HEYPASS · 2026-09-14.1
Privacy & data handling
How HeyPass handles your account, workspace and login-message data.
On this page
What we access
HeyPass receives the emails your mailbox rules forward to a dedicated application address. It checks the source account, sender authentication, validated login format and the approved member's active request. Existing separately authorised OAuth/IMAP connections can read candidate messages. New Google and Microsoft automatic connections are coming soon; forwarding does not grant general mailbox access.
Why and who receives it
Matching login codes are delivered only to the approved requester using the workspace's selected destination. Where separately configured, tested and enabled, sign-in links are claimed in the requesting HeyPass browser. HeyPass does not start a vendor login, keep vendor passwords or automatically log a user out of a vendor.
What HeyPass stores
We store your verified email, optional display name, workspace membership, application configuration, permissions, encrypted connection credentials when used, security-factor records and request/audit metadata. When configured, Stripe receives billing information entered on its hosted checkout and HeyPass stores the associated customer/subscription identifiers. No payment provider is contacted while billing is disabled. Authentication challenges are hashed. Received application mail bodies and login artifacts are not intentionally persisted in HeyPass application databases. A confirmed login format stores the application sender, redacted subject and login context, code shape or direct-link origin/path/query pattern, and revision as workspace configuration—not the full email, recipient or live URL token. These saved formats remain private to the workspace. HeyPass does not use them to train a model. They remain until replaced, removed or the application is archived. Change audits contain account/revision metadata, not the saved text. Database backups may contain older configuration until separately expired. Keep real secrets out of feedback.
Forwarded samples during setup
An owner can open a ten-minute learning window for a paused application after verifying its original inbox. The owner manually forwards one original login email from that inbox to the application's receiving address. HeyPass verifies the forwarding mailbox's signature and processes the sample in memory; quoted application headers are untrusted hints, not proof of application identity. The full sample and its code or tokenized link are not saved. A reduced redacted draft is held in memory until confirmation, cancellation, restart or expiry of that window. After authenticated format failures during forwarded-sample learning, connection tests or delivery, HeyPass may keep a structural preview for up to 24 hours: instruction categories, code lengths, link structure and formatting markers. Original prose, email addresses, codes, link tokens and attachments are omitted. Up to five previews per app account and 100 per workspace are retained. Owners can inspect, copy or delete these previews; they are excluded from member activity and monitoring exports. Content-free learning and receipt diagnostics follow the 24-hour retention policy. The owner reviews the detected fields before saving the format. Learning does not deliver the sample or enable access: a fresh original, authenticated forwarding test and explicit enablement are still required. The sender's mailbox and upstream mail providers may retain their own copies.
Retention in the application
Rejected-message metadata and deduplication records have a 24-hour maximum policy with maintenance margins. Request and security history has a 30-day policy. In-app links and forwarding-confirmation values expire in memory within five minutes and are cleared on use where applicable. Link claims are restricted to the requesting HeyPass session. This does not establish vendor-side browser binding or invalidate a link already revealed; the vendor controls its own token and session expiry. Feedback is retained for up to 30 days. Optional diagnostic summaries expire after seven days; queue tickets after fifteen minutes, with closed queue metadata retained for up to 24 hours. Billing webhook event identifiers are retained for 30 days. Active identity, configuration, ownership attestations and security-factor records remain while needed for the account; they are not covered by the message-history timer.
Assisted format learning
When enabled for a workspace, unfamiliar setup samples can be analyzed by DeepSeek after local sanitization. Only restricted instruction wording, credential shapes and link structure are sent; arbitrary words, personal details, addresses, codes and URL token values are removed. If sanitization cannot be completed, no request is made. DeepSeek receives no tools or authority to deliver credentials. Its own terms govern processing and retention, including processing in China; HeyPass does not promise zero provider retention or EU-only inference. Validated inactive proposals and content-free analysis records remain in HeyPass for up to seven days. For accounts not using adaptive login, the owner reviews a proposal, then a fresh authenticated application test and explicit enablement are still required, and everyday sign-ins do not invoke the model. Only configuration and controlled results are stored, not provider prompts or responses. Older backups can retain previous records.
Adaptive login
When adaptive login is enabled for a workspace, HeyPass learns each application's login email automatically. If a login email that arrives for an open request is not yet recognised, its wording is sent to DeepSeek, including at sign-in time. Before sending, HeyPass replaces codes, link tokens, email addresses, the account holder's name, IP addresses and other long numbers with placeholders. DeepSeek only identifies which placeholder is the login credential; HeyPass reads the value from the original, sender-verified email and checks it appears there verbatim. Password-reset, account-recovery and account-change emails are never delivered, whatever the model returns. HeyPass saves the learned format (wording anchors and credential shape), not the email. A format that works identically for two or more workspaces with different owners may be shared with other workspaces that use the same application. DeepSeek's own terms govern processing and retention, including processing in China.
Providers and inbox copies
The hosted setup uses Infomaniak for the application and Mailgun's EU region to receive forwarded login messages. Resend handles outgoing transactional delivery. Cloudflare can continue to provide DNS. HeyPass processes received message bodies in memory; this does not describe copies held in Mailgun's delivery queues, operational records or other providers' mailboxes. Provider retention is subject to their configuration and terms. Permanent receiving-address reservations retain the address and an opaque workspace identifier so an address is never assigned to another organization. Your source/destination email provider also handles messages. Cloudflare's email activity records may contain sender, recipient and subject metadata; a subject itself may contain a code. Resend may retain sent-message content. These providers' copies, recipient inboxes, backups and operating-system snapshots are outside HeyPass's in-memory deletion promise. We do not promise automatic deletion from someone else's inbox or exclusively Swiss processing.
Remembered sign-in
If you choose Stay signed in on a personal device, an essential authentication cookie can remember that browser for up to 30 days. We store hashed credentials, a browser label and creation, use and expiry timestamps; not a browsing history or a device fingerprint. Credentials rotate when restoring a session. Remembering does not bypass enrolled two-step verification after the protected session locks, and does not count as a fresh email verification for sensitive changes. You can revoke remembered browsers in Account security. Signing out forgets the current browser; expired device records and token history are removed by scheduled maintenance. Backups are subject to the separate backup policy.
What an owner can see
Owners see their workspace's members, access grants, application/source setup, request outcomes, security evidence and feedback submitted to the workspace. Members see only their own requests and granted applications. HeyPass's activity interface does not include email subjects, message bodies or code values. Support reports contain the text you choose to submit and a screen/account reference, not automatically captured mailbox content or browsing history. A member can optionally select a HAR file in the browser: only an allowlisted summary of HTTP methods, status numbers, durations and sizes is uploaded. Original URLs, headers, cookies, bodies and filenames are excluded. Summaries are encrypted in the workspace database and visible only to their submitter and the owner. Images and PDFs are not accepted.
Disconnect, revoke and delete
Owners can pause delivery, revoke individual/group access, archive an application and invalidate its receiving address. Delete the forwarding rule at the mailbox provider too; HeyPass cannot change that rule remotely. Existing OAuth connections can be disconnected and consent revoked at the provider. Previously delivered emails and existing vendor sessions cannot be recalled. Owners can schedule organisation deletion with a seven-day undo window after recent sign-in. Access is suspended immediately; undo does not restart requests or delivery. The maintenance process purges the active workspace directory and its central routing/membership records after the window; errors keep access suspended and are retried. A minimal workspace-ID/deletion-date tombstone remains to block reopening deleted workspaces in this identity store. Restoring older backups requires applying the deletion record first; backup erasure, provider copies, personal account deletion and a DPA still require operator coordination.
Google API data and Limited Use
For separately authorised Google API connections, use and transfer of Google API data must follow the Google API Services User Data Policy, including its Limited Use requirements. Mail data is used for the disclosed access-delivery feature, not advertising, resale, credit scoring or model training.
Optional application authenticators
Where enabled by the operator and workspace owner, an authorised owner can enroll an application's TOTP setup key separately from email forwarding. This long-lived key is encrypted in HeyPass storage and decrypted for code generation. It is not covered by the email in-memory retention promise. Pending enrollment expires after ten minutes; enrolled keys remain until removed or the workspace is deleted. Request/session metadata is retained for up to 24 hours with maintenance margins; security audit metadata follows the 30-day policy. Generated codes are returned only in the requesting browser, not sent by email or intentionally saved in the database or logs. Owners and requesters need recent personal MFA. Removing access stops future reveals, but cannot recall a copied code, invalidate a leaked key or terminate vendor sessions; rotate compromised keys at the vendor. Removing a key deletes active records, not older encrypted backups or snapshots, which require operator coordination. Owner confirmation records an attestation of a successful vendor test, not independently verified account ownership.
Account security
HeyPass uses access checks, signed ingress, sender validation and local tamper-evident audit records. You can enable an authenticator or passkey in Account security; enrolled factors are required when signing in. Keep access to your sign-in email and security factors private.
Product names belong to their owners. HeyPass is not affiliated with those providers.