Account and security
#Signing up
Email, and a password of at least 10 characters (and at most 200). That is the whole form.
Your account is active immediately — no verification email, no approval queue. If you signed up and cannot sign in, it is not a pending verification: it is the wrong password, or you already have an account on that address. Use Forgot password, which sends a link valid for one hour.
Signup asks for no payment details, and the Free plan never will.
A duplicate signup gets the same success response as a new one — the product does not confirm which addresses are registered. If somebody reports "it said the account was created but I cannot sign in", that is usually what happened.
#Signing in
Email and password. Rate-limited both per network and per account, so repeated wrong guesses slow down whether they come from one machine or many.
A session lasts seven days, then asks you to sign in again.
#Two-factor
Optional, TOTP-based, and you turn it on yourself under /account → Security.
Once enabled, a correct password leads to a second prompt: the six-digit code from your authenticator app, or one of your recovery codes. That second step has a five-minute window, and it is rate-limited per account.
Keep the recovery codes you are given at enrolment. Each works once. You can regenerate the batch later from Security by entering a live code, which invalidates the old ones.
If you lose both your authenticator and your recovery codes, there is no self-serve way back in — by design, because a self-serve bypass would be a bypass for anyone. That needs support and a real conversation.
#Changing your password
Under Security. Changing it signs out every other device, which is the point of doing it.
#The cabinet
/account, top right, in four sections:
Overview — your email, plan and price, the upgrade control, and the link into the billing portal.
Usage — what you have spent this month against each allowance, when it resets, and the export card. Read-only feeds and history do not count against usage.
Sessions — your saved assistant conversations, split between general chats and lookup or Telegram sessions, deletable one by one.
Security — password, two-factor and recovery codes, your active sign-ins, and the OSINT-history retention window.
#Active sessions
Security lists every session on the account with the device, browser, address and when it signed in, the current one marked. Revoke any of them — that is the control to use if you signed in somewhere you no longer trust.
#Support and escalation
- In-app chat — the Support app, once signed in. The assistant answers what it knows and hands over what it does not.
- Telegram — @exointel_support_bot. Link your Telegram from Support → Link, so the bot can see your account: it gives you a code to send to the bot within 15 minutes. Revoke the link any time.
- Email — support@exointel.watch.
Anything about money, account access or security goes to a person. You do not have to get past the assistant to reach one.