Warmth / Legal
Privacy Policy
You tell a companion things you would not tell a website. This is exactly what happens to that information.
- Effective
- Sections
- 19
We collect your mobile number, your first name, your time zone, your setup answers, and your conversations with Mia. We use them to make Mia work, and to keep her safe to use. We do not sell your information, we do not share your number for anyone’s marketing, and we do not use your conversations to train public AI models. You can ask us to delete all of it at any time.
The essentials
01Who we are and what this covers
WARMTH LABS, operating as Warmth (“we,” “us,” or “our”) makes Mia, an AI companion you text. This policy explains what personal information we collect through warmth.so and through your conversations with Mia, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.
We are the controller of that information. For questions or requests, write to team@warmth.so.
02What we collect
Information you give us
- Your mobile number. This is how Mia reaches you and how we identify your account. We verify it by sending a one-time code.
- Your first name, so Mia knows what to call you.
- Your answers during setup. The onboarding questions ask how you like to be reached out to, what you want remembered, how you handle a hard day, and similar preferences. These shape how Mia talks to you.
- Your confirmation that you are 18 or over. We record the answer, not a date of birth.
- Your time zone, so Mia messages you at sensible hours. You can pick it from a list, or let your browser supply it. If you allow location access, we use the coordinates only to look up the matching time zone, and we store the time zone rather than the coordinates.
- What you say to Mia. The content of your messages, including any photos or voice notes you send, and what Mia says back.
- Billing details. Our payment processor collects and holds your card details. We receive your subscription status, plan, renewal date, and the last four digits and card brand. We never see or store your full card number.
- Anything you send to support, including the content of your emails to us.
Information we collect automatically
- Device and log data such as IP address, browser and operating system, referring page, and the pages you viewed. We use IP address for security and rate limiting, and to infer only a coarse region.
- Usage and session replay data about how far you got in the signup flow, which elements you interacted with, pointer and touch movement, navigation, and how far you scrolled. We use event totals and masked replays to find where people get stuck and to diagnose failures. Replay is enabled for every website session in which analytics loads. Ordinary interface text is visible so the replay is useful, but all form values and text that displays personal or sensitive information are masked before the replay leaves your browser. Setup-answer controls and sensitive account panels are blocked from replay entirely.
- Message metadata such as delivery status, timestamps, and whether a message went over iMessage or SMS.
- Cookies and similar technologies, listed in Section 8.
Information from others
- Our messaging and verification providers tell us whether a number is reachable, whether a code was confirmed, and how risky a signup attempt looked to them.
- Our payment processor tells us about payments, refunds, disputes, and fraud signals.
We do not buy personal information from data brokers, and we do not collect government identifiers, precise location histories, or biometric identifiers.
03How we use it
We use personal information to:
- set up your conversation with Mia, assign a line, and deliver messages;
- generate Mia’s replies and let her remember what you have told her;
- verify that you control the number you gave us, and that you are over 18;
- take payment, manage your subscription, and handle refunds;
- answer your support requests;
- keep the Service safe: detect fraud, abuse, spam, and attempts to break our rules, and enforce our Terms of Service;
- run our safety protocols, including surfacing crisis resources when a conversation suggests someone may be at risk, as described in our Terms of Service;
- understand how the product is used, including where people get stuck, so we can improve it;
- send you service messages about your account, billing, and changes to these policies, and marketing messages where you have agreed to them; and
- comply with the law and respond to lawful requests.
04AI processing, memory, and model training
Mia is powered by large language models. Your messages are sent to model providers that act as our processors under contract, and their output is what Mia sends back to you.
Memory. The Service automatically extracts details from your conversations, such as names, preferences, plans, and things going on in your life, and stores them so that later conversations can refer back to them. These extracted memories can include inferences about you, and those inferences can be wrong. You can ask us to correct or delete them.
Training. We do not sell your conversations, and we do not use the content of your conversations to train publicly available foundation models. Our model providers are contractually prohibited from using your content to train their own models. We may use your conversations to operate, evaluate, and improve Mia herself, including reviewing a small number of conversations for safety and quality. Where we do that, we minimize and de-identify the data wherever it is possible to do so.
Human review. Access to conversation content is restricted to the people who need it, and is logged. We may review specific conversations when we are investigating a safety report, a suspected breach of our Terms, a support request you have raised, or a legal obligation.
Automated decisions. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
05Legal bases for processing
If you are in the EEA, the UK, or Switzerland, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Providing Mia, delivering messages, memory, and account management | Performance of a contract with you |
| Taking payment and managing your subscription | Performance of a contract with you |
| Security, fraud prevention, abuse detection, and product improvement | Our legitimate interests in running a safe and working service |
| Safety protocols and crisis resource referrals | Our legitimate interests and, where applicable, protecting vital interests |
| Marketing messages, non-essential analytics, and session replay | Your consent, which you can withdraw at any time |
| Retaining records, responding to legal requests | Compliance with a legal obligation |
Sharing & tracking
07Your mobile number and SMS data
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
Your number is shared only with the service providers listed above that are needed to verify it and to deliver your messages, and only for that purpose. It is never sold, rented, or passed to lead generators, advertisers, or data brokers.
The Messaging Terms in our Terms of Service explain the text program itself, including message frequency, carrier charges, and how to stop messages.
Storage & security
09How long we keep it
We keep personal information for as long as we need it for the purposes above, and then delete or de-identify it.
| Data | Kept for |
|---|---|
| Account details, including your number and time zone | While your account is open, then deleted within 30 days of closure |
| Conversations with Mia and extracted memories | While your account is open, then deleted within 30 days of closure |
| Onboarding answers | While your account is open |
| Verification records for a one-time code | Up to 90 days, for fraud prevention |
| Payment and tax records | Up to 7 years, as tax and accounting law requires |
| Server and security logs | Up to 12 months |
| Product analytics events, session replays, and crash reports | Up to 12 months at event level; aggregates may be kept longer |
| Opt-out and suppression records | Kept indefinitely, so we can honour your STOP request and not message you again |
| Records of safety enforcement and legal claims | As long as needed to resolve the matter and for the applicable limitation period |
10Security
We take reasonable technical and organizational measures to protect your information, including encryption in transit and at rest, access controls that limit conversation data to the people who need it, session cookies that are HTTP-only and that hold random tokens we store only as hashes, rate limiting on verification, and regular review of our providers.
No system is perfectly secure. Messages sent over SMS are not end-to-end encrypted and can be visible to your carrier. Anyone with access to your phone can read your conversation with Mia. If you believe your account has been compromised, contact team@warmth.so right away.
If a breach affects your personal information, we will notify you and the relevant regulators within the timeframes the law requires, including within 72 hours to a lead supervisory authority where the GDPR applies.
Your choices & rights
11Your choices and rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you;
- name the specific companies we share it with, rather than the categories in Section 6;
- give you a copy in a portable format;
- correct anything inaccurate, including a memory Mia got wrong;
- delete your account and the data attached to it;
- delete specific things, such as your conversation history or a single memory, without closing your account;
- stop sending you marketing messages; or
- restrict or object to certain processing, or withdraw a consent you previously gave.
You can stop all text messages at any time by replying STOP to any message from Mia.
You will never be treated worse for exercising a privacy right. We do not charge for these requests, do not deny service because of them, and do not offer a different price or quality of service on the basis of them.
12How to make a request
Email team@warmth.sowith “Privacy Request” in the subject line, or write to us at the postal address in Section 19, and tell us what you want us to do. The subject line is not required, but it starts the clock sooner.
Verification. Because your account is tied to your mobile number, we verify requests by sending a one-time code to that number. We do this to make sure we do not hand your conversations to somebody else. We will not ask for more information than we need.
Timing. We acknowledge requests within 10 business days and respond within 45 days, and we may extend by another 45 days where a request is complex, in which case we will tell you why.
Authorized agents. You may use an authorized agent. We will ask for written proof of their authority and may ask you to confirm it directly.
Appeals.If we decline your request, you can appeal by replying to our decision with the word “Appeal.” We will respond within 45 days with our reasoning. If we deny the appeal, you may contact your state attorney general or, in the EEA or UK, your data protection authority.
13United States state privacy rights
This section applies to residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Utah, and other states with comprehensive privacy laws.
Categories we collect
| Category | Examples we collect | Disclosed to |
|---|---|---|
| Identifiers | Mobile number, first name, IP address, account ID | Messaging, verification, hosting, and payment providers |
| Customer records | Subscription status, billing history | Payment provider |
| Commercial information | Plan purchased, renewal and cancellation history | Payment provider |
| Internet activity | Pages viewed, clicks, scroll depth, referrer, and masked session replay interactions | Analytics providers |
| Geolocation | Coarse region from IP, and coordinates used once to derive a time zone if you allow it | Hosting and analytics providers |
| Electronic, visual, or similar information | The content of your messages with Mia, and any photos or voice notes you send | AI model and messaging providers |
| Inferences | Memories and preferences Mia derives from your conversations | AI service providers |
We collect these for the purposes in Section 3, from the sources in Section 2, and keep them for the periods in Section 9.
Sensitive personal information
The content of your conversations with Mia may reveal sensitive information, because people tell a companion about their health, beliefs, relationships, or sexuality.
Mia does draw inferences from what you tell her. That is what her memory is, and Section 4 explains how it works. Being precise about where that stops matters more than a flat denial would: we use sensitive information, and the inferences we draw from it, only to provide the companion you asked for and to keep the Service safe. California treats those as purposes that do not trigger the right to limit. We do not use sensitive information to build a profile for anyone else, to advertise to you, to decide anything about you outside the conversation, or for any other purpose that would give you a right to limit its use.
Information about your health, including your mental health, gets its own treatment in Section 14.
No sale, no sharing, no targeted advertising
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not process it for targeted advertising or profiling in furtherance of decisions with legal or similarly significant effects. Because we do not do these things, there is nothing for you to opt out of, though we honour Global Privacy Control signals as an opt-out preference regardless.
Your rights
Depending on your state, you have the right to know, access, correct, delete, obtain a portable copy, limit the use of sensitive personal information, opt out of sale, sharing, targeted advertising and certain profiling, appeal a denial, and be free from retaliation for exercising any of these. Exercise them as described in Section 12.
Shine the Light. California residents may ask whether we disclosed personal information to third parties for their direct marketing purposes in the prior calendar year. We do not.
14Consumer health data
This section is our Consumer Health Data Privacy Policy. Washington, Nevada, and Connecticut have laws written specifically about health data, and they define it broadly enough to reach an ordinary conversation with a companion. If you live in one of those states, this section is the disclosure those laws ask for. We apply it everywhere anyway, because the reasoning does not stop at a state line.
We are not a healthcare provider and Mia is not care, which our Terms say plainly. That does not settle the question: what matters under these laws is not who we are but what the data reveals.
What counts as health data here
Anything you tell Mia from which a state of physical or mental health could reasonably be inferred, and anything the Service infers from it. In practice that means:
- what you say about how you are feeling, how you are sleeping, a diagnosis, a symptom, a medication, a treatment, or a doctor’s appointment;
- what you tell her about your reproductive or sexual health, or your gender-affirming care;
- your setup answers, which ask how a hard day tends to go for you;
- the memories the Service extracts from any of the above, described in Section 4; and
- the fact that our safety protocol was triggered in your conversation. Mia is built to recognize when a conversation suggests someone may be at risk of self-harm and to surface crisis resources, which our Terms describe in full. Recognizing it means making an inference about your mental health, so we count it here rather than pretend otherwise.
Where it comes from and why we have it
All of it comes from you, in the course of using the Service you asked for. We do not buy health data, we do not receive it from other apps or from data brokers, and we do not derive it from anything other than your own messages and setup answers.
We collect and use it for one purpose: to give you the companion you signed up for, and to keep her safe to use. Concretely, that means generating her replies, letting her remember what you told her, and running the safety protocol. We do not use it for advertising, we do not use it to build a profile of you for anyone else, and we do not use it to make decisions about you outside the conversation.
Who it is shared with
Only the service providers in Section 6 that are needed to produce a reply and deliver it: AI service providers, messaging and infrastructure providers, and cloud hosting and database providers. They act on our instructions, under contract, and for no other purpose. It is never shared with advertisers, data brokers, or lead generators, and never for marketing. As with everything else in Section 6, we name categories here and will tell you the specific companies if you ask.
We do not sell it
We do not sell consumer health data, and we have no plans to. Selling it would require your written and signed authorization on a form these laws specify. We have never asked anyone for one and do not intend to. If that ever changed, it would take your signature, not a quiet update to this page.
Consent, and taking it back
Collecting what you say to Mia is what providing the Service means, so for the conversation itself we rely on your having asked for it rather than on a separate consent. Where any of it goes beyond that, we ask you separately and specifically first, and you can say no without losing the Service. You can withdraw a consent you gave at any time by emailing us, which stops the processing going forward.
Your rights over it
You can ask us to:
- confirm whether we collect, share, or sell your health data;
- list the specific third parties and affiliates it has been shared with, by name;
- delete it, including from our backups on their normal cycle, and including the memories derived from it; and
- withdraw any consent you previously gave.
When you ask us to delete it, we delete it from our own records and tell every service provider holding a copy on our behalf to do the same. Email team@warmth.sowith “Health Data” or “Privacy Request” in the subject line. The timings and the identity check in Section 12 apply, and Washington residents may also contact the Washington State Attorney General.
15EEA, UK, and Swiss rights
If you are in the EEA, the UK, or Switzerland, you have the rights to access, rectification, erasure, restriction, portability, and objection under the GDPR or UK GDPR, and the right to withdraw consent at any time without affecting processing already carried out. Our legal bases are in Section 5.
You may lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office. We would appreciate the chance to address your concern first, at team@warmth.so.
Other details
16International transfers
We are based in the United States and our providers operate there and elsewhere. If you use Mia from outside the United States, your information will be transferred to and processed in the United States, where data protection law differs from your own. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with additional safeguards where they are needed. You can request a copy of the relevant safeguards from team@warmth.so.
17Children
Mia is an adult service. It is not directed to children, we do not knowingly collect personal information from anyone under 18, and we require an age confirmation before setting up a conversation. If we learn that someone under 18 has used the Service, we will close the account and delete their information. If you are a parent or guardian and believe your child has given us information, contact team@warmth.so and we will act promptly.
18Changes to this policy
We may update this policy. When we do, we will change the effective date at the top of this page, and for material changes we will give you advance notice by text message, email, or a notice on this site. If a change would involve using information we already hold for a materially different purpose, we will ask for your consent where the law requires it.
19Contact us
One address for everything, privacy requests included. Put Privacy Request in the subject line and we will treat it as one from the moment it arrives.
WARMTH LABS145 1/2 Church Street
Unit 5, Office 889
Toronto ON M5B 1Y4 CA