> ## Documentation Index
> Fetch the complete documentation index at: https://docs.callers.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Account Settings

> Choose how long recordings are kept, control support access and require multi-factor authentication.

Account-wide settings live on the **General** tab of **Settings**. Click your name at the bottom of the sidebar, choose **Settings**, and stay on **General**.

The **Account** section at the top holds your account name and, in a main account with white labeling, your logo and custom domain - see [White Label](/documentation/agencies/white-label). Below it are the settings on this page.

<Frame caption="Account settings on the General tab">
  <img src="https://mintcdn.com/voxiaai/Y4I0WKZoxEmByncR/images/documentation/using-callers/account-settings.png?fit=max&auto=format&n=Y4I0WKZoxEmByncR&q=85&s=fff499c45ce1ef0692fae1f3014eb173" alt="Retention period, Restrict Support Access, Multi-Factor Authentication (MFA) and Webhook Signature on the General tab" style={{borderRadius: '10px'}} width="1139" height="672" data-path="images/documentation/using-callers/account-settings.png" />
</Frame>

<Note>
  **Retention period**, **Restrict Support Access** and **Multi-Factor Authentication (MFA)** are shown to admins. An admin whose **Manage account settings** permission is turned off can see them but not change them - see [Access Permissions](/documentation/agencies/managing-subaccounts#access-permissions).
</Note>

## Retention Period

How long call recordings and transcripts are kept: **90 days**, **180 days**, **1 year** (default), **2 years** to **5 years**, or **Custom**. A custom period is set in days, with a minimum of 5 - an empty or smaller value falls back to 1 year. The change is saved as soon as you pick a value.

Recordings and transcripts older than the retention period are deleted. Contacts and call details such as status and duration are kept.

<Warning>
  Shortening the retention period also applies to existing calls, and deleted recordings and transcripts can't be restored.
</Warning>

Each account - including each subaccount - has its own retention period.

## Restrict Support Access

Turn this on to keep support staff and account managers out of your account. If you need help from a specific support person, invite them on the **Members** tab - as a member, they can access the account again.

## Multi-Factor Authentication (MFA)

Turn this on to require every member of this account to enter a code from an authenticator app each time they log in. It applies from each member's next login, including logins with SSO. Admins of a main account who work in its subaccounts follow their own account's MFA setting.

* **First login**: The member sees **Set up two-factor authentication**. They scan the QR code with an authenticator app, such as Google Authenticator, or type in the manual entry key, then enter the 6-digit code and click **Verify & continue**.
* **Every login after that**: They enter the 6-digit code from the app under **Two-factor authentication** and click **Continue**.

There are no backup codes. If a member loses access to their authenticator app, an admin opens the **Members** tab, chooses **Reset MFA** in the member's `⋯` menu, and the member sets up the app again at their next login. Accounts that use SSO don't have this menu - contact support instead.

Each subaccount turns MFA on or off separately.

## Webhook Signature

Every request sent to your webhook endpoints is signed, so you can check that it comes from Callers. Click **Show HMAC Secret** to see and copy the secret key. See [Validating Webhook Signatures](/documentation/webhook/validating-webhook-signatures).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.