The most frequent questions about the security of your account, data protection in your workspaces, technical access and your GDPR obligations. For the complete inventory of the mechanisms available, see the overview.
Click a question to display the answer.
Securing my account
How do I enable two-factor authentication (2FA)?
Learn more → Two-factor authentication (2FA)
How strong does my password need to be?
Learn more → Securing your organisation's accounts
I have doubts about a session left open elsewhere, what should I do?
Learn more → Edit my profile and my options
What should I do when I no longer need access to a client workspace?
Watch out for the right place. From Account → Received invitations, the Cancel button does take you out of the workspace, but the action is reversible: the row goes back to « Not accepted » and one click on Accept gives you access again. So it is not a revocation.
To leave for good, open the workspace and click the Members icon at the top right. If you are an Admin there, a trash icon appears on your own row and lets you remove yourself, permanently. If you are a User there, only the owner or the administrator who invited you can do it.
Learn more → Manage your invitations · Set member rights
Protecting data in my workspaces
How do I store a password or a key from an external tool in TimeTonic?
Learn more → Encrypted field
Where do I have to tick « Authentication required »?
- On a shared form view: Share button, then Edit options.
- On a field of type External form: Options tab of the field.
- On an Attachments field: Options tab of the field.
Check all three, every time.
Learn more → Check your external sharing
How do I limit a form link to a single use?
Learn more → External form
How do I revoke a share link that has already been circulated?
Learn more → Revoke an access
How do I hide a sensitive column from certain members?
Two other mechanisms depend on the state of the row rather than on the reader: conditional visibility and conditional read-only.
Learn more → Choosing the right level of protection · Restrict access to a column view by view
I hid my columns, but the user still sees too much. Why?
Link columns. A link column displays the records of another table through a view of that table. If no view is selected on it, from the record the user reaches data that you had hidden. The setting is made link column by link column.
The configuration has not been locked. Without Lock the view settings, a user can remove a filter or display a column again.
Learn more → View selection on a link column · Lock the options of a view
How do I display only part of a sensitive value?
Displays only the last four characters.
Combine it with setting the original column to Invisible: without that, the mask protects nothing.
Learn more → APPLY_MASK()
How do I limit a user to their own data only?
Learn more → Use the user ID as a default value · Create and use a mirror view
Securing technical access and integrations
How do I create an API key?
Learn more → Create and manage your API keys (Sesskey)
Which rights can I give to an API key?
Does a read-only key still see all my data?
To restrict the scope, create a dedicated account, give it access only to the filtered views required, then generate the key from that account.
Learn more → Create an API account restricted to filtered views
How do I revoke an API key?
Always name your keys after their use (api-make, api-n8n, api-reporting-client): that is what will allow you to delete the right one, months later.
Learn more → Revoke an access
What should I check on my exports and synchronisations?
Learn more → Personal data and technical data · Share your table data
Are my OpenAI or Mistral API keys stored by TimeTonic?
Learn more → Does TimeTonic store my OpenAI or Mistral API key?
GDPR and what to do
Which data counts as personal data?
Learn more → Personal data and technical data
What are privacy by design and privacy by default?
Can I record a demonstration video containing client data?
A client asks for access to their data, what should I do?
Learn more → Your GDPR obligations in TimeTonic · GDPR register template
Who should I contact if I suspect a data breach?
Learn more → Revoke an access · GDPR
Go further
Security overview
The complete inventory, from the account to the API.
Go further
Administrator checklist
The ten reflexes to check on your workspaces.
Go further
Check your external sharing
The three control points never to forget.