Terms of service
Last updated 13 August 2026
These terms are an agreement between you and HeyPass. By creating an account or forwarding mail to us, you accept them. If you are agreeing on behalf of an organisation, you confirm that you are permitted to bind it.
1. What HeyPass does
HeyPass receives email forwarded from a mailbox you control, identifies verification codes, sign-in links and browser approval requests inside it, and delivers each one to the single person in your organisation who requested it. It keeps a record of who requested what, and removes the rest.
HeyPass is not a password manager, an identity provider or a security control. It does not store your passwords and it does not protect your accounts. It relays a verification artifact and records that it did so.
2. Your account
You must be 18 or older and using HeyPass on behalf of an organisation rather than as a private individual. You are responsible for everything done under your account, for keeping your own credentials safe, and for removing people who no longer need access.
3. The mailbox you connect
You may forward mail only from a mailbox your organisation owns and controls. You confirm that you are entitled to do so, that forwarding it breaches no agreement or duty you owe to anyone, and that you have informed whoever needs to know.
You can stop forwarding at any moment from your own mail settings. Our permission is not required and we cannot prevent it.
4. Acceptable use
This section matters more than the rest. HeyPass moves credentials, so misuse causes real harm to real people.
Never use HeyPass for any of the following
- Financial accounts. Banking, payments, brokerage, lending, insurance, crypto exchanges or wallets. No verification code from a financial institution may be routed through HeyPass, by anyone, for any reason. We block sender domains identified as belonging to financial institutions, and we do not treat that as a defect.
- Health data. Medical records, patient portals, insurance claims, prescription services, or anything constituting protected health information. HeyPass is not HIPAA compliant, has not been assessed for it, and will not sign a business associate agreement.
- Government and identity systems. Tax portals, immigration or visa systems, national identity schemes, benefits systems, court or law enforcement systems, or anything issuing or verifying a government credential.
- Payment card data. HeyPass is not PCI DSS assessed. Keep cardholder data away from it.
- Accounts you do not control. Any account belonging to another person or organisation, whether or not you hold the password, and whether or not you were told it was fine.
- Personal accounts. An individual's own email, social, banking, health or shopping accounts, including your own. HeyPass is for accounts an organisation holds.
- Reselling access. Renting, reselling, brokering or otherwise commercialising access to a shared account, including group buys and account sharing services.
- Circumventing another provider. Working around a restriction, seat limit or term imposed by a service you do not own.
- Defeating someone else's security. Bypassing multi-factor authentication, device verification or any other control protecting an account that is not yours.
- Minors. Any account belonging to or operated by a person under 18.
- Unlawful or abusive activity. Fraud, phishing, spam, harassment, stalking, or anything illegal where you or the affected person is located.
If you are unsure whether something falls inside this list, treat it as though it does and write to us first.
Also not permitted
- Sharing one HeyPass member account between several people. Each person has their own.
- Automating, scraping or reverse engineering the service, or probing it for vulnerabilities without written permission. Responsible disclosure to hello@heypass.io is welcome and will not be treated as a breach.
- Uploading malware, or using HeyPass to distribute anything harmful.
- Presenting HeyPass as your own product, or implying that we endorse you.
5. Your accounts with other services
Whether you may share an account with your team is a matter between you and that provider, governed by your agreement with them. HeyPass makes an organisation's own shared accounts tidier and auditable. It does not make an arrangement permitted that your provider prohibits, and we make no representation that any particular sharing arrangement is allowed. Read your agreements. We cannot read them for you.
Product and company names appearing in HeyPass or on our website belong to their owners. HeyPass is not affiliated with, endorsed by or sponsored by any of them.
6. Plans and payment
The free plan costs nothing and is not a time limited trial. We may change what it includes, and if we reduce it we will tell everyone on it first and give reasonable notice.
Paid plans are not yet available. When they are, prices, billing terms and refund rules will be published before anybody is charged, and no existing user will be charged without agreeing first.
7. Your data
How we handle personal data is set out in the privacy policy. In short, verification artifacts are held only while valid, a request record is kept for you, and every other message is deleted automatically within 24 to 48 hours. Your content remains yours and we claim no ownership of it.
8. Availability
HeyPass is early software. It may be unavailable, delayed or wrong. Verification codes may arrive late or not at all, so keep an alternative route into every account you depend on.
The service is provided as is, without warranty of any kind, express or implied, including any warranty of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that it will be uninterrupted, timely, secure or error free.
9. Suspension
We may suspend or close an account immediately, without notice, if we believe it is being used in breach of section 4. Given what this product moves, we act on reasonable suspicion rather than waiting for proof, and we would rather be wrong occasionally than slow once.
You can close your account at any time. Stop forwarding mail and write to hello@heypass.io, and we will delete your data.
10. Liability
To the maximum extent the law allows, HeyPass is not liable for indirect, incidental, special or consequential loss, or for lost profits, revenue, data or goodwill, however caused.
Our total liability arising from these terms is limited to the greater of the amount you paid us in the twelve months before the claim, or one hundred United States dollars. On the free plan that means one hundred dollars.
Nothing here excludes liability that cannot be excluded by law, including for fraud or for death or personal injury caused by negligence.
11. Indemnity
You will cover us against claims, losses and reasonable legal costs arising from your use of HeyPass in breach of these terms, in particular any breach of section 4.
12. Changes
We may update these terms. For material changes we will email account holders at least 14 days before they take effect, rather than quietly editing the date at the top. Continuing to use HeyPass after that means you accept them.
13. Governing law
These terms are governed by the laws of the State of Wyoming, United States, without regard to its conflict of law rules. Disputes will be brought in the state or federal courts located in Wyoming, and both sides consent to that jurisdiction.
14. Contact
For anything at all, including security reports and privacy requests, write to hello@heypass.io.