Security and data
HeyPass receives the messages selected by your forwarding rules, which may include their full contents and headers. Review what each workspace role can see and how long this information is retained before continuing.
What arrives
The messages selected by your forwarding filters, with their headers. HeyPass processes raw email in memory and may retain a redacted structural preview after a format failure.
Who gets what
The person who asked gets that one code in their own inbox, or the link once in their HeyPass tab. Admins see the record of each request.
How long
Failed-format previews expire within 24 hours. Rejected-mail metadata has a 24-hour policy, and request history a 30-day policy. Saved formats remain as configuration. Upstream providers have their own retention policies.
Assisted learning
When enabled, DeepSeek helps identify unfamiliar login formats from sanitized wording, including during sign-in for adaptive accounts. HeyPass removes credentials and personal identifiers first and checks the result locally. Processing may occur in China; zero provider retention is not promised. Details are in the Product Privacy Notice.
How to stop
Turn off the rule in your mail provider, then remove the mailbox in HeyPass.
Controls in the product
Owners can add a second step
A passkey or an authenticator app protects owner actions. Email codes do not count as a second step.
Each mailbox is verified
An 8-digit code goes to the mailbox before HeyPass accepts any mail from it. Mail from an unverified mailbox is rejected and never delivered.
Forwarded mail must be signed
HeyPass accepts only mail carrying the service’s own valid email signature, checked directly or through Gmail or Outlook’s forwarding seal.
Checks for sensitive actions
Identified reset, recovery and change-of-email messages are rejected. Unsupported or ambiguous formats stop for review.
One verified inbox per person
A code is sent only to the email a member signs in to HeyPass with. Admins cannot redirect it to another address.
Financial senders are blocked
HeyPass blocks known financial senders and payment-confirmation emails, with no override.
HeyPass never asks for
A mailbox password for the forwarding setup
The password for any service
Your phone number
Your date of birth
Found a security problem?
Write to hello@heypass.io with the subject “HeyPass security report”. Do not include a live code, a sign-in link or a forwarded email.