Your Account

Account Management

How to update your profile, change your email, manage connected Instagram and TikTok accounts, control sessions and notifications, sign out, and what DMpro offers for two-factor security.

Go to Dashboard → Profile. You will see a form with your current information and edit buttons next to each field.

What you can edit

  • Name. Your display name in DMpro. Click Edit, enter the new name, and click Save. Changes take effect immediately, but messages you already generated keep the old name (they were generated with it). New messages use the updated name.
  • Country. Click Edit and pick from the searchable dropdown. This sets the currency shown on the pricing page and the default country on your invoices. It does not change which language DMpro uses, and it does not touch your billing address in Stripe (that is set separately).
  • Onboarding preferences. Click Edit Onboarding to go back through the onboarding flow with your current answers pre-filled. This changes which starter prompts are suggested, which persona-specific features appear, and which integrations are recommended. It does not touch your existing prompts or campaigns, those are preserved.
  • Connected social accounts. Manage your Instagram and TikTok handles (see the next question).
  • Notification preferences. Your email preferences (see the notification preferences question below).

What you cannot edit

  • Your email. It is the primary key for your DMpro account, so it cannot be edited directly here. See “How do I change my email address?” below.
  • Your referral code. It is auto-generated and cannot be customized. If you are on a Professional plan or higher and want a custom code, contact support.
Note: DMpro does not currently support profile photos, just name and text.

One DMpro account equals one profile. If you want a separate identity for different work, create a second DMpro account, keeping in mind the fingerprint system can flag a social handle that is shared across two different DMpro accounts.

Your email is your primary account identifier, the destination for your sign-in codes, your billing email in Stripe, and where all notifications land, so DMpro treats an email change as a security-sensitive action.

The standard flow

  1. Go to Dashboard → Profile → Change Email.
  2. Enter your new email address.
  3. DMpro sends a 6-digit code to the new email.
  4. Enter the code to confirm.
  5. DMpro sends a security notification to your old email confirming the change.
  6. Your new email is now active.

The 6-digit code expires after 10 minutes. If it expires before you confirm, request a new one.

Tip: after the change, DMpro automatically updates your billing email in Stripe. If you want a different billing email (for example, a personal address for DMpro but a corporate address for invoices), set that separately in the Stripe Customer Portal.

If the new email is already in use

DMpro allows one account per email address. If the new email is already tied to another DMpro account, you will see “This email is already in use.” Use a different email, or contact support if you need the two accounts merged manually.

If you lost access to your old email

  1. Try the sign-in flow with your account email.
  2. The verification code goes to that account email, which you may not be able to reach anymore.
  3. Contact support at [email protected] from any email you control.
  4. Support will ask for proof of ownership (a past invoice, your Stripe email, etc.) before making the change.

This kind of recovery is handled case by case and typically takes 24 to 48 hours.

Note: changing your email does not cancel an active trial or subscription. Trials continue as scheduled, and subscription charges continue on whatever payment method is on file.

Go to Dashboard → Profile → Connected Social Accounts to see every Instagram or TikTok handle DMpro has associated with your account: the handle, the platform, the date it was first connected, when it was last used, its DM volume over the last 30 days, and a remove button.

How accounts get added

You do not add handles manually. DMpro detects them automatically: you sign in to Instagram or TikTok in a browser where the extension is installed, you open the extension, DMpro reads your current handle from that active browser session, and the handle is added to your Connected Accounts list.

Removing an account

Click the trash icon next to any handle and confirm. Removing an account does not affect anything on Instagram or TikTok itself, it only removes the association from DMpro, and DMs sent from that handle stop counting toward your DMpro stats. You can always re-add a handle by signing back in and using the extension again.

Connected account limits by plan

PlanConnected accounts
Free2 (1 Instagram + 1 TikTok)
Starter2
Growth2
Professional3
Enterprise10

If you go over your limit, the extension warns you and the extra account is not able to send.

Switching between accounts

Sign in to whichever account you want to send from in your browser. DMpro auto-detects it and uses it, no settings change needed.

Note: if a handle DMpro detects was previously seen on a different DMpro account, it triggers a fingerprint block on your account. A handle DMpro has never seen before is simply recorded with no issue.

Sharing accounts across users

On Free, Starter, and Growth, it is one user per DMpro account. If a teammate signs in to Instagram in their own browser with the extension installed, that uses their own DMpro account, not yours. Enterprise team plans allow multiple team members to share one DMpro account using multiple Instagram and TikTok handles across the team.

Disconnecting

DMpro does not use OAuth for Instagram or TikTok, so there is no traditional “disconnect” button. To stop DMpro from using an account, sign out of Instagram or TikTok in your browser, or uninstall the DMpro extension.

On privacy: your handle name is public and stored in your Connected Accounts list, handle stats are aggregated for your usage view, and your Instagram or TikTok password is never captured or stored by DMpro.

DMpro sessions run on JWT tokens and last 30 days on each device. After 30 days of no activity, you are asked to sign in again with a fresh 6-digit code.

Sliding window renewal

Every time you use the extension or the dashboard, your session token refreshes and the 30-day clock resets from that point. If you use DMpro daily, you effectively stay signed in indefinitely.

When you get signed out

  • You did not use DMpro for 30 days straight, so the session expired.
  • You explicitly signed out.
  • A security event triggered a rare server-side session invalidation.
  • You changed your email. Old sessions are invalidated and you sign in again with the new email.

Multiple devices and storage

Each device keeps its own independent session, so signing out on your laptop does not sign you out on your desktop. Your session token is stored locally: in Chrome extension storage for the extension, and in localStorage for the dashboard. Both are same-origin scoped, so other websites cannot access them.

Note: the token uses HS256 (HMAC SHA-256), expires 30 days from issue, and contains only your user ID and email, nothing more sensitive. If a token were ever stolen, it could be used until it expires, so contact support right away to have it invalidated.

Incognito sessions are separate from your normal browser session. Signing in while incognito does not share the login with your regular browser, and closing the incognito window loses that session.

Go to Dashboard → Profile → Sessions to see every device currently signed in to your account: the device and browser (for example “Chrome on Mac” or “Brave on Windows”), an approximate IP address and location, when it was last active, and a sign-out button.

Signing out one session

Click Sign Out on any session in the list. Only that device is signed out, everything else stays active. This is useful if you lost a laptop and want to remotely revoke it, signed in on someone else’s computer, or just switched browsers and want to clean up.

Signing out everywhere

Click Sign Out All Sessions to sign out every device at once, including the one you are using. You will need to sign back in with the standard magic code flow.

Sessions that sit inactive for 30 days expire automatically, so you do not need to manually clean those up.

Tip: if you see a session you do not recognize, sign it out immediately from the Sessions list, then sign out of all sessions and sign back in fresh from your legitimate device, contact support to investigate, and review your billing history for any unauthorized charges.

Each browser you sign in to counts as its own session (Chrome, Brave, and Edge on one computer would be 3 sessions), and the extension keeps its own session separate from the dashboard even on the same device. On Enterprise team accounts, each team member has their own session under the shared account, and admins can see all team member sessions in a separate Team Sessions view.

Note: DMpro currently shows only active sessions, not a full session history. If you need a historical audit for a security review, contact support with your DMpro email.

Go to Dashboard → Profile → Notification Preferences to see a toggle for every notification type DMpro sends by email.

NotificationDefaultCan turn off?
Product updatesOnYes
Marketing (promotions, discounts)OffYes (opt in)
Weekly usage report (Mondays)OnYes
Monthly usage report (1st of month)OnYes
Payment notificationsOnNo, required for account safety
Trial expiry warnings (3 days before)OnYes
Gift expiry warnings (7 and 3 days before)OnYes
Runway warnings (credits running low)OnYes
Security alertsOnNo, required for account safety

Payment notifications and security alerts cannot be turned off, everything else is optional and can be toggled per your preference.

Marketing emails

Marketing is off by default. You opt in explicitly, either by toggling Marketing on in Notification Preferences or by clicking a promotional link in an email that asks to opt you in. This default-off approach is compliant with CAN-SPAM (US), GDPR (EU), and CASL (Canada) email regulations. Product update emails cover DMpro’s features and roadmap and are non-promotional, while marketing emails are about discounts, sales, and referral opportunities.

How often emails go out

Weekly and monthly reports arrive between 6 and 8 AM your local time on Mondays and the 1st of the month respectively. Product updates go out occasionally, roughly 2 to 4 times a month, and marketing (if you opted in) goes out about 1 to 2 times a month.

Every email includes an unsubscribe link at the bottom for that specific category. Transactional emails come from [email protected] and marketing emails come from [email protected], so add both to your contacts to keep them out of spam.

Note: DMpro does not currently send SMS, push, or in-app notifications, everything goes by email. On Enterprise team plans, admins can set team-level notification defaults, though individual toggles still work on top of them.

Signing out clears your session on the current device only. Your account, prompts, campaigns, credits, and subscription all stay intact.

From the dashboard

  1. Click your avatar in the top-right corner.
  2. Click Sign Out.
  3. Your session is cleared and you are redirected to the login page.

From the extension

  1. Open the DMpro extension.
  2. Click the settings gear icon.
  3. Click Sign Out.
  4. Your session on this browser is cleared and the extension shows the sign-in screen.

Signing out has no effect on other devices you are signed in to, on active subscriptions or credits, or on your Instagram or TikTok connection (DMpro does not control that). Signing back in uses the standard magic code flow: enter your DMpro email, receive a 6-digit code, enter it, and you’re in, usually about 30 seconds.

Tip: on a public or shared computer, sign out when you are done. Otherwise the session stays active on that machine for 30 days. If you never sign out and never use DMpro again on that device, it will still automatically expire after 30 days of inactivity.

DMpro is passwordless, so there is no password to change if you suspect a session is compromised. Instead, sign out of all sessions, sign in fresh, and contact support if you noticed anything suspicious. See “How do I manage multiple sessions across devices?” for the sign-out-everywhere flow.

DMpro uses passwordless magic-code sign-in rather than a traditional password, and this is inherently a form of two-factor authentication: it requires access to your email plus the one-time 6-digit code, rather than just a password. Classic 2FA is usually described as “something you know (a password) plus something you have (a phone or authenticator).” DMpro’s flow is closer to “something you have (email access) plus something you have (the code),” so it is not classic password-plus-second-factor 2FA in the strict sense, even though it does require a second, real-time proof of access every time you sign in.

Note: dedicated additional 2FA layers are not yet available on DMpro. TOTP apps like Google Authenticator, hardware keys like YubiKey, and SMS-based 2FA are all not currently supported. These are on the roadmap, and you’re welcome to contact support if you’d like to advocate for them.

Best practices in the meantime

  • Use a strong email account and enable 2FA on your email provider (Gmail, Outlook, etc.). This effectively secures your DMpro account too, since your email is the recovery mechanism.
  • Watch for phishing. DMpro will never ask for a password (it does not have one for you to give). If someone claiming to represent DMpro asks for your credentials, it is a scam.
  • Sign out on shared devices, and review your active sessions periodically.
  • Only install the DMpro extension from the official Chrome Web Store.

What DMpro does on its end

Server-side, DMpro applies rate limiting to prevent brute-force attempts on your email, invalidates sessions when it detects suspicious activity, encrypts all data at rest, and uses HTTPS for all API traffic.

Tip: Enterprise plans get extra security options: SSO (SAML, OAuth) by contacting [email protected], IP allowlisting, full audit logs of admin actions, and a custom session timeout shorter than the standard 30 days.

Still stuck? We’re happy to help.

Sign in to your DMpro account, review your plan, or reach out to support directly.

Back to Help Center