Client account settings
A client's Esqase account belongs to the client, not to your firm. They choose how they sign in, how they are notified, and whether to keep the account at all. This page describes what a client finds under Settings in their portal, and on the account screen of the Esqase Client app, so you can answer questions about it, and so you know what your firm can and cannot do on a client's behalf.
Your firm cannot link or unlink a client's Google account, sign in as them, or delete their Esqase account. Those are the client's own, by design.
Before you begin
- Settings live in the client portal. A client opens the account menu at the top right and chooses Settings. A back arrow sits beside the Settings heading and returns them to whatever they were looking at, or to their list of matters if they arrived from a link. Under the heading are three tabs: Profile, Security and Notifications.
- In the Esqase Client app, the same settings are on the account screen. The client taps their initials at the top left of Home, Matters, Events or Messages. Each section below says where its part of the account screen differs.
- Settings is a narrower page than the rest of the portal. It sits on the same white card, centred in a single reading column about half the width of a matter page, so the forms and toggles stay close together instead of stretching across a wide screen. The bottom bar a client uses to move around a matter is not shown here, because Settings does not belong to a matter.
- Nothing here changes your records. A client's name in their portal profile is their account name. It does not rewrite the contact record you hold, and changing it does not affect access.
- Access still depends on the email address you hold. Settings cannot grant a client anything. See How clients sign in.
📷 Screenshot: The client portal Settings page, showing the back arrow beside the Settings heading, the Profile, Security and Notifications tabs, and the narrow centred column.
Profile
The Profile tab holds the client's first and last name, which they can edit and save, and their email address, which is shown but cannot be changed there. A client who needs a different address should ask the firm they work with, because the address is what connects them to your records.
The page also links to the Esqase privacy policy and terms of service.
Profile in the Esqase Client app
Personal details on the account screen holds the same First name and Last name, with Save, and shows the Email read-only with the line "To change your email, ask your law firm. It is what connects you to their records." Terms and privacy opens the Terms of Service, Privacy Policy, Acceptable Use Policy and Data Processing Agreement, and the app's Open-source licences. The account screen also shows the client's account ID with a Copy button, and the app version.
Security
The Security tab is where a client manages how they get in. Some of these actions ask the client to sign in again first, if it has been a while. That is deliberate, and it is what stops someone using an unattended browser to take an account over.
Sign-in methods
Two rows, showing what is available on the account:
- Email code. Always available, and there is nothing to configure. Esqase emails a 6-digit code to the account's address each time the client signs in that way.
- Google. Link Google connects a Google account so the client can use Continue with Google, and Unlink disconnects it. Linking only works when the Google account's email address is the same as the account's own address.
There is no password on a client account, so there is none to set, change, forget or leak. A client who unlinks Google still signs in with an emailed code, which means unlinking never locks anyone out.
📷 Screenshot: The Security tab showing the two Sign-in methods rows, with Google linked.
Sign out of other devices
One button signs the account out everywhere except the browser the client is using. It is the right answer to a lost laptop or a shared computer, and it takes effect within a minute on every other device. Like the other actions on this page, it asks the client to sign in again first if their session is more than a few minutes old, so an unattended browser cannot be used to lock the real owner out of their own devices.
Security emails
Esqase emails the account address whenever something on the account changes: a Google or Apple account is linked or unlinked, Face ID or fingerprint sign-in is turned on for a phone, the client signs out of their other devices, or a deletion is requested. Each email names what happened and tells the client what to do if it was not them. They are sent to the address on the account, not to your firm, and nobody at your firm is copied.
A client who receives one of these and does not recognise it should sign out of their other devices on this page, and unlink any Google account they do not recognise.
Delete account
The last section is the danger zone. Delete account opens a dialog that explains what happens, asks the client to type DELETE to confirm, and then schedules the deletion.
What deletion does:
- The account is scheduled for permanent deletion 30 days later, and the client is signed out everywhere.
- Signing in again within those 30 days cancels it. Nothing else is needed, and the client keeps everything.
- After 30 days the sign-in identity is permanently removed, along with the client's own portal settings, notification preferences and the devices registered for alerts.
What deletion does not do:
- Records your firm holds stay with your firm. Invoices, payments, documents, signed agreements, forms, meetings, messages and the audit trail are your firm's records, kept for the legal and accounting reasons every law firm keeps them. Deleting an Esqase account does not delete a case file, and it is not a request to your firm to erase anything.
- A client who wants records held by your firm changed or erased asks the firm directly, and the firm decides what its obligations allow. Point them at your own privacy policy for that.
Important: Deleting the account removes the way in, not the file. If a client asks for their data to be erased, treat that as a request to your firm, handled by your firm's own process, and separate from the button in their portal.
A client can also delete the account from the Esqase Client app, and the steps for both are on Deleting your Esqase client account.
📷 Screenshot: The Delete account dialog showing the 30-day explanation, the DELETE confirmation field, and the destructive button.
Security in the Esqase Client app
Security and privacy on the account screen holds the same controls and adds the phone's own:
- Unlock, a switch for Face ID, Touch ID or fingerprint sign-in, which also locks the app when the client comes back to it.
- Sign-in methods, with Email code, Google and, on an iPhone, Apple, each with Link or Unlink.
- Devices, which lists the phones signed in to the account, lets the client sign out any other phone, and turns off Face ID or fingerprint sign-in for a phone. Sign out of other devices is here too.
- Allow screenshots, on Android only, which blocks screenshots and screen recordings of the app when turned off.
Confirming it is you works the same way: a fresh emailed code, Google or Apple, never Face ID. See Signing in to the Esqase Client app.
Notifications
The Notifications tab is the per-type grid a client uses to choose how they hear from you: in the portal, as a push notification on a device, or by email. The choices are per person, not per firm, so they apply to every firm the client works with on Esqase.
Push needs the in-app channel, so turning in-app off for a type turns its push off as well. Full detail is on How clients get portal notifications.
Notifications in the Esqase Client app
Notifications on the account screen is the same grid, and a change in the app or on the web applies to both. Push there covers alerts on the phone as well as in the browser. Above the grid, the app says whether notifications are on for it on this phone, with Turn on notifications or Open settings when they are off. The notification history is Inbox on the account screen.
Appearance in the Esqase Client app
Appearance on the account screen chooses how the app looks on that phone: Same as device, the default, which follows the phone's light or dark setting, Light or Dark. The choice applies at once and stays on that phone. See The Esqase Client app.
Common questions
A client cannot get in. Can we reset something for them? No, and there is nothing to reset. A client signs in with a 6-digit code emailed to their own address, or with Google (or Apple, in the app on an iPhone), and all of them are theirs to do. If they cannot get in, check that the address on their contact record is the one they are typing.
A client deleted their account by mistake. Can we undo it? They can, and easily: ask them to sign in again within 30 days, which cancels the deletion. Nothing on your side needs to change, and your records were never affected.
Will a deleted account remove the client from our contacts? No. The contact record, and everything attached to it, is yours. If you also want the contact removed, do that in the dashboard as you would for anyone else.
How does a client get out of Settings? The back arrow beside the Settings heading takes them back where they came from. A client who opened Settings from a link, with nothing to go back to, lands on their list of matters instead.
Does a client have to have an account to work with us? No. Everything you send opens once the client proves the address on the record, and Esqase keeps an account behind the scenes for that address without the client filling anything in. Settings exist for clients who want Google sign-in, or control over their notifications.