Privacy Policy
Last updated: 17 September 2026
Who we are
Warmloom (“we”, “us”) is a service operated by LOULEK COMMUNICATION, a French société à responsabilité limitée (SARL) registered at 17B boulevard Pasteur, 75015 Paris, France, company number 989 763 305 (RCS Paris). We are the data controller for the personal data described below, except where stated otherwise.
For any question about this policy or to exercise your rights, write to privacy@warmloom.com.
What Warmloom does, in one paragraph
Warmloom looks for publicly available business events (an opening, a launch, a funding round, a hire) at companies matching what you sell, identifies a relevant contact, verifies that the email address exists, writes one short outreach email, and creates it as a draft in your own Gmail account. You stay the sender. We never send from our own infrastructure.
Data we collect about you (our user)
- Account: your name, email address and profile picture, received from Google when you sign in.
- Gmail connection: the email address of the mailbox you connect, and the OAuth access and refresh tokens that let us act on your behalf. Tokens are stored in our database and are never shared.
- Your settings: the website you sell from, your campaigns and targeting, your email signature (including any image you paste into it), your sending window and follow-up preferences.
- Emails we create for you: subject, body, recipient, status, and whether a reply or a bounce was detected.
- Technical: for visitors who use the free search without an account, we store a counter associated with your IP address in order to enforce the daily limit.
Mailboxes connected with an app password
Instead of connecting through Google, you can connect any mailbox with an app password issued by your email provider. In that case we store the server addresses, the login, and the password, encrypted with AES-256-GCM using a key held only on our server and never written to the database. We use those credentials for exactly three things: sending your scheduled emails through your provider's SMTP server, placing each email in your Drafts folder before it goes out, and searching your mailbox for replies and bounces to the emails Warmloom itself sent. We do not read, index, or store the rest of your mailbox. You can remove the mailbox at any time, which deletes the stored credentials; you can also revoke the app password from your provider.
How we use Google user data
When you connect a Gmail mailbox through Google, we request exactly two permissions, and we use them for exactly these purposes:
gmail.compose: to create the outreach email as a draft in your mailbox, and to send that draft at the time you scheduled. We never send anything you have not seen or scheduled.gmail.metadata: to read the headers only (sender, subject, date) of the email threads Warmloom itself created, so we can tell you when a prospect has replied and stop the follow-ups, or detect that an address bounced. This permission does not give access to the body of any message, and we never look at threads we did not create.
Limited Use. Warmloom's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the service or as required by law, and we do not allow humans to read it: except with your explicit consent for a support request you raised, where it is necessary for security purposes, or where the law requires it. Google user data is never used to train any artificial intelligence or machine learning model.
Data about the prospects we find
To write a relevant email, Warmloom processes a limited amount of personal data about the person you want to contact: their name, their professional role, their professional email address, their employer, and the public business event that justifies the outreach. This data comes from public sources: the company's own website, public business registries, press articles and search engines.
Legal basis: our legitimate interest, and yours, in business-to-business prospecting (Article 6(1)(f) GDPR). We minimise what we keep, we only address people in a professional capacity about a topic relevant to their job, and we never process special categories of data.
If you are a prospect and received an email: you can ask us to erase your data and never be contacted again by writing to privacy@warmloom.com. We will action it without delay and add the address to a permanent suppression list. You can also reply directly to the sender, who remains responsible for their own outreach.
Who processes data on our behalf
We use a small number of providers, each for a specific purpose:
- Google (Ireland/USA): sign-in and the Gmail API for the mailbox you connect.
- OpenAI (USA): generating the analysis and the text of the emails. Content sent to OpenAI is not used to train their models under their API terms.
- Brave Search, DataForSEO: public web and news searches.
- MillionVerifier: checking that an email address exists before anything is sent.
- Neon (USA): our database.
- OVHcloud (France): our application server.
International transfers. Some of these providers are located in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Cookies
Warmloom sets no analytics, advertising or tracking cookie, and no third-party cookie. The only cookies are strictly necessary or set at your explicit request, which under French (CNIL) and EU rules require no consent banner: the sign-in session cookie and its anti-forgery token (Auth.js), and a language preference stored only when you click FR or EN, kept one year. Referral links carry their code in the address, not in a cookie. If we ever add audience measurement, we will ask for your consent first.
How long we keep data
- Your account, campaigns and emails: for as long as your account exists, then deleted within 30 days.
- OAuth tokens: until you disconnect the mailbox or delete your account, then deleted immediately.
- Prospect data: up to 24 months from the last contact, then deleted.
- Addresses that bounced: kept indefinitely in a suppression list, precisely so that no one ever writes to them again.
- Anonymous usage counters: 30 days.
Your rights
Under the GDPR you may access, correct, erase, or export your data, object to processing, or ask us to restrict it. Write to privacy@warmloom.com and we will answer within one month.
You can disconnect your mailbox at any time from your profile page, which immediately revokes our access, and you can also revoke it directly from your Google account permissions. If you believe we have mishandled your data, you have the right to lodge a complaint with the CNIL (www.cnil.fr) or your local supervisory authority.
Security
Data is transmitted over TLS and stored on servers in France and the United States. Access to production data is restricted to the people who operate the service. OAuth tokens are only ever used to perform the actions described above, and never shared with third parties.
Changes
We will update this page when the service changes, and we will change the date at the top. If a change materially affects how we handle your data, we will tell you by email before it takes effect.