Account and running it · Chapter 15
My account: profile, security, devices and more
Everything that concerns only you stands under “My account”: what you are called, how you sign in, which devices you are signed in on and where your uploads go. There are six tabs. You reach it through the round account button; the menu it opens also holds “Settings” (operators only), “About nexpaper” and “Sign out”.
Profile
The tab “Profile” shows how the others see you on your documents, notes and in the history.
- “Display name”: If it stays empty, nexpaper shows your user name. You still sign in with the user name.
- “Upload a picture”: A photo from your phone or camera. nexpaper cuts it to a square and keeps only the picture, no place and no device from the file.
- “Mail address”: It serves for “Forgot your password?” and for notices such as the one about a new sign-in. You enter it and press “Send confirmation”. Only once you have opened the link in the mail does it count. If the address changes, the old one is told. Without a mail server at the operator, no mail arrives.
- “Language”: German or English, and more if the operator has added them. It applies to your account only.
Security
This tab is the most important one. From top to bottom:
- Password
Whoever signs in with a password changes it here: “Current password”, “New password”, “Once more”, then “Change password”. It needs at least 12 characters. Afterwards all other devices are signed out.
- Second factor
With “Set up” you scan a QR code with an authenticator app or type the key below it. Then you enter the code from the app and your password and press “Turn on”. nexpaper then shows recovery codes once; “Save as file” helps, and “I have them” closes the window. The codes belong on paper and away from the phone. Each one opens the door once when the phone is missing.
- New recovery codes
When few are left (“Few recovery codes left”), you make new ones while you can still sign in. The old ones then stop working.
- Passkeys
With “Add a passkey” the browser asks for a fingerprint, your face or a PIN. Afterwards you sign in on the sign-in page with “Sign in with a passkey”, without a password and without a code. Up to ten passkeys per account are possible. Passkeys work only over https (or localhost), and only once the operator has entered the public address.
- Sign-in provider
If the operator has set up a sign-in service, there is “Link with …” here. Your password confirms it is you; then it goes to the provider briefly and back. With “Unlink” you separate them again.
- Signed-in devices
Each device stands in the list with its network and last use and can be ended with “Sign out”; “Sign out everywhere else” ends all the others. The switch “Tell me about a new sign-in” is on out of the box: by push and mail you learn which device, which browser and roughly from where.
Good to knowYou can switch the second factor off only if the operator does not require it for everybody. Out of the box they do.
Devices and apps
This is where phones and programs attach to your account.
- Pair a device: “Show a code for pairing” shows a QR code that you scan with the device. It is valid for 5 minutes and once, and the device gets a key of its own that you can block singly. A paired device acts with the rights of your account but can neither change settings nor pair other devices.
- From other apps on the iPhone: The instructions for the shortcut “Nach nexpaper” are in the chapter On the phone.
- API keys: For scripts of your own or a scanner that uploads directly. A key can only read or only upload, never change settings. The card is usable only if the operator has allowed API keys. More in the chapter Bringing things in.
- Notifications on your devices: On the device you are using, press “Turn on for this device” and allow it in the browser. With “Send a test” you check that it arrives. Push needs https (or localhost). On the iPhone it works only from the app on the home screen, from iOS 16.4. Push comes for a new sign-in, a finished export and a finished import from Paperless-ngx, among others, and never with the content of a document.
Upload, AI and look
- Tab “Upload”: “Where your uploads go” decides which vault the phone, the browser, the mailbox and the intake folder file into. Without a choice it is your personal vault. “On the phone” controls whether nexpaper starts there with the quick upload. Under “By mail” you enter further sender addresses for the operator's mailbox, up to 20; each gets a mail with a confirmation link.
- Tab “AI”: With “AI proposals for my documents” you switch the AI off for yourself. When it is off, your uploads get only rules and what nexpaper reads itself, and your text never goes to a model. If the operator has not allowed the AI for your account, it says so there.
- Tab “Look”: “Light or dark” with “Like the system”, “Light” and “Dark”, and for the archive “List” or “Tiles”. This applies to your account only.
Forgotten password, deleting an account
If you have forgotten your password, “Forgot your password?” on the sign-in page helps. You enter your name or your mail address, and if there is an account with an address for it, a link is on its way that works once and for 24 hours. That needs a mail server and the public address; otherwise the operator sends you the link under “Settings”, “Accounts”. Your second factor stays as it was.
You do not delete an account yourself. Only the operator does that, and they are asked where the documents of your personal vault go.