Privacy Policy
Last updated: 23 July, 2026
This policy explains what Warmly does with data. The operator, and the data controller, is Nicholas Webster.
Warmly is built to know as little about you as possible. There are no accounts, no names, no email addresses, no profiles and no advertising.
1. Summary
- We do not ask for, or hold, your name, email address, phone number or date of birth.
- Your device identifies itself with an anonymous cryptographic key. We cannot link it to you.
- We store the location of each message you leave, because that is what the app does. We do not keep a history of where you go.
- We do not sell data, share it with advertisers, or use it for advertising or profiling.
- There is no analytics or tracking SDK in the app.
2. What we collect
A device identifier. Your device generates a cryptographic key, held in its secure hardware, and identifies itself to us with the public part of that key. We store an identifier derived from it. It is not linked to you, your Apple ID, or any other service, and it does not travel to a new device.
The messages you leave, and the latitude and longitude of the place you left them, and the time you left them.
Your current location, at the moment your device asks for nearby messages. Your device sends its position so we can return the nearest messages waiting for you. We use it to answer that request and we do not store it. We do not receive a continuous stream of your location, and we do not build a movement history.
A push notification token, so we can notify you when a message arrives or when someone likes what you left.
Reports. If you report a message, we store the message, the fact it was reported, and the identifier of the device that sent it.
3. What we do not collect
Server logs. We do not keep access logs. Our servers do not record the IP addresses of requests.
We also do not collect contacts, photos, calendar, health data, advertising identifiers, browsing activity, or any other data from your device. We do not use cookies or tracking pixels in the app.
4. Why we are allowed to use it (legal bases)
- To provide the service you asked for, we rely on performance of a contract: your device identifier, your messages, their locations, and your push token.
- To keep Warmly safe and lawful, we rely on legitimate interests: checking messages, handling reports, blocking abusive senders, rate limiting, and server security.
- To send notifications, we rely on your consent, given to iOS. You can withdraw it in Settings at any time.
- Location access is granted by you through iOS and can be withdrawn in Settings. Withdrawing it stops the app working.
5. Message checking
Every message is checked automatically before it is made available to anyone, using a language model provided by Anthropic. The message text is sent to Anthropic for that check. It is not used to train models. No location, device identifier or other data accompanies it.
No human reads messages routinely. A message is only read by a person if it is reported.
6. Who else is involved
We use a small number of providers, who process data on our instructions:
| Provider | What they do |
|---|---|
| DigitalOcean | Hosts our servers and database |
| Anthropic | Runs the automated message check |
| Apple | Delivers push notifications, and provides the device attestation used for the anonymous identifier |
We do not share data with anyone else, except where we are legally required to.
Some of these providers operate outside the UK and EEA. Where data is transferred, it is protected by appropriate safeguards such as standard contractual clauses.
7. How long we keep things
| Data | Retention |
|---|---|
| A message you left that has not been delivered | Until it is delivered or you delete it. There is no expiry. |
| A message that has been delivered but not hearted | Deleted 7 days after delivery |
| A message that has been hearted | Deleted immediately |
| A message you received | Shown once, then gone. Held on your device only until dismissed. |
| Your push token | Until replaced, or the app is uninstalled and the token goes stale |
| Reports | Kept indefinitely as a safety record |
| Blocked device identifiers | Kept indefinitely, so a block holds |
8. Your rights
Under UK and EU data protection law you have rights to access, correct, delete, restrict, object to, and port your personal data, and to complain to a regulator.
There is an important practical limit. Warmly holds no information that identifies you. We cannot connect a request from you to any data we hold, because we have no way to verify that a given device is yours. So we usually cannot action an access or deletion request, because we cannot find your data and could not safely give it to you if we could.
What you can do instead:
- Delete any message you left that has not yet been delivered, from within the app.
- Delete the app. Your device identifier is destroyed with it and cannot be recovered by anyone, including us.
- Turn off location or notifications in iOS Settings.
If you believe we hold data about you and can tell us enough to find it, contact us and we will do what we reasonably can.
To complain, contact the Information Commissioner's Office at ico.org.uk, or your local supervisory authority.
9. Children
Warmly is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child is using Warmly, contact us and we will act.
10. Security
Traffic between the app and our servers is encrypted in transit. Access to our servers and database is restricted. Your device identifier is held in your device's secure hardware and cannot be extracted from it.
No system is perfectly secure, but note that a breach of our database would expose message text and the locations of messages, not names, emails or identities, because we do not hold any.
11. Changes
We may update this policy. The current version is always available here.
12. Contact
Please use the contact form linked at the bottom of this page.