{
  "slug": "hey",
  "category": "email-providers",
  "name": "HEY",
  "description": "Paid email service from 37signals with a screening-based inbox and its own apps. Works only through the HEY apps, without IMAP or POP3.",
  "website": "https://www.hey.com",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 32,
  "coverage": 100,
  "summary": "HEY scores 32 out of 100 (grade F) on the email providers criteria. It meets 5 of 19 criteria: no ads or data sales, tells users about requests, TLS configuration, security headers and custom domains. It partly meets independent audit, transparency report, encrypted mailbox storage and mail transport security. It does not meet open source, no trackers or telemetry, end-to-end encryption, open protocols, sign up without personal data, IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/email-providers/hey/",
  "markdown": "https://privacyratings.com/email-providers/hey/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://37signals.com/policies/privacy",
      "note": "The privacy policy describes web analytics and some third-party cookies for analytics and ad measurement."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.hey.com/faqs/#does-hey-serve-ads-or-sell-my-personal-data",
      "note": "Funded by subscriptions. No ads, and data is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.hey.com/security/external-audits/trail-of-bits-june-2020.pdf",
      "note": "Trail of Bits and Doyensec reviewed HEY before launch and the full reports are public, but they are more than three years old."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://37signals.com/policies/privacy",
      "note": "Publishes a policy for government data requests, but no request counts."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://37signals.com/policies/privacy",
      "note": "Affected users are notified before data is disclosed, unless legally prohibited or in some emergencies."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.hey.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.hey.com",
      "note": "Grade A+ (120/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.hey.com/security/",
      "note": "Not supported."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://www.hey.com/security/",
      "note": "Content is encrypted at rest and per field in the database, with keys HEY holds."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "no",
      "evidence": "https://www.hey.com/faqs/#can-i-check-my-hey-email-with-my-existing-email-app",
      "note": "Only the HEY apps work. IMAP and POP3 are not supported."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.hey.com/domains/",
      "note": "Available with HEY for Domains."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "no",
      "evidence": "https://www.hey.com/faqs/#what-if-i-forget-my-password",
      "note": "A backup email address is required at sign-up."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Not offered."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "partial",
      "evidence": null,
      "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT. Missing: DNSSEC, DANE none."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T10:59:44.784Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}