Skip to article

Administration

Security & data controls

Manage sessions, provider access and deletion as separate responsibilities.

Account controls

Settings → Account & Security provides supported email, password and account-management actions. Settings → Devices shows sessions that can be reviewed and revoked. Confirm the account before taking a destructive action.

Authentication links, session cookies, API tokens and provider secrets are credentials. Never include them in a support screenshot or shared conversation.

Connected access

Use a dedicated, minimally privileged provider credential where the connector requires one. OAuth consent belongs on the provider’s authorization screen. An integration should use the selected business resource, not every resource your personal account can see.

Disconnect in Obelo and revoke or rotate at the provider when appropriate. The policy for already-imported data is separate from permission to fetch more data.

Data requests and deletion

The Privacy Policy explains categories of information, purposes, sharing, retention and rights. Review the in-product confirmation when requesting website or account deletion. Records may be retained where required for legal, security or accounting duties.

For a request not covered by the interface, email the privacy contact with enough information to identify the account. We may need to verify identity and the relevant organization’s authority. Do not email a full archive of private workspace data as proof.

Something unclear or out of date?

Suggest a correction