Documentation

Settings

Settings is where you manage your profile, dashboard preferences, sign-in security, your data, and the workspace you share with teammates. Open it from Settings in the sidebar.

The page is a row of tabs: Account, Preferences, Security, Data & Privacy, Workspace, and Billing. The tab you are on is written into the page address, so a link like /settings?tab=security opens straight to that tab.

Note

Billing is not shown on self-hosted enterprise deployments, which do not use credits.

Account

The Account tab holds your personal details and the account deletion control.

Settings, Account tab: a Profile card with avatar, display name and email fields, above a red Delete account card

Profile

The card shows your avatar, your name, and the date you joined next to Member since.

Field Notes
Display name Shown throughout the dashboard. Edit it, then Save changes — the buttons only appear once you have changed something. Cancel discards the edit.
Email Read-only. The hint reads Email is managed by your sign-in provider, because your address comes from the Microsoft or Google account you sign in with. If a change to your address is already in flight, the hint reads Pending change to … instead.

Delete account

Request account deletion sits in the red Danger zone card at the bottom of the tab. It asks you to confirm in a dialog — Keep my account backs out, Request deletion goes ahead.

What happens when you confirm:

  1. Your account is deactivated immediately and you are signed out.
  2. Your data is kept for a 30-day grace period.
  3. At the end of the grace period everything is permanently removed — assistants and their configuration, conversations, analytics, and uploaded knowledge base documents.

You can cancel during the grace period and reactivate the account. Once the 30 days have elapsed the cancellation is refused, because the permanent deletion is already under way.

Preferences

Appearance

Theme is a Light / Dark switch. The change applies straight away and is saved to your account, so the dashboard opens in the same theme on your other devices. It is the same setting as the theme toggle in the top bar.

Interface language offers English, Español, Français, Deutsch, and Português. Your choice is saved to your account as soon as you pick it.

Notifications

Two switches, saved together with Save Preferences. Reset puts them back to their last saved state.

Switch What it controls
Activity Updates Email notifications when people interact with your assistants
Weekly Digest A summary of agent activity, delivered every Monday

API Keys

There is no API Keys tab. It was withdrawn because the keys it issued opened nothing: Hiroi has no public REST API, so a key was a live secret with no endpoint to send it to.

Everything the dashboard does runs on your signed-in session. The two things you can integrate with are covered in the developer section: Embedding the widget and Actions, which call your endpoint rather than the other way round. If you created keys while the tab was visible, they are inert — nothing accepts them.

Security

Passkeys

A passkey signs you in with your device biometrics or PIN instead of a password, and cannot be phished. Add passkey asks you to name it — something you will recognise later, like MacBook Touch ID — then hands off to your browser and operating system to create the credential.

Each passkey in the list shows when it was added and when it was last used. Remove deletes one after a confirmation.

If your browser does not support passkeys, the card says so instead of offering the button.

Two-factor authentication

Two-factor authentication is delivered through passkeys — there is no separate authenticator app to set up. The badge on this card reflects your actual state:

Badge Meaning
Enabled via passkeys You have at least one passkey registered
Not configured You have none — add one in the Passkeys section above

Removing your last passkey therefore also turns off two-factor protection, and the confirmation dialog warns you about that.

Data & Privacy

Data export

Download my data builds a JSON file containing your profile, bots, widget sites, conversations, activity logs, consent records, and token usage. This is the GDPR Article 20 data-portability export.

The file is generated on the spot and saved by your browser — nothing is stored on our side afterwards. You can take up to three exports an hour.

Data retention

Conversations older than your retention period are deleted automatically. The default is 365 days.

Retention period offers 7, 14, 30, 60, 90, 180, and 365 days, plus the 365 days (default) option. The setting applies to every assistant on your account and saves as soon as you pick it. Choosing a shorter period is a straightforward way to hold less data.

A record of the legal agreements you have accepted — the document name, its version, where the consent was recorded, and the date. Each entry is badged Accepted or Withdrawn. The most recent 50 records are shown.

Buttons that open the Terms of Service, Privacy Policy, Cookie Policy, and Data Processing Agreement in a new tab.

Workspace

The Workspace tab manages the organization currently selected in the sidebar switcher. Every account gets a personal workspace; shared workspaces let teammates work on the same assistants.

Not yet available on hiroi.ai. Shared workspaces are turned off for launch — creating one, inviting people into one and deleting one are all disabled, so the Invitations card and the Delete organization control below do not appear. Every account has the personal workspace it was given at sign-up, and existing shared workspaces keep working. When the feature opens it will be a paid one: add credits to your account to unlock it.

Organization

Name is editable by admins and owners. A personal workspace cannot be renamed. Under the field sit the workspace's URL slug, a Personal badge where relevant, your own role, and the member count.

Members

Everyone with access to the workspace, with their name and email address.

If you are an admin or the owner, each row you are allowed to change carries a role selector and a Remove button. You cannot change your own role or the owner's from this list; those rows show a plain role badge instead. Removing someone revokes their access to the workspace's assistants and data immediately.

Roles, from least to most access:

Role Access
Viewer Read-only: assistants, contacts, conversations, and analytics
Member Everything except workspace settings and member management
Admin Everything, including workspace settings, members, and invitations
Owner The person who created the workspace. Ownership cannot be transferred from this list — the role selector offers Viewer, Member, and Admin only — and the last owner cannot be demoted or removed

Invitations

Admins of a shared workspace see an Invitations card. Invite member takes an email address and a role, and sends the person a link to join. Invitations expire after 7 days.

Pending invitations are listed with a status badge; Revoke cancels one before it is accepted.

Danger zone

Personal workspaces have no danger zone. In a shared workspace, what you see depends on your role:

  • Leave organization — for members who do not own the workspace. You lose access to its assistants, conversations, and settings; an admin can re-invite you later.
  • Delete organization — for the owner. This permanently removes the workspace, its members, and all associated data. You have to type DELETE into the dialog to enable the button.

Billing

Billing is the last tab and shows the same content as the Billing page: your credit balance, purchases, and usage. See Billing and credits.