Promptwatch Logo

HEY Email Privacy Proxy

HEY email stops spy pixels and prevents user IP tracking by proxying all HTML email images, fonts, and external assets.
37signalshey.com
Preview

What is HEY Email Privacy Proxy?

When a HEY user views an email that contains an external image, 37signals can fetch that image through the HEY Email Privacy Proxy. The image host sees HEY's request instead of the reader's IP address, which prevents the host from learning the reader's network location or directly tying the fetch to that person's device.

HEY's image-proxy documentation says the service requests only image URLs referenced in viewed emails. It does not crawl websites, follow page links, execute scripts, or index content. It caches successful responses, follows redirects to the final image, honors HTTP cache headers, and rejects responses that are not image content.

The full recorded user agent starts hey.com/imageproxy, while this directory uses the broader stable token hey.com. Cloudflare does not mark the client as following robots.txt, and the bot metadata leaves compliance unknown. The record also has no verified IP status or signature-agent URL. A matching header identifies the claimed proxy but should not grant access to private image URLs.

This proxy protects email privacy; it is not an AI crawler. Its requests do not improve AI search visibility, create citations, or supply a documented training dataset. They also should not be treated as ordinary email-open analytics because the recipient's address is hidden and cached images can serve later views without another origin request.

Indirectly relevant

Is HEY Email Privacy Proxy relevant for AI search?

Indirectly. HEY Email Privacy Proxy has no AI product of its own, but its output can end up in the systems that AI answers draw on.

HEY Email Privacy Proxy fetches pages to build link-preview cards. It does not feed an AI index, but it reads the same Open Graph and structured metadata that AI systems parse to understand your pages, so clean preview metadata doubles as AI-friendly metadata.

How to handle HEY Email Privacy Proxy

Allow public email images if HEY recipients should see them, and send accurate Cache-Control, ETag, or Last-Modified headers so the proxy can reuse responses. Do not put secrets in an image URL or assume that an unguessable path replaces authorization.

The stable token supports this policy notice:

User-agent: hey.com
Disallow: /

Robots compliance is unconfirmed in the bot metadata and marked false by Cloudflare. Since the proxy requests explicit email assets rather than crawling, enforce any denial at the image host, CDN, or application. Expect blocking to remove remote images from HEY messages rather than stop a page preview.

Examples

  • A HEY user opens a newsletter, and the proxy retrieves its banner image without exposing the reader's IP address to the newsletter host.
  • HEY identifies a one-pixel tracking image and removes it, so the sender's server receives no request for that tracker.
  • Several later views use HEY's cached copy of a product image, leaving the origin with one proxy request rather than a reliable count of opens.

Frequently asked questions about HEY Email Privacy Proxy

Learn about AI visibility monitoring and how Promptwatch helps your brand succeed in AI search.

37signals operates the proxy as part of the HEY email service.

Be the brand AI recommends

Monitor your brand's visibility across ChatGPT, Claude, Perplexity, and Gemini. Get actionable insights and create content that gets cited by AI search engines.

Promptwatch Dashboard