> ## Documentation Index
> Fetch the complete documentation index at: https://help.whetstone.au/llms.txt
> Use this file to discover all available pages before exploring further.

# Account settings, security and privacy

> Managing your Whetstone profile, password, two-factor authentication, notifications, privacy, and closing your account.

Everything here is under **Account**, reachable from your name or photo in the top-right corner.

## Changing your password

Enter your current password, then the new one — 8 characters minimum, checked against known leaked passwords. If you signed in with Google or LinkedIn there is no Whetstone password to change; manage it with them instead.

<Warning>
  **Changing your password signs out every other device** — your phone, your other browser, and anyone who should not have been signed in at all. You stay signed in where you made the change. Resetting a forgotten password does the same thing, for the same reason.
</Warning>

## If too many sign-in attempts fail

After **10 failed attempts within an hour**, the account is locked. Failed sign-ins, failed password resets and failed two-factor recovery codes all count towards the same total — they are three ways at the same door.

<Note>
  A locked account **does not unlock itself on a timer**. A timer would only tell someone guessing how long to wait. The Whetstone team is alerted the moment it happens, and a conversation with you is what lifts it — reply to any Whetstone email.
</Note>

## Two-factor authentication

Strongly recommended, especially for advisors receiving payouts.

<Steps>
  <Step title="Enable it">
    Choose **Enable two-factor** in your account settings.
  </Step>

  <Step title="Scan the barcode">
    Use an authenticator app — Google Authenticator, Microsoft Authenticator, Authy and 1Password all work. If you cannot scan, type in the key shown underneath.
  </Step>

  <Step title="Confirm">
    Enter the 6-digit code the app shows. From then on, signing in asks for your password and a fresh code.
  </Step>
</Steps>

**Recovery codes — do not skip this.** When you enable two-factor you are shown a list of one-time recovery codes. This is the only time you will see them.

* Save them somewhere that is not your phone — a password manager, or printed with your important papers
* Each one works once
* Using one to sign in **switches two-factor off**, so you can set it up again on your new phone
* Wrong recovery codes count towards the lockout above, because redeeming a code removes your second factor

Lost your phone and your codes? Contact support. Recovering an account with neither is deliberately slow, because the alternative is an account anyone can talk their way into.

## Notifications

Choose which emails you get. Everyone gets the essentials — payment receipts, confirmations and security notices — regardless of these settings. Session reminders, booking updates, new-message alerts and payout confirmations are all on by default, and leaving them on is wise: they are how you find out something needs you.

## Closing your account

**Business owners:** **Account** → **Delete account**.
**Advisors:** **Account** → **Leave the platform** → **Close account permanently**.

Either way it is permanent, either role can do it, and **having past bookings no longer stops you**. What changes is how much survives:

| Your account                                                 | What happens                                                                                                                         |
| ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ |
| Nothing is attached to it — no bookings, payments or reviews | It is **deleted outright**. Nothing is kept.                                                                                         |
| It has bookings, payments or reviews                         | It is **anonymised**. Everything identifying you is erased; what is left is a booking with an amount and a date, attached to nobody. |

Financial and dispute records have to be kept — a legal obligation, not a preference. That is met by erasing *you* from them rather than by refusing to close your account.

Either way, the sign-in account goes so nobody can sign back in, your uploaded photo and documents are deleted, and you are emailed a confirmation.

<Warning>
  **Money or commitments in flight will stop it.** A booking still live or awaiting payment has to finish or be cancelled, and a held payment has to be released or refunded, before an account can close.
</Warning>

Cannot reach your own account — locked out, lost the address, or just want to ask by email? Contact support and the team can close it for you, under exactly the same rules.

## Your privacy in short

* **Your challenge description** is seen by you and the Whetstone team only. Never published, never shown to advisors at large.
* **Your messages** are between you and the other party. The team can read a thread when handling a problem on that booking, and **every time they do it is logged** — who looked, at what, and when. They can post in a thread too, always labelled as Whetstone, and always to both of you at once.
* **Advisor ID and credential documents** are private to the reviewing team. Clients only ever see the Verified badge.
* **Card and bank details** are held by Stripe, not Whetstone.
* **Reviews you write** are public on the advisor's profile. **The outcome survey is not.**

The full legal detail is in the Privacy Policy and Terms, linked at the bottom of every page.

## Related articles

* [Can't sign in](/troubleshooting/cant-sign-in)
* [Contact support](/support/contact)
* [Getting paid](/advisors/getting-paid)


## Related topics

- [Setting up your advisor profile](/advisors/advisor-profile.md)
- [Can't sign in to Whetstone](/troubleshooting/cant-sign-in.md)
- [Fix Whetstone payment problems](/troubleshooting/payment-problems.md)
- [Getting paid as a Whetstone advisor](/advisors/getting-paid.md)
- [Create Your Whetstone Account](/getting-started/create-your-account.md)
