Help › Account and privacy › Security
Security: who can see your data
Heft reads your bank account and your mailbox so it can find the receipt for every payment. Here's what Heft never does, who can see your data, and how you stay in control.
Updated 8 Oct 2026
What Heft never does
- Move money
- Bank accounts and Revolut are connected read-only. You make payments yourself.
- Send or delete mail
- Gmail is connected read-only. Heft can't send, delete or move anything in your mailbox.
- Read accounts you don't pick
- When you connect, you choose which accounts belong to the company. Heft never reads any other account, including your private one.
- Send anything without you
- Letters to others, such as cancelling a subscription, can only be sent by a person, never by Heft alone. They go out from Heft's address, with you in copy.
Who can see your data
- Heft support
- Only if you grant it, as the owner or a director. Support can then read but change nothing, for 30 days at most. You can end the access early at any time.
- Anyone else at Heft
- Nobody looks at your data. Technical access to the servers exists only for maintenance and emergencies.
- Your team
- Each member sees what their role allows. An assistant helps match receipts but can't lock a month or change access.
- Your tax adviser
- They see and work on only what their mandate covers, such as bookkeeping or VAT. They can never change access or your company details.
How you find out
When someone or something gets access, whether a member, a tax adviser, an AI agent or a login for a supplier portal, the owner and directors get a push notification and an email straight away. The message names only the kind of access, so nothing confidential shows on a lock screen. You see who it is in the app.
What Heft itself does is listed under Activity, each with Undo.
Approving with a passkey
A passkey replaces your password. You sign in with Face ID, your fingerprint or your device's screen lock; your face or fingerprint never leaves your device.
You approve important steps the same way, such as connecting a bank or a mailbox. Heft first shows you in words what you're approving, and stores your approval together with that exact text. So it can always be shown later who approved what.
A new passkey can approve anything only after 24 hours, unless you confirm it with a passkey you already have.
Encryption and login details
Every connection to Heft and between Heft's services is encrypted, and stored data is kept encrypted on Google Cloud.
Login details, such as Revolut's read-only access or a supplier-portal login, get an extra layer: Heft encrypts them with a key of their own, kept apart from the database. A copy of the database can't open them.
Heft uses a supplier-portal login only to fetch invoices there: in a fresh, sealed-off browser that can reach only that portal and is deleted afterwards.
If your phone is gone
Under Settings › Account you see every signed-in device and can sign each one out, or tap Sign out everywhere. That's also where you remove a passkey.
If you've lost all your passkeys, you recover your account by email. That takes 24 hours, and the owner and directors are told straight away. If someone signs in with your passkey in the meantime, the recovery is cancelled. So taking over your mailbox alone doesn't get anyone into your company right away.
Disconnecting
Under Settings › Connections you disconnect your bank, Gmail or Revolut at any time. After that Heft reads nothing more there. Bank access also ends on its own; the app shows you when.
Where it's processed
Everything runs in the EU: your data on Google Cloud in Frankfurt, the AI models on Google Cloud in the EU and on AWS in Frankfurt. None of it is used for AI training.
Found a security issue? Write to support@namequick.app.
Data and privacy