Legal · Last updated 25 September 2026
Cookie Policy
Contents
This Cookie Policy explains how Warmerly uses cookies and similar technologies, such as your browser's local and session storage, on our website, web app and documentation. Our Android app does not use cookies; it keeps your sign-in in the phone's secure storage.
What are cookies?
Cookies are small text files placed on your device by websites you visit. They allow the site to remember your preferences, keep you logged in, and understand how you use the service. Local and session storage do a similar job inside your browser; session storage is cleared when you close the tab.
Your choice
The first time you visit, a banner asks you to accept or decline non-essential cookies. Your choice is stored in a cookie (warmerly_cookie_consent, 1 year) and applies across the whole site, including the app and documentation.
Until you accept, nothing non-essential is stored on your device. If you decline, Google Analytics is instructed — via Google Consent Mode — not to store analytics or advertising cookies on your device. Strictly necessary cookies are still set, because the service cannot function without them. You can change your mind by clearing your cookies for this site, which brings the banner back. If you accepted and later decline, PostHog's storage is removed and Google Analytics stops using its cookies; to remove the other cookies already set, clear this site's cookies in your browser.
Global Privacy Control
If your browser or a browser extension sends a Global Privacy Control (GPC) signal, we treat that as a standing decline of all non-essential cookies — the same outcome as clicking "Essential only" on the banner — and we do not show you the banner at all, since your browser has already told us your choice. We record that decline in warmerly_cookie_consent, replacing any earlier acceptance. In that state, wm_ft and wm_vid are never written, and Google Consent Mode stays denied for analytics and advertising storage. You can read more about GPC at globalprivacycontrol.org.
Cookies we use
Strictly necessary (always set)
- warmerly_session: keeps you logged in. HttpOnly, Secure, SameSite=Lax. Expires after 30 days.
- warmerly_workspace: remembers which workspace you are currently working in. Expires after 1 year.
- warmerly_impersonator: set only when a Warmerly administrator is temporarily viewing an account for support purposes. Expires after 24 hours.
- warmerly_support_session: links your messages in the support chat widget to your conversation so replies reach you. Expires after 30 days, or after 1 year if you reopen a conversation from a link in one of our emails.
- warmerly_support_captcha: records that you passed the support chat's anti-spam check, so you are not challenged repeatedly. Expires after 24 hours.
- warmerly_cookie_consent: stores your answer to the cookie banner. Expires after 1 year.
- warmerly_theme: set only if you choose a theme with the light/dark switch, and remembers that choice (light, dark or match your system) across the website, the app and the documentation. Expires after 1 year.
Our network and security provider, Cloudflare, may also set a short-lived security cookie (such as __cf_bm) to tell people from automated traffic, and the support chat's anti-spam check is provided by Cloudflare Turnstile. These are used only for security.
Analytics and attribution (only if you accept)
- _ga, _ga_* (Google Analytics 4, set by Google LLC): measure page views and which pages lead to sign-ups, so we can see what is worth improving. Typically expire after 2 years. Accepting grants analytics storage only: Google's advertising consents stay switched off, and we do not use Google's advertising features. Data may be processed outside the UK/EEA under the Standard Contractual Clauses.
- ph_*_posthog (PostHog, set by PostHog Inc. on our behalf; a cookie, a copy in local storage, and a per-tab entry in session storage) and __ph_opt_in_out_* (records that you accepted): a random identifier that links your visits together, so we can see how the product is used, which errors people run into, and replay sessions to fix problems. If you are signed in, it is linked to your account. Expires after 1 year. Data is processed in the United States under the Standard Contractual Clauses.
- wm_ft (set by us): records where you first arrived from — campaign parameters in the link you clicked, the referring site, the Google click identifier, and your Google Analytics identifier — so we can tell which marketing actually works. Expires after 30 days.
- wm_vid (set by us): a random identifier that links the pages you view into a single visit, so we can see which content actually helps people and which leads nowhere. It holds no personal details and is never shared with anyone else. Expires after 12 months. If you choose "Essential only", this cookie is never written — we still count page views on our own servers without it, as described in section 6 of our Privacy Policy, but without storing anything on your device.
We do not sell your personal data, and we do not use these cookies to build advertising profiles beyond measuring the performance of our own marketing.
Browser storage (only if you accept)
These are not cookies, but they are stored on your device in the same way and we treat them under the same rules — if you choose "Essential only", or your browser sends a GPC signal, none of them are written and the features below simply forget between page loads instead.
- warmerly:cta-popup (local storage, set by us): remembers that you have already seen or dismissed the sign-up prompt on our marketing pages, so you are not shown it again for 7 days — or ever again, once you have clicked through to the sign-up form.
- warmerly:warmi-nudge (session storage, set by us): remembers that Warmi, our chat assistant, has already offered to help during this visit, so it only offers once. Cleared when you close the tab.
- warmerly:free-mailbox-announce (session storage, set by us): remembers that you closed the free-mailbox announcement, so it stays closed for this visit. Cleared when you close the tab.
Browser storage that remembers something you did
These are set by us, only to remember something you did or something we have already shown you, so the site works the way you left it. They are never sent to anyone, including us, and are not used for analytics.
- warmerly_support_conversation_id (local storage) and warmerly_support_chat_pos (session storage): keep your support conversation open across pages, and remember where you moved the chat window.
- warmerly:signup-draft (session storage): keeps the name and email address you have typed into the sign-up form if you leave the page and come back. Never your password. Cleared when you close the tab.
- warmerly_android_app_prompt_dismissed and warmerly_mascot_polish_banner_dismissed (local storage): remember that you closed a prompt or announcement on our home page.
- Inside the app, a few interface settings: dismissed banners and introductions (warmerly.planLimitBanner.dismissedOn, warmerly.leadsIntro.seen.v1, warmerly.leads.introCollapsed, warmerly.onemail-banner-dismissed, warmerly_changelog_modal_shown_for), which assistant animations you have seen and whether you prefer fewer of them (warmi:seen, warmi:reduced), the results of the website summary tool you ran (warmerly:website-summary-runs:v1), and whether an email search you started is still running (wf-finding-emails-*, session storage).
Measuring our own pages without cookies
Separately from the above, we count how often each call-to-action on our marketing pages is clicked — for example "the sign-up button in a blog post" versus "the one in the page footer" — so we can tell which parts of the site are useful. This counting happens on our own servers and is entirely anonymous: we record only a date, the name of the button, and a broad section of the site such as "blog". No cookie or browser storage is involved, nothing is stored on your device, and nothing recorded identifies you, your device or your visit — the records are counts, not events, and cannot be traced back to any individual. For that reason it does not require your consent and it runs whatever you choose on the banner.
If you go on to create an account, we also record which of those buttons brought you to the sign-up form. That travels in the web address you follow rather than in anything stored on your device.
Our servers also record the pages viewed on our website and in the app, without storing anything on your device, as described in section 6 of our Privacy Policy.
Product analytics without cookies
If you choose "Essential only", have not yet answered the banner, or your browser sends a GPC signal, we still measure how the site is used and record errors it runs into, through PostHog, so we can fix problems and improve the product. In that case nothing is stored on your device. Instead, PostHog links the pages of your visit using a code it calculates on its servers from technical details of your connection, which changes every day, so visits on different days are never linked to each other. Your identity is not attached and no session is recorded.
The Google Analytics script also loads on every page. Until you accept, Consent Mode tells it not to read or write any cookie; Google may still receive basic signals without identifiers, which it uses only for aggregate measurement.
Managing cookies
Beyond the banner, you can block or delete cookies and site data in your browser settings. Blocking strictly necessary cookies will prevent you from logging in. You can also opt out of Google Analytics specifically using Google's browser opt-out add-on.
Changes
We will post any updates to this Cookie Policy on this page and update the date above.
Contact
Questions? Email hello@warmerly.com, or privacy@warmerly.com for privacy requests.



