Legal
Privacy Policy
Effective date: September 21, 2026
WarmList collects very little: an email address, a payment record held by Stripe, the product URL you give us, and whatever you choose to paste into Reply Studio. This policy explains that in full — including how we handle the public Reddit posts your morning list is built from.
1. What we collect from you
- Account email. You sign in with Google or an emailed one-time link; either way, the only account credential we hold is your email address, stored with our auth provider, Supabase. There are no passwords.
- Payment metadata. Payments run through Stripe, which is also the seller on your purchase (Section 4). We receive confirmation data — that a checkout was paid, the plan, the amount, the renewal date, and a customer and subscription reference. Your card number never touches our servers.
- Your product URL. The page you want lists for, and the summary of it our analysis produces.
- What you put into Reply Studio. The Strategy that tells WarmList how to write, and any Knowledge you add — pasted text, uploaded files, and pages fetched from URLs or a blog you point us at. Treat this the way you would a shared document: do not paste anything you would not want processed by the providers in Section 4.
- Your work in the app. Which threads you saved, dismissed, copied, or marked as answered, the drafts generated for you and your edits to them, so that the list keeps its state and does not offer you the same thread twice.
- Operational logs. Standard technical logs (request timestamps, errors, run costs) kept to run and debug the Service.
- Usage analytics. Which pages of our site you view (path and query string), the site that referred you, and any UTM campaign tags on the link you followed — recorded against an anonymous visitor ID set by a first-party cookie and, once you sign in, associated with your account. Section 6 describes the cookies involved.
2. Public data we process
To build your morning list, we read posts and comments that are publicly visible on Reddit. The authors of those posts are not WarmList users and have no relationship with us; their public posts are processed to compile the list you subscribed to. We may display a small, dated sample of such public posts on our website to show how the service works; usernames are removed and links are not included. Because these are public posts, they can contain personal data their authors chose to publish — a username, the text of the post itself. We do not access private subreddits or direct messages, and we do not try to identify people beyond what they have made public themselves.
If you are the author of a public Reddit post that appeared in a WarmList list and would like it excluded from future lists — or deleted from the data we have stored — email support@warmlist.app.
3. How we use information
We use the information above to build and deliver your daily list and drafts, run your subscription, respond to support requests, and keep the Service secure and working. We do not sell personal information, and we do not use it for advertising. We do not use what you paste into Reply Studio to train our own models, and the model providers in Section 4 process it only to answer our requests.
4. Third-party processors
The Service is built on a small set of providers:
- Stripe — payments. WarmList sells through Stripe Managed Payments, so Link is the merchant of record on your purchase and your purchase shows as Sold through Link. Card details are collected and stored by Stripe, not by us. Stripe emails your receipts, invoices, and refund notices directly, calculates and remits sales tax, VAT, and GST, screens for fraud, handles chargebacks, and gives you order management (cancel, update card, update billing address) on link.com.
- Supabase — authentication and data storage: your account email, your product, your lists, and your drafts.
- Google — sign-in. When you choose "Continue with Google", Google handles the sign-in and shares your email address with us; we receive no other Google account data.
- Cloudflare — hosting and infrastructure. The Service runs on Cloudflare, so requests to it pass through Cloudflare's network.
- Reddit — the source of the public posts we read.
- Third-party data providers — the licensed collection providers we read those public posts through.
- LLM providers (OpenAI and, where configured, OpenRouter) — scoring and draft generation use large-language-model APIs; excerpts of public Reddit posts, your product URL and its summary, and the Strategy and Knowledge you put into Reply Studio are processed by those APIs for that purpose.
- Resend — transactional email. Your morning summary and account emails are delivered through Resend. Payment-related emails come from Stripe instead.
Each provider processes data under its own terms and privacy policy.
5. Data retention and deletion
We keep your account data, lists, and drafts for as long as your subscription is active, and for 90 days after it ends — long enough that coming back does not mean starting over. After that we delete them. To delete your account and its data sooner, email support@warmlist.app from your account address; we will complete the deletion within 30 days. Payment records may be retained where required for legal, tax, or accounting purposes.
Because Stripe is the seller on your purchase, you can also ask Stripe to delete the data held for your Managed Payments transactions and the associated Link account; Stripe then cancels the subscriptions sold to you through Managed Payments and removes your data from the objects those transactions produced, including the ones in our Stripe account.
6. Cookies
WarmList sets two kinds of first-party cookies, and no others:
- Authentication. Session cookies from our auth provider, Supabase, that keep you signed in.
- Self-hosted analytics. To see how the site is used, we set wl_vid — a random, anonymous visitor ID — and wl_attr, which remembers how you first arrived: any UTM tags on the link, the referring site's hostname, the first page you landed on, and the time. Both expire after 90 days. The pages you view here and the source of your visit are recorded against that anonymous ID and, once you sign in, associated with your account.
This measurement runs entirely on our own infrastructure — there is no third-party analytics service, no advertising cookie, and no cross-site tracking, and the data is never shared with or sold to anyone. Stripe's checkout page is hosted by Stripe and sets its own cookies under Stripe's privacy policy.
We honor your browser's tracking-preference signals. If your browser sends Global Privacy Control (GPC) or Do Not Track (DNT), we do not set the analytics cookies and do not record analytics events for you — checked both in your browser and again on our servers. You can also switch the analytics off yourself, right here:
Checking your analytics setting…
Opting out stops analytics events from this browser and deletes the two analytics cookies. The choice is stored in your browser (not on our servers), so it applies per browser and is cleared if you clear your site data. Authentication cookies are unaffected — you stay signed in either way.
7. Your privacy rights
Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, or to restrict or object to our processing of it, by emailing support@warmlist.app from your account address. We respond without undue delay, and exercising a privacy right never changes how we treat you. You can also opt out of our self-hosted analytics at any time — either with the control in Section 6 or by turning on GPC or DNT in your browser; both are honored automatically, with no account needed.
If you are in the EEA or the UK: our legal bases are performance of our contract with you (accounts, subscriptions, daily lists and drafts), our legitimate interests (the self-hosted analytics in Section 6 and keeping the Service secure), and legal obligations (payment and tax records). WarmList is operated from Japan — a country covered by an EU adequacy decision — and the processors listed in Section 4 run infrastructure in other countries, including the United States, where your data may be processed. You also have the right to lodge a complaint with your local data-protection authority.
If you are a California resident: we do not sell personal information and do not share it for cross-context behavioral advertising, and we never have. We honor the Global Privacy Control signal as described in Section 6. The rights above cover your CCPA rights to know, delete, and correct.
8. Changes to this policy
If this policy changes, the updated version will be posted here with a new effective date. Material changes will be announced on the site or by email to your account address.
9. Contact
WarmList is operated by Shunsuke Nakagawa, an independent developer based in Japan, who is responsible for the data described in this policy. For any privacy question or request, email support@warmlist.app or see the contact page.