Legal · Last updated 24 September 2026
Privacy Policy
Contents
- 1. Information we collect
- 2. How we use your information
- 3. Automated processing and AI
- 4. Access by our staff
- 5. Google and Microsoft mailbox data
- 6. Why we use your data, and our lawful basis (UK GDPR / EU GDPR)
- 7. Data storage and security
- 8. Data retention
- 9. Who we share data with, and international transfers
- 10. Your rights
- 11. Cookies
- 12. Children
- 13. Changes to this policy
- 14. Contact
This Privacy Policy explains how Warmerly ("we", "us") collects, uses, and protects information about you when you use our website, our web and mobile apps, and our services.
Data controller: Warmerly, a sole trader based in the United Kingdom. Full operator details are on our Trust page. Contact for anything in this policy: privacy@warmerly.com.
If you are not a Warmerly customer and we hold data about you because you appear in our business-contact database, the notice that applies to you is our Prospect Privacy Notice. If you are a resident of California or another US state with a comprehensive privacy law, see our US State Privacy Notice for the categories/disclosure table and rights specific to those laws.
1. Information we collect
We collect the following categories of information:
- Account data: your name, email address, hashed password (or the fact that you sign in with Google or Microsoft), workspace and team membership, role, notification preferences, and billing details.
- Mailbox connection data: when you connect a mailbox, we store encrypted OAuth refresh tokens or encrypted IMAP/SMTP credentials, together with metadata such as the mailbox address, provider, and folder structure.
- Mailbox contents: where you use the Warmerly inbox, we periodically read your connected mailbox and store the messages we find — sender and recipient addresses, subject, message body (plain text and HTML), attachment metadata, and threading headers. This covers your Inbox and your Sent folder. It includes ordinary business mail that has nothing to do with Warmerly, because that is what an inbox contains.
- Warmup mail: the conversational messages Warmerly generates and exchanges between mailboxes in the warmup network. Connecting a mailbox to the warmup network means that mailbox's address, display name, and signature are visible to the other participating customers' mailboxes it exchanges mail with, because that is how the network functions — it is not a one-way simulation, it is real mail sent between real customer mailboxes.
- Campaign data: the outreach sequences you build, the recipient lists you upload or select, the messages sent, and engagement events (delivery, opens, clicks, replies, bounces, unsubscribes).
- Other channel data: where you connect LinkedIn, WhatsApp, or Instagram accounts, the messages and contacts on those accounts that are synced into the Warmerly inbox, together with the connection credentials held by our integration provider.
- Business contact data: information about companies and business contacts held in our lead database, used by the lead finder and email finder. See the Prospect Privacy Notice.
- Support data: messages you send us through the in-app support chat or by email, including anything you choose to include in them.
- Usage data: IP address, browser and device type, pages viewed, actions taken, errors, and timestamps, collected via server logs, product analytics and session replay.
Features that handle data in their own way
- Mobile app. The Android app uses the same account and shows the same data as the web app. It keeps your sign-in securely on the device. If you allow notifications, we store a push token for your device and send notifications — for example when a prospect replies — that can include the sender's name or address and a short preview of the message. Notifications are delivered through a push-notification service and Google's Android push service. You can turn them off in the app's settings or your phone's settings, and signing out stops them. The app contains no third-party advertising or analytics code.
- Hosted mailboxes. Where you buy a mailbox from us, or use the free mailbox every new account is given, we create and run that mailbox on our own mail servers. We therefore hold its address, its sign-in credentials (encrypted), and the mail sent and received through it.
- Transactional email API. If you send your application's email through our API, we process the sender and recipient addresses, the subject, and the message you submit, and keep a delivery record for each message (whether it was accepted, delivered, deferred or bounced, and the receiving server's response). The message body is held only while the message is being delivered. Addresses that hard-bounce are suppressed automatically. For this mail you are the controller of your recipients' data and we act as your processor.
- Connected apps. You can let an AI assistant or other app act on your workspace through our authorisation flow. We record which app you authorised, what it may access, and when; we store only one-way hashes of the access tokens. The app receives the data it asks for on your behalf, and its own privacy terms govern what it does with it. You can revoke access at any time.
- Support chat (Warmi). Warmi is an AI assistant that answers support questions on our website and in the apps, and may also answer email sent to our support address. We keep the conversation so it can continue across pages and so a person can pick it up if needed. Where you are signed in, Warmi can see information about your account and workspace in order to answer. A short anti-spam check may run before you can send a message.
- Website and app analytics. We record the pages viewed on our website and in the app, in the way described in section 6. If you accept analytics cookies, we also use product analytics and session replay — a recording of how pages are used, including clicks, scrolling and what is displayed — to find and fix problems. Session replay does not run unless you accept. Errors that occur in your browser or on our servers are recorded whether or not you accept, without storing anything on your device.
- Where you came from. When you create an account, we record how you reached us: the site that referred you, the page you arrived on, any campaign details in the link you followed, your answer to "how did you hear about us", and — only if you accepted cookies — the details held in our attribution cookie. When you sign up or sign in, we also link your earlier page views on that device to your account, so we can see which pages helped.
Where we get data from
Most of what we hold comes from you. The rest comes from:
- the mailboxes and messaging accounts you connect, and the people who write to them;
- other customers' mailboxes in the warmup network;
- Google or Microsoft, if you sign in with them (your name and email address);
- a colleague who invites you to a workspace (your email address);
- our payment provider (payment status, and the billing details you give it);
- your browser and device, automatically, as described above and in our Cookie Policy;
- public sources, for the business-contact database (see the Prospect Privacy Notice).
2. How we use your information
- To provide the services you signed up for — warmup, inbox, campaigns, deliverability testing, and lead discovery.
- To send service and relationship mail (see below).
- To send you marketing about Warmerly, where you have opted in. You can withdraw at any time using the unsubscribe link in any such message.
- To understand how the product is used, fix errors, and improve it, including through aggregated or de-identified statistics that do not identify you.
- To detect and prevent abuse of the platform, including spam, fraud, and security incidents.
- To comply with legal obligations.
Service and relationship mail is not marketing. Once you have an account, running the service necessarily involves sending you mail about it. This includes:
- Deliverability and sender-health reports — warmup progress, inbox placement results, and reputation summaries for mailboxes you connected.
- Blocklist and DNS alerts — a connected domain or mailbox failing authentication (SPF/DKIM/DMARC), a blocklist listing, or a mailbox disconnecting.
- Onboarding sequence and setup emails — guidance while you get set up and milestone check-ins on your account.
- Billing notices — receipts, failed-payment and dunning emails, and plan-change confirmations.
- Account, security, and workspace mail — sign-in codes, verification, password resets, and team invitations.
- Replies to support requests you raised, and AI-lead digests summarising activity in your own inbox.
These arise from the contract we have with you as a customer, not from marketing consent, so they are not subject to opt-in and are not affected by declining marketing cookies. This is legally and practically distinct from marketing and broadcast mail — product announcements, guides, and offers — which is sent only to people who have opted in and always carries an unsubscribe link. Most of the mail above is genuinely optional and can be turned off individually from Settings → Notifications in the app (mailbox alerts, lead digests, and setup tips each have their own toggle); account, security, and billing mail cannot be turned off because it keeps the service and your account working.
Stopping marketing. You can stop marketing email at any time, free of charge, with the unsubscribe link in any marketing message or by emailing privacy@warmerly.com. We keep a record that you opted out so that it keeps being honoured.
3. Automated processing and AI
Several Warmerly features are built on large language models supplied by third parties. Specifically, we send data to an AI provider in order to:
- classify messages in your inbox as leads, not relevant, or spam — this sends the sender address, the subject, and an extract of the message body;
- draft suggested replies to messages in your inbox;
- generate personalised opening lines and message content for your campaigns, which involves the recipient's details and publicly available information about their company;
- power the support chat assistant.
AI processing produces output for you, inside your workspace. We do not use your content to train our own models, and we do not permit our AI provider to train on data submitted through our account. The providers we use are listed in our Data Processing Agreement.
We also use automated checks to protect the service and the people our customers write to — for example, pausing a mailbox or campaign whose bounce rate or sending reputation becomes unsafe, limiting activity beyond what a plan allows, and our payment provider's fraud screening of payments.
None of this processing produces decisions with legal or similarly significant effects about you within the meaning of Article 22 UK/EU GDPR. Classification and drafting are suggestions; you remain in control of what is sent. If an automated check affects your account and you disagree with it, contact us and a person will review it.
4. Access by our staff
Warmerly administrators can, for support and abuse-investigation purposes, temporarily access a customer workspace, including the inbox. This is audit-logged, time-limited, and indicated in the interface while it is happening. We do this only where it is necessary to resolve a problem you have raised, or to investigate a credible abuse report.
5. Google and Microsoft mailbox data
Warmerly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Warmerly's use of information received from Microsoft APIs adheres to the Microsoft Identity Platform terms.
In plain terms: mailbox data obtained through these APIs is used to provide the features you have turned on — warmup, inbox sync, inbox classification and reply drafting, and campaign sending — and for no other purpose. It is not used for advertising, it is not sold, it is not used to train generalised AI or machine-learning models, and it is transferred to third parties only where necessary to provide those features (our hosting provider, and our AI provider for the classification and drafting features described in section 3), to comply with law, or as part of a merger or acquisition.
Human access to this data is limited to the circumstances in section 4, to what you explicitly ask us to look at, and to what is required for security or to comply with law.
6. Why we use your data, and our lawful basis (UK GDPR / EU GDPR)
| Purpose | Lawful basis |
|---|---|
| Creating and running your account and workspace, and providing the features you use: warmup, the inbox, campaigns, the lead and email finder, hosted mailboxes, the transactional email API, the mobile app and its notifications, and connected apps. | Contract — this is the service you signed up for. |
| Taking payment, issuing invoices, and handling refunds and disputes. | Contract; and legal obligation for the tax and accounting records we must keep. |
| Service and relationship mail — account, security, billing, alerts, reports and setup guidance (see section 2). | Contract for mail the service needs to work. Legitimate interests for optional mail such as setup tips and digests: helping you get value from what you pay for. Each optional type can be switched off. |
| Marketing email about Warmerly. | Consent. You can withdraw it at any time with the unsubscribe link in any such email. |
| Answering support requests, including through the Warmi support chat. | Contract where you are a customer. Legitimate interests where you are not: answering questions from people considering the service. |
| The AI features described in section 3. | Contract — they are features of the service, and they run only on the data in your own workspace. |
| Keeping the platform secure and preventing spam, fraud and abuse, including keeping addresses that have bounced or asked not to be contacted from being mailed again. | Legitimate interests: protecting our customers, the people they write to, and the sending reputation the whole service depends on. Legal obligation where the law requires it. |
| Understanding how our website and app are used, finding and fixing errors, and learning which pages and channels bring people to us — using the measurements that store nothing on your device. | Legitimate interests: running and improving our own website and product. It is a modest and expected use, and you can object at any time. |
| Analytics and advertising-attribution cookies, and product analytics with session replay that stores data on your device. | Consent, given through the cookie banner. You can withdraw it at any time — see our Cookie Policy. |
| Staff access to a workspace for support or to investigate abuse (section 4). | Legitimate interests: resolving the problem you raised, or stopping abuse of the platform. |
| Maintaining our business-contact database. | Legitimate interests — see the Prospect Privacy Notice for the balancing test. |
| Complying with the law, responding to lawful requests, and establishing or defending legal claims. | Legal obligation; and legitimate interests in protecting our legal position. |
| Selling or transferring all or part of the business. | Legitimate interests: allowing the business to be sold or reorganised while the service continues for you. |
Where we rely on consent, you may withdraw it at any time; that does not affect processing that took place before you withdrew. Where we rely on legitimate interests, we have weighed them against your rights and expectations, and you can ask us for more detail or object (section 10).
Site analytics. We record which pages are visited on our website and inside the app, so we can see which content and features actually help people. This runs on our own servers and stores nothing on your device, so it is not a cookie and does not depend on the cookie banner. We do not store your IP address or your browser's user-agent string: they are combined into a one-way cryptographic value that groups a visit together and cannot be reversed to identify you, and that value is regenerated every 30 days so it cannot build up a long-term profile. If you are signed in, the pages you view in the app are recorded against your account. If you accept analytics cookies, we additionally use the wm_vid cookie described in our Cookie Policy to do the same thing more accurately. We rely on legitimate interests for the server-side part: understanding how our own site is used is a modest and expected purpose, we hold no directly identifying data for anonymous visitors, and you can object using the contact details in section 14.
Do you have to give us your data? No law requires you to. Your name, email address and a way to sign in are needed to create an account, and billing details are needed for a paid plan; without them we cannot enter into or perform our contract with you. Anything else — connecting a mailbox, uploading contacts, answering how you heard about us (which you can answer "prefer not to say") — is up to you, and only means the related feature is unavailable if you choose not to.
Where you use Warmerly to process other people's data — your campaign recipients, your imported lists, the contacts in your mailbox, the recipients of your transactional email — you are the controller of that data and we act as your processor. Our DPA governs that relationship, and you are responsible for having a lawful basis to contact those people. If you are one of those people, please contact the Warmerly customer who holds your data; if you contact us instead, we will pass your request to them.
7. Data storage and security
We use technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption at rest of mailbox credentials and tokens, hashed passwords, and access to production systems that is restricted to those who need it and logged. Our infrastructure is hosted in the UK and the EEA; see section 9 for transfers outside them. No method of transmission or storage is completely secure, so while we work to protect your data we cannot guarantee its absolute security. If a breach affects your data in a way that is likely to put you at high risk, we will tell you without undue delay.
8. Data retention
We keep personal data only for as long as we need it for the purposes above:
- Your user profile (name, email address, sign-in details): kept while you have an account. If you ask us to close it, we delete it, subject to the exceptions below.
- Workspace data — connected and hosted mailboxes, synced mail, campaigns, contacts you have added, transactional email records, settings and the billing record linked to the workspace: kept while the workspace exists. When a workspace is deleted, it can be restored for 30 days after the deletion takes effect, and is then permanently deleted.
- Tax and accounting records: kept for as long as the law requires (currently 6 years under UK law).
- Mailbox tokens and credentials: deleted immediately when you disconnect a mailbox.
- Mailbox contents synced into the Warmerly inbox: deleted when the mailbox is disconnected (and in any case within 30 days), or with the workspace when it is deleted.
- Hosted mailboxes: once a hosted mailbox is cancelled or its free period ends, the mailbox and its mail are kept for a 30-day recovery window and then deleted.
- Warmup activity logs: 12 months, then deleted.
- Marketing site analytics records: 12 months, then deleted.
- In-app activity records: 90 days, then deleted.
- Product usage records — a dated record of actions taken in the app, such as connecting a mailbox or launching a campaign, used to understand where the product works and where it does not: 24 months, then deleted. These records hold no message content and no contact details.
- Product analytics, error reports and session replays held by our analytics provider: deleted automatically at the end of that provider's retention period for our account.
- Campaign records and engagement events: retained while the campaign exists, and deleted with the workspace.
- Support conversations: kept for as long as they may be needed to help you with the issue and any follow-up, and while your account exists.
- Security and audit logs, and records of privacy requests: kept for as long as they are needed to protect the service, investigate incidents, and show that we have met our legal obligations.
- Suppression records: addresses that have hard-bounced, or whose owner has asked us to erase them, are kept on our platform-wide suppression list indefinitely — deleting the record that someone opted out would risk them being contacted again. A workspace's own unsubscribe list is kept for as long as the workspace exists.
We may keep data for longer where the law requires it, or where it is needed to establish or defend a legal claim, and only for as long as that need lasts.
9. Who we share data with, and international transfers
We do not sell our customers' personal data. We share it only with:
- the service providers listed on our Sub-processors page, who run parts of the service for us — hosting and network, payments, email delivery, AI processing, analytics, and messaging integrations — under contracts that limit them to acting on our instructions;
- other customers in the warmup network, to the extent described in section 1;
- apps and integrations you choose to connect;
- professional advisers, insurers, banks and payment providers, where needed;
- police, regulators, courts and other authorities, where the law requires it or it is needed to protect people or the service;
- anyone you ask us to share it with; and
- a buyer or successor if all or part of the business is sold or transferred, in which case this policy continues to apply to it.
Some of our service providers are outside the UK and EEA — in particular our AI provider, our payment provider's group, our analytics provider, our email delivery provider, and some integration providers, several of them in the United States. Where personal data is transferred outside the UK/EEA, we rely on UK adequacy regulations or an EU adequacy decision where one covers the recipient (including the UK Extension to the EU-US Data Privacy Framework, for recipients certified under it), and otherwise on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards using the contact details in section 14. The full list of sub-processors and their locations is on our Sub-processors page and in our DPA.
10. Your rights
Under UK and EU data protection law, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct inaccurate or incomplete data.
- Erase your data (the "right to be forgotten"), where there is no overriding reason for us to keep it.
- Restrict our processing in certain circumstances — for example while we check a correction you have asked for.
- Portability — receive the data you gave us, where we process it under contract or consent, in a structured, machine-readable format, or have it sent to another provider.
- Object to processing based on legitimate interests. You can object to direct marketing at any time, and we will always stop.
- Withdraw consent, where processing is based on consent.
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (see section 3).
How to exercise them. Use our privacy request form or email privacy@warmerly.com. Many things — your profile, notification settings, connected mailboxes, workspaces — you can also change or delete yourself in the app. There is no charge, unless a request is manifestly unfounded or excessive.
Verifying your identity. Before acting on a request, we need to be satisfied that it comes from you. Usually this means replying from, or confirming control of, the email address on your account; we will ask for more only where we need it, and use it only for the request.
How long it takes. We respond within one month of receiving your request (or of verifying your identity, if later). If a request is complex, or you have made several, we may extend this by up to two further months and will tell you why within the first month. If we cannot do what you ask, we will explain why.
Complaints. If you are unhappy with how we have handled your data, please tell us first so we can try to put it right. You also have the right to complain to the UK Information Commissioner's Office — ico.org.uk/make-a-complaint, telephone 0303 123 1113 — or, if you are in the EU, to the data protection authority where you live or work.
11. Cookies
We use a small number of cookies for authentication, and — only if you accept them — for analytics and marketing attribution. See our Cookie Policy for the full list.
12. Children
Warmerly is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us their data, contact us and we will delete it.
13. Changes to this policy
We will post any updates to this policy on this page and update the "last updated" date. Material changes will be notified by email.
14. Contact
Warmerly. Email privacy@warmerly.com for privacy matters, or hello@warmerly.com for anything else.



