwords, two-factor secrets, passkeys, linked providers, sessions and security history are deleted. Items and comments you authored remain with a stable anonymous author, so your former team's history stays intact.

Reporting a security concern

If you believe you have found a vulnerability, or you see activity on your account you do not recognise, email support@laya.net with the subject "Security report". Include what you saw, when, and any steps to reproduce — and please never include passwords, tokens or recovery codes in the email.

Still stuck?

Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.

Contact support