Clicky

Help CenterPrivacy, Legal and Support › Your Data and Security

Are my mailbox password and Twilio keys stored securely?

Your Data and Security · Updated September 23, 2026

Yes. Your mailbox password, your Twilio account SID and auth token, and your Legiit marketplace token are all encrypted before they are stored, using AES-256-GCM. The key that unlocks them is kept apart from the database, and the saved values are never sent back to your browser, not even in their encrypted form.

How they are stored

  • The value is encrypted the moment you save it, so what sits in storage is unreadable on its own.
  • The key that opens it is not held in the database. Somebody with a copy of the database alone would still have nothing usable.
  • Every screen that shows your settings has these values stripped out first. Once saved, a password or token cannot be read back through the app by you or by anyone else. If you need to change one, you enter it again.

What they are used for

Each credential is unlocked only at the moment the feature you connected it to needs it, and only for that feature.

  • Your mailbox password is unlocked when an email is sent through your mailbox, and when the connection is checked as you save the mailbox.
  • Your Twilio account SID and auth token are unlocked when a tracking number or a call recording needs to be handled.
  • Your Legiit marketplace token is unlocked when the app talks to Legiit on your behalf.

The Privacy Policy puts the same commitment in writing: credentials you provide are stored encrypted and used only to operate the features you connect them to.

How to remove a saved credential

All three are removed from Settings, and removing one deletes the stored value.

Your mailbox

  1. Open Settings and find the Outreach Autopilot card.
  2. Click Remove next to the address you want gone.
  3. You will be asked Disconnect your@address.com? Confirm, and the mailbox and its stored password are removed.

Your Legiit marketplace token

  1. Open Settings and find the Legiit Marketplace card.
  2. When it is connected, the card shows ✓ LEGIIT CONNECTED.
  3. Click Disconnect. Your stored token is removed and orders can no longer be placed from the app until you connect again.

Your Twilio keys

  1. Open Settings and find the Call Tracking card.
  2. When Twilio is connected, the card shows ✓ TWILIO CONNECTED.
  3. Click Disconnect next to it.
  4. You will be asked Disconnect Twilio? Existing tracking numbers stop being manageable from here. Confirm to remove your stored keys.

If you are on a team seat

Two of these belong to the account owner. The Legiit Marketplace card is not shown on a seat's Settings page at all, and Disconnect on Call Tracking does not go through, so the card carries on showing ✓ TWILIO CONNECTED. Ask the account owner to remove either one. Mailboxes under Outreach Autopilot can be removed from a seat.

Disconnecting removes your stored Twilio keys from Legiit Leads. It does not close anything in your Twilio account, and any tracking numbers you already bought stay in Twilio, billed by Twilio, until you release them there.
Was this helpful?

Still stuck?

A real person on the Legiit team will help. No bots, no runaround.

Contact Supporthelp@legiit.com