TermsPrivacy

Warmth / Legal

Privacy Policy

You tell a companion things you would not tell a website. This is exactly what happens to that information.

Effective
August 19, 2026
Sections
19
The short version.

We collect your mobile number, your first name, your time zone, your setup answers, and your conversations with Mia. We use them to make Mia work, and to keep her safe to use. We do not sell your information, we do not share your number for anyone’s marketing, and we do not use your conversations to train public AI models. You can ask us to delete all of it at any time.

Part 01

The essentials

01Who we are and what this covers

WARMTH LABS, operating as Warmth (“we,” “us,” or “our”) makes Mia, an AI companion you text. This policy explains what personal information we collect through warmth.so and through your conversations with Mia, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.

We are the controller of that information. For questions or requests, write to team@warmth.so.

02What we collect

Information you give us

  • Your mobile number. This is how Mia reaches you and how we identify your account. We verify it by sending a one-time code.
  • Your first name, so Mia knows what to call you.
  • Your answers during setup. The onboarding questions ask how you like to be reached out to, what you want remembered, how you handle a hard day, and similar preferences. These shape how Mia talks to you.
  • Your confirmation that you are 18 or over. We record the answer, not a date of birth.
  • Your time zone, so Mia messages you at sensible hours. You can pick it from a list, or let your browser supply it. If you allow location access, we use the coordinates only to look up the matching time zone, and we store the time zone rather than the coordinates.
  • What you say to Mia. The content of your messages, including any photos or voice notes you send, and what Mia says back.
  • Billing details. Our payment processor collects and holds your card details. We receive your subscription status, plan, renewal date, and the last four digits and card brand. We never see or store your full card number.
  • Anything you send to support, including the content of your emails to us.

Information we collect automatically

  • Device and log data such as IP address, browser and operating system, referring page, and the pages you viewed. We use IP address for security and rate limiting, and to infer only a coarse region.
  • Usage and session replay data about how far you got in the signup flow, which elements you interacted with, pointer and touch movement, navigation, and how far you scrolled. We use event totals and masked replays to find where people get stuck and to diagnose failures. Replay is enabled for every website session in which analytics loads. Ordinary interface text is visible so the replay is useful, but all form values and text that displays personal or sensitive information are masked before the replay leaves your browser. Setup-answer controls and sensitive account panels are blocked from replay entirely.
  • Message metadata such as delivery status, timestamps, and whether a message went over iMessage or SMS.
  • Cookies and similar technologies, listed in Section 8.

Information from others

  • Our messaging and verification providers tell us whether a number is reachable, whether a code was confirmed, and how risky a signup attempt looked to them.
  • Our payment processor tells us about payments, refunds, disputes, and fraud signals.

We do not buy personal information from data brokers, and we do not collect government identifiers, precise location histories, or biometric identifiers.

03How we use it

We use personal information to:

  • set up your conversation with Mia, assign a line, and deliver messages;
  • generate Mia’s replies and let her remember what you have told her;
  • verify that you control the number you gave us, and that you are over 18;
  • take payment, manage your subscription, and handle refunds;
  • answer your support requests;
  • keep the Service safe: detect fraud, abuse, spam, and attempts to break our rules, and enforce our Terms of Service;
  • run our safety protocols, including surfacing crisis resources when a conversation suggests someone may be at risk, as described in our Terms of Service;
  • understand how the product is used, including where people get stuck, so we can improve it;
  • send you service messages about your account, billing, and changes to these policies, and marketing messages where you have agreed to them; and
  • comply with the law and respond to lawful requests.

04AI processing, memory, and model training

Mia is powered by large language models. Your messages are sent to model providers that act as our processors under contract, and their output is what Mia sends back to you.

Memory. The Service automatically extracts details from your conversations, such as names, preferences, plans, and things going on in your life, and stores them so that later conversations can refer back to them. These extracted memories can include inferences about you, and those inferences can be wrong. You can ask us to correct or delete them.

Training. We do not sell your conversations, and we do not use the content of your conversations to train publicly available foundation models. Our model providers are contractually prohibited from using your content to train their own models. We may use your conversations to operate, evaluate, and improve Mia herself, including reviewing a small number of conversations for safety and quality. Where we do that, we minimize and de-identify the data wherever it is possible to do so.

Human review. Access to conversation content is restricted to the people who need it, and is logged. We may review specific conversations when we are investigating a safety report, a suspected breach of our Terms, a support request you have raised, or a legal obligation.

Automated decisions. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

05Legal bases for processing

If you are in the EEA, the UK, or Switzerland, we rely on the following legal bases.

PurposeLegal basis
Providing Mia, delivering messages, memory, and account managementPerformance of a contract with you
Taking payment and managing your subscriptionPerformance of a contract with you
Security, fraud prevention, abuse detection, and product improvementOur legitimate interests in running a safe and working service
Safety protocols and crisis resource referralsOur legitimate interests and, where applicable, protecting vital interests
Marketing messages, non-essential analytics, and session replayYour consent, which you can withdraw at any time
Retaining records, responding to legal requestsCompliance with a legal obligation
Part 02

Sharing & tracking

06Who we share it with

We do not sell your personal information. We share it only in the ways described here.

Service providers. Companies that process data on our behalf, under contract, only on our instructions, and only for the purposes below.

Category of providerWhat it does for us
AI service providersGenerate Mia’s replies from your messages. Prohibited by contract from training their own models on your content.
Messaging platform and infrastructure providersDeliver and receive messages over iMessage and SMS, and assign the line Mia texts you from.
Phone verification providersSend the one-time code that confirms your number, and judge whether the request came from a person or a script. They receive your number, your IP address, and information about your browser and device for that purpose, and use it for fraud prevention rather than advertising.
Cloud hosting and database providersRun the website and store your account, your conversations, and our logs.
Analytics providersProduct analytics, crash diagnostics, and masked session replay. Ordinary interface text is visible; form values and personal or sensitive text are masked, and sensitive controls and account panels are blocked from replay.
Payment processorsTake payment and hold your card details as their own controller. We never receive your full card number.
Customer support toolsHandle the emails you send us.

We name categories rather than individual companies here, which is what this kind of disclosure calls for and what keeps this list accurate as providers change. If you want to know the specific companies behind any of these categories, ask us and we will tell you. That offer is open to everyone, not only to people in places where the law requires it of us.

Messaging platforms and carriers. Conversations carried over iMessage are handled by Apple, and messages sent over SMS pass through your mobile carrier. Each does so under its own terms, not ours. See Section 7 for what we do and do not share about your number.

Legal and safety. We may disclose information if we reasonably believe it is required by law, subpoena, or court order, or necessary to investigate fraud or a violation of our Terms, or to protect the rights, property, or safety of any person, including where there is a credible risk of serious harm.

Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that deal. We will give you notice before your information becomes subject to a materially different privacy policy.

De-identified and aggregated data. We may create and share data that cannot reasonably be used to identify you, and we will not attempt to re-identify it.

07Your mobile number and SMS data

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

Your number is shared only with the service providers listed above that are needed to verify it and to deliver your messages, and only for that purpose. It is never sold, rented, or passed to lead generators, advertisers, or data brokers.

The Messaging Terms in our Terms of Service explain the text program itself, including message frequency, carrier charges, and how to stop messages.

08Cookies and analytics

Cookies are small files a site stores in your browser. Similar technologies, including local storage and pixels, do much the same job. This is what warmth.so uses. It is a short list because we do not advertise: there are no advertising cookies here, no retargeting, and no cross-site tracking.

This covers the website. Your text conversations with Mia happen in your messaging app and do not involve cookies at all.

PurposeSet byWhyLasts
Phone verification sessionUsPoints at the verification you have in progress, so the code screen survives a reload and your number never has to be sent to us a second time. It holds a random id rather than your number, and it is HTTP-only, so scripts cannot read it.35 minutes
Signed-in sessionUsKeeps you signed in to your account pages. HTTP-only and pinned to this site. It holds a random token that we store only as a hash, so a copy of our database cannot be turned back into a working cookie.30 days, or until you sign out
Fraud prevention device idUsA random id, HTTP-only and with nothing personal in it, sent with verification requests so one browser cannot request codes for many numbers unnoticed. Strictly necessary for fraud prevention, and used for nothing else. Clearing cookies resets it.2 years
Verification antifraud signalsOur phone verification providerRuns on the signup form to tell a person from a script, so nobody can drive up our messaging bill by requesting codes in bulk. It reads your browser, device, and network characteristics, including your IP address, and keeps an identifier in local storage and IndexedDB so the check can be tied to the code request that follows. Strictly necessary for fraud prevention. It does not follow you across sites and is not used for advertising.Until you clear your browser storage
Product analyticsOur analytics providerCounts pageviews, clicks, and scroll depth so we can see where people get stuck in signup. It records a masked reconstruction of every eligible website session and receives diagnostic reports when the site crashes so we can fix the problem.Up to 12 months
Traffic and performance measurementOur hosting providerAggregate visitor counts and page speed metrics. No cross-site identifier.Up to 24 hours

What our analytics actually record

Analytics tools vary enormously in how far they go, so it is worth being specific about where ours stop:

  • Session replay is switched on. For every website session where analytics loads, it reconstructs page structure and changes, pointer and touch movement, clicks, scrolling, and navigation. It is a reconstruction of the page rather than a video recording of screen pixels.
  • Sensitive text and all form values are masked. Ordinary headings, instructions, buttons, and other interface copy remain visible so a replay can show what happened. Every value you type is replaced before replay data is sent. Text that displays a name, phone number, verification code, location, personal setup answer, or account and billing detail is also masked. Controls where you choose personal setup answers and sensitive account panels are excluded from replay entirely.
  • High-risk capture is disabled. Replays do not include canvas content, cross-origin frames, console logs, network requests, request or response headers, or request or response bodies. Query strings and URL fragments are removed from replayed page addresses.
  • No profile for anonymous visitors. We do not create a person record for everyone who lands on the site.
  • No personal data in events. Our funnel events carry which step you reached, not who you are.
  • Crash reports are limited to diagnostics. They can include the error type, message, stack trace, current page or route category, and coarse browser information. We do not intentionally attach form values, phone numbers, request bodies, or cookies.
  • We do collect pageviews, clicks on elements, scroll depth, referrer, coarse device and browser information, and the masked session replay interactions described above.

Two things that sound like they should be on the list above and are not. Rate limiting, which stops one machine from requesting thousands of verification codes, counts requests against an IP address on our servers and does not use a cookie. And the fraud prevention device id in the table is kept out of analytics entirely: it is an antifraud signal, so it is not sent to our analytics provider and is not used to identify you there.

How to turn them off

Every major browser lets you block or delete cookies and site storage in its settings. Blocking the strictly necessary ones will break phone verification, so signup will not work. Browser content blockers can also block analytics requests. If your browser sends a Global Privacy Control signal, we do not load analytics at all for that visit. We also treat that signal as an opt-out of any sale or sharing of personal information, though as described below we do neither. You can also email team@warmth.so and we will exclude your analytics data and confirm when it is done.

If you are in the EEA or the UK. We do not set advertising cookies anywhere and we do not track you across sites. To stop the analytics above, enable Global Privacy Control, use a browser content blocker, or write to us at the address above.

Part 03

Storage & security

09How long we keep it

We keep personal information for as long as we need it for the purposes above, and then delete or de-identify it.

DataKept for
Account details, including your number and time zoneWhile your account is open, then deleted within 30 days of closure
Conversations with Mia and extracted memoriesWhile your account is open, then deleted within 30 days of closure
Onboarding answersWhile your account is open
Verification records for a one-time codeUp to 90 days, for fraud prevention
Payment and tax recordsUp to 7 years, as tax and accounting law requires
Server and security logsUp to 12 months
Product analytics events, session replays, and crash reportsUp to 12 months at event level; aggregates may be kept longer
Opt-out and suppression recordsKept indefinitely, so we can honour your STOP request and not message you again
Records of safety enforcement and legal claimsAs long as needed to resolve the matter and for the applicable limitation period

10Security

We take reasonable technical and organizational measures to protect your information, including encryption in transit and at rest, access controls that limit conversation data to the people who need it, session cookies that are HTTP-only and that hold random tokens we store only as hashes, rate limiting on verification, and regular review of our providers.

No system is perfectly secure. Messages sent over SMS are not end-to-end encrypted and can be visible to your carrier. Anyone with access to your phone can read your conversation with Mia. If you believe your account has been compromised, contact team@warmth.so right away.

If a breach affects your personal information, we will notify you and the relevant regulators within the timeframes the law requires, including within 72 hours to a lead supervisory authority where the GDPR applies.

Part 04

Your choices & rights

11Your choices and rights

Wherever you live, you can ask us to:

  • tell you what personal information we hold about you;
  • name the specific companies we share it with, rather than the categories in Section 6;
  • give you a copy in a portable format;
  • correct anything inaccurate, including a memory Mia got wrong;
  • delete your account and the data attached to it;
  • delete specific things, such as your conversation history or a single memory, without closing your account;
  • stop sending you marketing messages; or
  • restrict or object to certain processing, or withdraw a consent you previously gave.

You can stop all text messages at any time by replying STOP to any message from Mia.

You will never be treated worse for exercising a privacy right. We do not charge for these requests, do not deny service because of them, and do not offer a different price or quality of service on the basis of them.

12How to make a request

Email team@warmth.sowith “Privacy Request” in the subject line, or write to us at the postal address in Section 19, and tell us what you want us to do. The subject line is not required, but it starts the clock sooner.

Verification. Because your account is tied to your mobile number, we verify requests by sending a one-time code to that number. We do this to make sure we do not hand your conversations to somebody else. We will not ask for more information than we need.

Timing. We acknowledge requests within 10 business days and respond within 45 days, and we may extend by another 45 days where a request is complex, in which case we will tell you why.

Authorized agents. You may use an authorized agent. We will ask for written proof of their authority and may ask you to confirm it directly.

Appeals.If we decline your request, you can appeal by replying to our decision with the word “Appeal.” We will respond within 45 days with our reasoning. If we deny the appeal, you may contact your state attorney general or, in the EEA or UK, your data protection authority.

13United States state privacy rights

This section applies to residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Utah, and other states with comprehensive privacy laws.

Categories we collect

CategoryExamples we collectDisclosed to
IdentifiersMobile number, first name, IP address, account IDMessaging, verification, hosting, and payment providers
Customer recordsSubscription status, billing historyPayment provider
Commercial informationPlan purchased, renewal and cancellation historyPayment provider
Internet activityPages viewed, clicks, scroll depth, referrer, and masked session replay interactionsAnalytics providers
GeolocationCoarse region from IP, and coordinates used once to derive a time zone if you allow itHosting and analytics providers
Electronic, visual, or similar informationThe content of your messages with Mia, and any photos or voice notes you sendAI model and messaging providers
InferencesMemories and preferences Mia derives from your conversationsAI service providers

We collect these for the purposes in Section 3, from the sources in Section 2, and keep them for the periods in Section 9.

Sensitive personal information

The content of your conversations with Mia may reveal sensitive information, because people tell a companion about their health, beliefs, relationships, or sexuality.

Mia does draw inferences from what you tell her. That is what her memory is, and Section 4 explains how it works. Being precise about where that stops matters more than a flat denial would: we use sensitive information, and the inferences we draw from it, only to provide the companion you asked for and to keep the Service safe. California treats those as purposes that do not trigger the right to limit. We do not use sensitive information to build a profile for anyone else, to advertise to you, to decide anything about you outside the conversation, or for any other purpose that would give you a right to limit its use.

Information about your health, including your mental health, gets its own treatment in Section 14.

No sale, no sharing, no targeted advertising

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not process it for targeted advertising or profiling in furtherance of decisions with legal or similarly significant effects. Because we do not do these things, there is nothing for you to opt out of, though we honour Global Privacy Control signals as an opt-out preference regardless.

Your rights

Depending on your state, you have the right to know, access, correct, delete, obtain a portable copy, limit the use of sensitive personal information, opt out of sale, sharing, targeted advertising and certain profiling, appeal a denial, and be free from retaliation for exercising any of these. Exercise them as described in Section 12.

Shine the Light. California residents may ask whether we disclosed personal information to third parties for their direct marketing purposes in the prior calendar year. We do not.

14Consumer health data

This section is our Consumer Health Data Privacy Policy. Washington, Nevada, and Connecticut have laws written specifically about health data, and they define it broadly enough to reach an ordinary conversation with a companion. If you live in one of those states, this section is the disclosure those laws ask for. We apply it everywhere anyway, because the reasoning does not stop at a state line.

We are not a healthcare provider and Mia is not care, which our Terms say plainly. That does not settle the question: what matters under these laws is not who we are but what the data reveals.

What counts as health data here

Anything you tell Mia from which a state of physical or mental health could reasonably be inferred, and anything the Service infers from it. In practice that means:

  • what you say about how you are feeling, how you are sleeping, a diagnosis, a symptom, a medication, a treatment, or a doctor’s appointment;
  • what you tell her about your reproductive or sexual health, or your gender-affirming care;
  • your setup answers, which ask how a hard day tends to go for you;
  • the memories the Service extracts from any of the above, described in Section 4; and
  • the fact that our safety protocol was triggered in your conversation. Mia is built to recognize when a conversation suggests someone may be at risk of self-harm and to surface crisis resources, which our Terms describe in full. Recognizing it means making an inference about your mental health, so we count it here rather than pretend otherwise.

Where it comes from and why we have it

All of it comes from you, in the course of using the Service you asked for. We do not buy health data, we do not receive it from other apps or from data brokers, and we do not derive it from anything other than your own messages and setup answers.

We collect and use it for one purpose: to give you the companion you signed up for, and to keep her safe to use. Concretely, that means generating her replies, letting her remember what you told her, and running the safety protocol. We do not use it for advertising, we do not use it to build a profile of you for anyone else, and we do not use it to make decisions about you outside the conversation.

Who it is shared with

Only the service providers in Section 6 that are needed to produce a reply and deliver it: AI service providers, messaging and infrastructure providers, and cloud hosting and database providers. They act on our instructions, under contract, and for no other purpose. It is never shared with advertisers, data brokers, or lead generators, and never for marketing. As with everything else in Section 6, we name categories here and will tell you the specific companies if you ask.

We do not sell it

We do not sell consumer health data, and we have no plans to. Selling it would require your written and signed authorization on a form these laws specify. We have never asked anyone for one and do not intend to. If that ever changed, it would take your signature, not a quiet update to this page.

Consent, and taking it back

Collecting what you say to Mia is what providing the Service means, so for the conversation itself we rely on your having asked for it rather than on a separate consent. Where any of it goes beyond that, we ask you separately and specifically first, and you can say no without losing the Service. You can withdraw a consent you gave at any time by emailing us, which stops the processing going forward.

Your rights over it

You can ask us to:

  • confirm whether we collect, share, or sell your health data;
  • list the specific third parties and affiliates it has been shared with, by name;
  • delete it, including from our backups on their normal cycle, and including the memories derived from it; and
  • withdraw any consent you previously gave.

When you ask us to delete it, we delete it from our own records and tell every service provider holding a copy on our behalf to do the same. Email team@warmth.sowith “Health Data” or “Privacy Request” in the subject line. The timings and the identity check in Section 12 apply, and Washington residents may also contact the Washington State Attorney General.

15EEA, UK, and Swiss rights

If you are in the EEA, the UK, or Switzerland, you have the rights to access, rectification, erasure, restriction, portability, and objection under the GDPR or UK GDPR, and the right to withdraw consent at any time without affecting processing already carried out. Our legal bases are in Section 5.

You may lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office. We would appreciate the chance to address your concern first, at team@warmth.so.

Part 05

Other details

16International transfers

We are based in the United States and our providers operate there and elsewhere. If you use Mia from outside the United States, your information will be transferred to and processed in the United States, where data protection law differs from your own. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with additional safeguards where they are needed. You can request a copy of the relevant safeguards from team@warmth.so.

17Children

Mia is an adult service. It is not directed to children, we do not knowingly collect personal information from anyone under 18, and we require an age confirmation before setting up a conversation. If we learn that someone under 18 has used the Service, we will close the account and delete their information. If you are a parent or guardian and believe your child has given us information, contact team@warmth.so and we will act promptly.

18Changes to this policy

We may update this policy. When we do, we will change the effective date at the top of this page, and for material changes we will give you advance notice by text message, email, or a notice on this site. If a change would involve using information we already hold for a materially different purpose, we will ask for your consent where the law requires it.

19Contact us

One address for everything, privacy requests included. Put Privacy Request in the subject line and we will treat it as one from the moment it arrives.

team@warmth.so

WARMTH LABS
145 1/2 Church Street
Unit 5, Office 889
Toronto ON M5B 1Y4 CA

Also from Warmth

Terms of Service
Back to top

A friend for everyone.

BlogTerms of ServicePrivacy Policy

© 2026 WARMTH LABS

Contactteam@warmth.soDiscord