Email from WarmLoop
This page covers the email sent for the WarmLoop research service and WarmLoop Record, the service our Terms of Service describe. It is sent for three reasons: something a person asked for, something a customer did about one of its records or its organization account, and the legal, account, billing, security and service notices our Terms of Service require. Every message is transactional and goes to one recipient. There is no newsletter, no marketing list and no bulk mail, and WarmLoop sends no marketing email unless you have separately agreed to receive it.
Automated messages from WarmLoop come only from no-reply@mail.warmloop.com, including account sign-up and password-reset codes and receipts. Messages from a person at WarmLoop come from info@warmloop.com or privacy@warmloop.com. A message claiming to be from WarmLoop from any other address is not from us. WarmLoop never asks for a sign-in code by phone or by reply, never sends attachments, and links only to warmloop.com, account.warmloop.com, mcp.warmloop.com, record.warmloop.com or a Stripe-hosted page.
What we send, and to whom
| Message | Who receives it | What triggers it |
|---|---|---|
| One-time sign-in code | A reader of a record a customer has shared | The reader enters their own email address on the record's access page and asks for a code. The code, and the sign-in link sent with it, expire in ten minutes and work once. |
| Access requested | The author of the record, or WarmLoop if no author address is found | Someone asks to read a record on its access page. The message carries one link, which opens a page where the author approves or denies the request, once, within 14 days. |
| Access approved | The person who asked to read the record | The author approves the request. The message links to the record. A denial sends no message. |
| Published, needs attention, or failed | The person who published the record, at their own account address | A publish job finishes, stops on a finding the author must resolve, or fails, including when the virus scan rejects an upload. |
| A publish waiting for a decision | The organization's owners and administrators and, for a new version of a published record, the record's author, except the person who asked | Someone asks through their AI assistant to publish a record, and the publish waits for a confirmation in a WarmLoop account. The message names who asked and the record's title, and links to the page where the request is confirmed or refused. It is sent once for each request. |
| A change to a record confirmed | The organization's owners, the person who confirmed the change and the person who asked for it | A request to make a record public, to add a reader or to publish is confirmed in a WarmLoop account. The message says what changed, who confirmed it, when, and from which network address where it is known. |
| Confirmation of record changes turned on or off | The organization's owners | Someone turns the organization's confirmation of record changes on or off. The message names who did it and when. |
| A record deleted | The organization's owners | Someone other than an owner deletes one of the organization's records on the Records page. The message names who deleted it, the record's title and address, and the date on which it will be erased. |
| Invitation to an organization account | The invited person | An owner or administrator of an organization account invites that address. The message names the inviter and the organization, its link expires in 7 days, and it carries a link to stop further invitations to that address. |
| Confirmation of a certification | The person who certified, and the organization's owner where an administrator certified | An organization certifies that it holds the rights to a collection of licensed documents. The message carries the statement accepted, section 27 and clauses 17.1 and 17.5 of the Terms of Service, and a link to revoke the certification. |
| Account sign-in code | A person signing in to a WarmLoop account with Google, or with Microsoft where the sign-in does not show that a second factor was used, at the account's address | The person completes the Google or Microsoft sign-in, or asks for the code again. The subject line is the six-digit code followed by "is your WarmLoop sign-in code". The code expires in ten minutes and works once, and the sign-in finishes only when it is entered in the same browser. |
| Account sign-up and password-reset code | A person who creates a WarmLoop account with an email address and password, or resets that password | The person signs up, or asks to reset the password. Amazon Cognito, the Amazon Web Services sign-in service WarmLoop accounts use, sends it from no-reply@mail.warmloop.com through Amazon Simple Email Service, like WarmLoop's other messages. An account that signs in with Google or Microsoft receives none of these. |
| Legal, account, billing, security and service notices | The account holder, at the account address | A change to the Terms of Service, a fee or the Privacy Policy; planned maintenance; a payment problem, suspension, termination or withdrawal of the service; a security incident that affects you; a notice about one of your records. Our Terms of Service require these, so they cannot be turned off while the account is open. |
| Receipts and billing notices | The owner and the administrators of the organization account | A subscription starts or is renewed (a receipt, with a link to its invoice); a payment does not go through, a last notice before the subscription ends, and its end; a change of seats, a cancellation or its undoing, and a new card given on the Organization page. WarmLoop's own system sends these, with a link to the invoice where there is one and never an attachment or a card detail. Stripe, our payment processor, takes the payments. |
| Operational alert | WarmLoop's own operator mailbox | A service event WarmLoop staff need to act on. Never sent to customers. |
How addresses reach us
Every address reaches us in one of four ways: the address a person signs up or signs in with; an address a signed-in customer enters for a specific matter, as a named reader of a record; an address an owner or administrator of an organization account enters to invite a person; or an address a person enters on a record's access page to ask for a code or for access. WarmLoop does not import, buy, scrape, rent or share address lists. Recipients are our customers, the people our customers name as readers of their records or invite to their organization accounts, and people who sign up or ask to read a record.
How to stop a message
- Sign-in codes are sent only when you ask for one. If you did not ask for a record's code, ignore the message; nothing happens without the code. An account sign-in code you did not expect means someone else may be using your Google or Microsoft account: do not share the code, secure that account, and tell us at info@warmloop.com.
- Access to a record can be ended by the customer that shared it at any time, which stops every message about that record. Ask them, or write to info@warmloop.com and we will pass the request on promptly.
- Invitations to an organization account carry a link that stops further invitations to your address.
- Legal, account, billing, security and service notices go to the account address for as long as the account is open, because our Terms of Service require them.
- Any other category can be turned off for your address by writing to privacy@warmloop.com, a mailbox a person reads. Say which message you received and we will stop it; if the only way to do that would stop all WarmLoop email to your address, we will tell you first.
Bounces, complaints, and abuse
An address that bounces or that reports a WarmLoop message as unwanted is placed on our suppression list automatically and is never sent to again. Our operator is notified of every bounce and complaint and also removes the address from the customer's reader list. To report a message you believe is abusive or not from us, forward it with its headers to info@warmloop.com.
Authentication
Mail from mail.warmloop.com is DKIM-signed with a 2048-bit key. The domain publishes an SPF record that authorizes only our sending service and a DMARC policy of reject, so a message that fails authentication is refused by receiving mail systems that honour DMARC rather than delivered. Mail is sent through Amazon Simple Email Service in the Canada (Central) region.
Related pages
How we handle personal information is in the Privacy Policy. The terms on which the service is provided are in the Terms of Service.