# Overview

Secure Foxora by separating account access, task authority, connected services, and device-local data instead of treating them as one permission.

![Overview](https://www.foxora.ai/docs/images/v5.0.8/reference/settings-permissions.webp)

*Studio interface in English. Sample data.*

1. Review **Account → Security & sessions** and revoke unknown devices.
2. Choose the least authority a task needs: Ask permissions, Accept edits, Auto mode, or Full Access.
3. In **Settings → Permissions**, enable only the device capabilities required for your work.
4. Store keys in dedicated Models, Plugins, or Channels fields; never paste secrets into prompts.
5. Export important data before account deletion or device cleanup.

Account deletion, local data removal, browser-profile cleanup, and external-provider revocation are separate actions. Completing one does not imply the others happened.

**Expected result:** trusted devices remain signed in, unnecessary capabilities are off, and sensitive data has a known storage and deletion path.
