Privacy Policy
Last updated September 2026 · Operated by WarmUp, Inc.
What we collect
- Employer accounts: your email address, used to create your account and send you sign-in links. No passwords are stored because we don’t use passwords.
- Candidate profiles: the information candidates submit about themselves (name, photo, location, work history, skills, preferences) for the purpose of being presented to hiring companies.
- Interview requests: which signed-in employer asked about which candidate, so we can coordinate the interview.
- Certification waitlist: the email address you give us, so we can tell you when certification opens. You can leave it from the empty directory page or, once you’ve had a conversation, from the optional prompt at the end of a chat with our AI assistant. Either way it goes on the same list.
- Operational records: short-lived rate-limit counters (which may be keyed by network address) to prevent abuse of our forms.
- Website analytics and visitor identification: on our public pages (not inside the signed-in portal) we use Microsoft Clarity to see how the site is used, and lemlist to tell us which companies visit and, for visitors in the United States, sometimes who. Details and how to opt out are under “Analytics and visitor identification” below.
- Public AI assistant conversations: If you chat with the assistant on our public site, we save the conversation with a non-reversible fingerprint of your network address for abuse review. These records are not linked to a candidate or employer account. Our scheduled cleanup removes public conversations older than 90 days.
- Profile assistant conversations: If profile assistance is available and you use it while signed in, we save the conversation linked to your candidate profile. These conversations do not have a scheduled age-based deletion period. They are deleted when your candidate record is deleted.
- Resume imports: When you upload a PDF to fill in your profile, we send it to our AI provider to suggest profile information. That import does not store the PDF itself. Information you choose to keep is saved on your profile.
- Resumes kept for screening: A resume you provide during screening, or that our team uploads to your candidate record, is stored so our team can review it. We may also send it to our AI provider to help with screening or, when you request available profile assistance, suggest profile information. The stored resume is replaced when another is uploaded and deleted when your candidate record is deleted.
What we don’t do
- No advertising pixels and no ad retargeting.
- No sale of personal information to anyone.
- Inside the signed-in portal, the only cookie we set is the session cookie that keeps you signed in. Our public pages also carry the two services described in the next section.
How information is used and shared
Published candidate profiles are listed in a directory that only signed-in hiring companies can browse. An individual profile can also be opened by anyone holding its link, so it can be shared without the recipient needing an account. Published profiles are excluded from search-engine indexing. We share data only with the service providers that run the product: Supabase (database and file storage), Vercel (hosting), Resend (transactional email), and Anthropic, the AI provider that reads uploaded resumes and powers our AI assistant. Each processes data on our behalf.
Analytics and visitor identification
Our public pages use two third-party services. Neither service loads on the signed-in portal pages (/admin, /onboard, /ask, /favorites, /login, /auth).
Microsoft Clarity. We use Microsoft Clarity to understand how visitors use our website: behavioural metrics, heatmaps, and session replays of clicks, scrolls, and page rendering. Clarity sets first- and third-party cookies to do this. We use the information to improve the site. Microsoft processes this data as a data controller and stores it on Microsoft Azure; how Microsoft collects and uses data is in the Microsoft Privacy Statement.
lemlist website visitors. We use lemlist to identify the companies that visit our public pages, from your network address and similar signals, so our sales team knows which businesses are interested in working with us. For visitors in the United States, lemlist may also match a visit to a person’s name, job title, and public LinkedIn profile using its identification partners; that only happens where lemlist can confirm the visitor is in the US. We use this to decide whom to contact and how; we never sell it. lemlist’s handling of this data is described in the lemlist privacy policy.
Your choices. Blocking third-party scripts or cookies in your browser stops both services. To ask lemlist not to identify you, or to have your details removed from what it holds, write to privacy@lemlist.com. To ask us to delete anything we hold about your visit, email mike@sendwarmup.com and we will take care of it.
Retention and your choices
Expired sessions, sign-in tokens, invites, and rate-limit records are deleted automatically on a nightly schedule. Candidate profiles persist until the candidate or our team removes them. If you have an account, you can take your profile off the public directory yourself, at any time, from Privacy & account in your dashboard. It happens immediately and you can put it back up the same way. You can also delete your account and everything attached to it from that same page, it happens immediately and cannot be undone. To access or correct your information, or to come off the waitlist, email mike@sendwarmup.com and we’ll take care of it.
Changes
If this policy changes in a way that matters, we’ll update this page and adjust the date above.