DRAFT, pending legal review. This is a plain-language draft of how Warm Hello works today, not final legal terms. Bracketed items are still to be filled in.
Privacy Policy
Version 0.1 · effective October 11, 2026
This policy explains what Warm Hello collects, what it does with it, who else handles it, and how to have it removed. Warm Hello is operated by [LEGAL ENTITY] ("we", "us"), [REGISTERED ADDRESS]. Questions about this policy or your data go to [CONTACT EMAIL].
In short
- Warm Hello keeps what it needs to run your relationship workspace: your account, your contacts, the history of who you talk to, your notes and your chats with the assistant.
- It reads your mailbox only through a connection you set up, with your own app password or your own sign-in to Google or Microsoft.
- The assistant runs on your own Anthropic or OpenAI API key. What the assistant reads is sent to that provider under your key and your agreement with them.
- We do not sell your data, show you ads, or use your data to train AI models.
- During the beta, ask us at [CONTACT EMAIL] for a copy of your data or to delete it.
What we hold
Your account. Your email address, your name if a sign-in provider gives us one, how you sign in (an emailed code, GitHub or Google), the workspace your account belongs to, and which version of these documents you accepted and when.
Your workspace. The contacts and companies you add or that Warm Hello finds in your mail, the opportunities and tasks you track, the interactions it logs (who wrote to whom, when, and a short summary or excerpt), the notes you write, your settings and preferences, and the decisions you make about what to show or hide.
Your conversations with the assistant. The messages you send, the assistant's replies, and the results of the tools it used to answer (for example, a list of recent emails it read). They are kept until you delete the conversation.
Your connections. The credentials for the mailbox you connect (an app password, or the access and refresh tokens Google or Microsoft issue) and your AI provider API key. They are encrypted before they are stored, and they are never shown to the assistant or sent anywhere except to the service they belong to.
Usage records. For each assistant turn: which provider and model answered, how many tokens it used, an estimated cost, how long it took and whether it finished. These records hold no message text.
Files you upload. Files you attach to a contact are kept in object storage while your account exists. There is no way to delete one yourself yet; email [CONTACT EMAIL] and we will delete it.
Your mailbox
You choose whether to connect a mailbox, and which one. Warm Hello connects to Gmail or Microsoft 365 through your own sign-in, or to any IMAP mailbox with an app password you create.
When you use the daily update or ask the assistant about your mail, Warm Hello reads message headers (sender, recipients, subject, date) and message text from the folders it is asked to look in. It uses them to answer you, to keep your contacts and their history up to date, and to suggest who to follow up with. It stores a summary or short excerpt of an interaction, not a copy of your mailbox.
Warm Hello saves draft replies to your mailbox's Drafts folder for you to review. The assistant can also send an email from your connected mailbox when you ask it to; it is instructed to confirm with you first. You can disconnect a mailbox at any time in Settings, which deletes its stored credentials.
The AI assistant and your API key
The assistant runs on the AI provider you choose, Anthropic (Claude) or OpenAI, using the API key you add. To answer you, Warm Hello sends that provider your message, the conversation so far, the instructions that make up the assistant, and whatever your workspace or mailbox data the assistant reads to answer: contact details, interaction history, notes and email text.
That processing happens under your API key and your own agreement with the provider, and their terms and privacy policy apply to it. Warm Hello does not use your data to train models, and we do not ask the providers to.
If you connect Claude (claude.ai or Claude Desktop) to Warm Hello through its MCP connection, the tools you allow return your workspace data to that client, under your agreement with Anthropic. You can turn that connection off in Settings.
Who else handles your data
We use these service providers to run Warm Hello. They handle your data only to provide their service to us:
- Fly.io runs the application (United States).
- Neon hosts the database (United States).
- Cloudflare stores uploaded files and backups (R2), and may carry traffic to the application.
- Resend delivers sign-in codes and other account email.
- Sentry receives error reports. Reports are scrubbed of secrets and personal details before they are sent, and carry technical details, not your workspace content.
- Google, Microsoft or your mail provider, when you connect a mailbox, and GitHub or Google when you sign in with them.
- Anthropic or OpenAI, called with your own API key, as described above.
We do not sell or rent your data, and we do not share it with advertisers. We may disclose data if the law requires it, and we will tell you when we are allowed to. [LEGAL REVIEW: confirm sub-processor list, regions and any data transfer mechanism.]
Cookies and your browser
Warm Hello sets one cookie, to keep you signed in. There are no advertising or tracking cookies, and no third-party analytics. Your browser also keeps a few things on your device, in its own storage, which we do not read:
- your theme, and your email address if you tick "Remember my email on this device" (both kept after you sign out);
- the last few contacts you opened from quick search (up to 8, with each one's name, email address or company), cleared when you sign out;
- the assistant panel's width, whether it was open, and your chat display choices;
- actions you have staged but not yet carried out, in this browser tab only.
How long we keep it, and your choices
We keep your data while your account exists. Disconnecting a mailbox or API key deletes its stored credentials straight away. Deleting a conversation deletes its messages. Database backups are kept for a limited period and then overwritten, so deleted data can remain in a backup until then. [LEGAL REVIEW: state the backup retention period.]
During the beta there is no self-serve export or account deletion yet. Email [CONTACT EMAIL] and we will send you a copy of your data, correct it, or delete your account and its data within [RESPONSE PERIOD].
As a beta, we may reset data while Warm Hello is built (see the Terms of Use), which can delete it sooner.
Depending on where you live, you may have further rights over your personal data, such as to object to processing or to complain to a data protection authority. [LEGAL REVIEW: jurisdiction-specific rights, e.g. GDPR / UK GDPR / CCPA, and the lawful bases relied on.]
Security
Data travels over HTTPS. Each workspace's data is isolated in the database by row-level security, so one account cannot read another's. Credentials and API keys are encrypted at rest. No system is perfectly secure; if a breach affects your data we will tell you as the law requires.
Children
Warm Hello is not for anyone under 18, and we do not knowingly collect data from children.
Changes to this policy
Each version of this policy is dated. When we change it, we ask you to accept the new version the next time you sign in, and we keep a record of which version you accepted and when.
Contact
[LEGAL ENTITY], [REGISTERED ADDRESS]. Email: [CONTACT EMAIL].