Email policy

Email from WarmLoop

Last updated October 7, 2026

This page covers the email sent for the WarmLoop research service and WarmLoop Record, the service our Terms of Service describe. It is sent for three reasons: something a person asked for, something a customer did about one of its records or its organization account, and the legal, account, billing, security and service notices our Terms of Service require. Every message is transactional and goes to one recipient. There is no newsletter, no marketing list and no bulk mail, and WarmLoop sends no marketing email unless you have separately agreed to receive it.

Automated messages from WarmLoop come only from no-reply@mail.warmloop.com, including account sign-up and password-reset codes and receipts. Messages from a person at WarmLoop come from info@warmloop.com or privacy@warmloop.com. A message claiming to be from WarmLoop from any other address is not from us. WarmLoop never asks for a sign-in code by phone or by reply, never sends attachments, and links only to warmloop.com, account.warmloop.com, mcp.warmloop.com, record.warmloop.com or a Stripe-hosted page.

What we send, and to whom

MessageWho receives itWhat triggers it
One-time sign-in codeA reader of a record a customer has sharedThe reader enters their own email address on the record's access page and asks for a code. The code, and the sign-in link sent with it, expire in ten minutes and work once.
Access requestedThe author of the record, or WarmLoop if no author address is foundSomeone asks to read a record on its access page. The message carries one link, which opens a page where the author approves or denies the request, once, within 14 days.
Access approvedThe person who asked to read the recordThe author approves the request. The message links to the record. A denial sends no message.
Published, needs attention, or failedThe person who published the record, at their own account addressA publish job finishes, stops on a finding the author must resolve, or fails, including when the virus scan rejects an upload.
A publish waiting for a decisionThe organization's owners and administrators and, for a new version of a published record, the record's author, except the person who askedSomeone asks through their AI assistant to publish a record, and the publish waits for a confirmation in a WarmLoop account. The message names who asked and the record's title, and links to the page where the request is confirmed or refused. It is sent once for each request.
A change to a record confirmedThe organization's owners, the person who confirmed the change and the person who asked for itA request to make a record public, to add a reader or to publish is confirmed in a WarmLoop account. The message says what changed, who confirmed it, when, and from which network address where it is known.
Confirmation of record changes turned on or offThe organization's ownersSomeone turns the organization's confirmation of record changes on or off. The message names who did it and when.
A record deletedThe organization's ownersSomeone other than an owner deletes one of the organization's records on the Records page. The message names who deleted it, the record's title and address, and the date on which it will be erased.
Invitation to an organization accountThe invited personAn owner or administrator of an organization account invites that address. The message names the inviter and the organization, its link expires in 7 days, and it carries a link to stop further invitations to that address.
Confirmation of a certificationThe person who certified, and the organization's owner where an administrator certifiedAn organization certifies that it holds the rights to a collection of licensed documents. The message carries the statement accepted, section 27 and clauses 17.1 and 17.5 of the Terms of Service, and a link to revoke the certification.
Account sign-in codeA person signing in to a WarmLoop account with Google, or with Microsoft where the sign-in does not show that a second factor was used, at the account's addressThe person completes the Google or Microsoft sign-in, or asks for the code again. The subject line is the six-digit code followed by "is your WarmLoop sign-in code". The code expires in ten minutes and works once, and the sign-in finishes only when it is entered in the same browser.
Account sign-up and password-reset codeA person who creates a WarmLoop account with an email address and password, or resets that passwordThe person signs up, or asks to reset the password. Amazon Cognito, the Amazon Web Services sign-in service WarmLoop accounts use, sends it from no-reply@mail.warmloop.com through Amazon Simple Email Service, like WarmLoop's other messages. An account that signs in with Google or Microsoft receives none of these.
Legal, account, billing, security and service noticesThe account holder, at the account addressA change to the Terms of Service, a fee or the Privacy Policy; planned maintenance; a payment problem, suspension, termination or withdrawal of the service; a security incident that affects you; a notice about one of your records. Our Terms of Service require these, so they cannot be turned off while the account is open.
Receipts and billing noticesThe owner and the administrators of the organization accountA subscription starts or is renewed (a receipt, with a link to its invoice); a payment does not go through, a last notice before the subscription ends, and its end; a change of seats, a cancellation or its undoing, and a new card given on the Organization page. WarmLoop's own system sends these, with a link to the invoice where there is one and never an attachment or a card detail. Stripe, our payment processor, takes the payments.
Operational alertWarmLoop's own operator mailboxA service event WarmLoop staff need to act on. Never sent to customers.

How addresses reach us

Every address reaches us in one of four ways: the address a person signs up or signs in with; an address a signed-in customer enters for a specific matter, as a named reader of a record; an address an owner or administrator of an organization account enters to invite a person; or an address a person enters on a record's access page to ask for a code or for access. WarmLoop does not import, buy, scrape, rent or share address lists. Recipients are our customers, the people our customers name as readers of their records or invite to their organization accounts, and people who sign up or ask to read a record.

How to stop a message

Bounces, complaints, and abuse

An address that bounces or that reports a WarmLoop message as unwanted is placed on our suppression list automatically and is never sent to again. Our operator is notified of every bounce and complaint and also removes the address from the customer's reader list. To report a message you believe is abusive or not from us, forward it with its headers to info@warmloop.com.

Authentication

Mail from mail.warmloop.com is DKIM-signed with a 2048-bit key. The domain publishes an SPF record that authorizes only our sending service and a DMARC policy of reject, so a message that fails authentication is refused by receiving mail systems that honour DMARC rather than delivered. Mail is sent through Amazon Simple Email Service in the Canada (Central) region.

Related pages

How we handle personal information is in the Privacy Policy. The terms on which the service is provided are in the Terms of Service.