Keep your Sprecho account secure

Password rules, email verification, how sessions work, signing out everywhere, SSO for teams, and what to do if you think someone else has access.

Updated August 23, 20264 min read

Your Sprecho account holds your dictation history, your dictionary and your plan. This article covers the controls that protect it and the steps to take if something looks wrong.

Everything here lives in Settings → Account, split into Personal Data and Security.

Choosing a password

Sprecho requires at least 8 characters, including one uppercase letter, one lowercase letter and one number, and refuses a new password that matches the current one. A strength indicator appears as you type.

Those are minimums, not a recommendation. A password manager generating something long and unique is a better answer than a memorable phrase that follows the rules.

To change it: Settings → Account → Security → Change Password. You enter the current password, then the new one twice.

Changing your password signs you out on every device, including the one you are using. That is intentional: if the reason you are changing it is that someone else might know it, leaving their session alive would defeat the point. You will be asked to sign in again afterwards, and a confirmation email goes to your address.

Signing in without a password

If you created the account with Google, Microsoft or Apple, that provider handles the sign-in and Sprecho stores no password for you. Whatever protection you have configured there — two-step verification, a passkey, a hardware key — applies to Sprecho too, which for many organisations is the simplest way to raise the bar.

Verifying your email address

After registration you get a six-digit code by email. Entering it in the app verifies the address.

Verification matters more than it looks: password reset, account deletion and security notices all go to that address. If it was mistyped, those routes point at a mailbox you do not control. You can request a new code from the app if the first one expired, and you can correct the address under Settings → Account → Personal Data → Change Email, which asks for your password and sends a code to the new address.

Changing the email address also ends all sessions.

How sessions work

  • Signing in creates a session that the app refreshes silently in the background, so you stay signed in across restarts for up to 30 days of inactivity.
  • Settings → Account → Security → Log out ends every session on the account, not only this device's. It is Sprecho's sign-out-everywhere.
  • Changing your password or your email address also ends every session.

If you are being signed out unexpectedly rather than on purpose, that is a different problem — see I keep getting signed out.

Single sign-on for teams

Enterprise organisations can connect Sprecho to their own identity provider so that employees sign in with the company account and no separate Sprecho password exists. Deprovisioning then happens where it should: removing someone in your directory removes their access to Sprecho.

Setup, the supported protocols and what members see is covered in set up single sign-on (SSO) and SAML.

If you think someone else has access

  1. Change your password now. This alone ends every active session on the account, including theirs.
  2. If you sign in with Google, Microsoft or Apple, change the password there instead and sign out of Sprecho — the provider owns the credential, not Sprecho.
  3. Check your history. Open the history view and look for dictations you do not recognise.
  4. Check your email address under Settings → Account → Personal Data. An attacker who changes it takes over the password-reset route.
  5. Write to support@sprecho.ai from the address on the account. Tell us roughly when you noticed and what looked wrong, and we can check the sign-in records for the account.

If the account belongs to a company team, tell your team owner as well. They can remove the member's seat immediately, which cuts off access to team resources while the rest is sorted out.

Reducing what is there to lose

Security and data minimisation reinforce each other. If your dictations do not need to be stored, an account compromise exposes far less:

Frequently asked questions

Open Settings → Account → Security and click Log out. That ends every session on the account, not only the one on the device you are using, so every other signed-in device has to sign in again.

Was this article helpful?

Still stuck?

Tell us what you are trying to do and we will walk you through it.

Related articles