Privacy Policy

Last updated 2026-09-25

The short version

Milespie has no ads, no analytics tracking, doesn’t sell data, and doesn’t do anything with your itineraries that you didn’t ask for. Everything below spells out exactly which data is involved — what’s written here is all of it.

What an account needs

Accounts can only be created inside the iOS app with Sign in with Apple. Signing in on the web with the same Apple ID gets you the same account. Your password never passes through us.

From Apple we receive an identifier for your Apple ID, your email (if you chose “Hide My Email”, this is Apple’s relay address, not your real inbox), and the name you chose to share the first time you signed in. These are stored with your account.

When you sign in, the app also sends Apple’s signed proof of purchase (StoreKit’s AppTransaction). We verify it really comes from Apple and is for this app before creating an account. If an Apple ID that never bought the app signs in on the web, we create no account and keep no data.

What you put in

Everything in your trips is stored in Cloudflare’s D1 database: trip names and dates, each day’s items, transit legs, places, costs, notes, tags, checklists and reminder times. New accounts come with a sample trip you can simply delete.

Images you upload are stored in Cloudflare R2, including QR codes and e-tickets you mark as credentials. Only your account (and travel companions you invite to a party) can read them.

All three kinds of sharing are opt-in and can be turned off any time:

  • Showcase link: anyone with the link can view the trip, without costs, credentials or booking references.
  • Recipe link: anyone with the link can copy the trip into their own account. They get a snapshot; later edits don’t follow.
  • Party: members you invite can read and edit the trip, including attachments. Attachments a member uploads count against their own quota.

What gets sent to Google

Our server forwards the following to Google, who handles it under their own privacy policy. Only the query itself is sent — never your account, name or email.

  • Place search (Google Places API): what you type in a place field, and the place you pick.
  • Route lookup (Google Routes API): the coordinates of the start and end points, and the departure time.
  • Map thumbnails (Maps Static API): the coordinates to draw.

When you paste a Google Maps short link, our server follows it to read the start and end points inside.

Results are cached on our side for a while to call Google’s API less often. The cache holds the places and images themselves, not who searched for what.

Your location

“Sort by distance” asks for location permission when you tap it. Your location is only used on your device to sort; it is never sent to our server or stored.

The app side

The iOS app has no analytics and no third-party SDKs. Apart from the sign-in and proof of purchase above, it only syncs trips with your own account.

Your trips live in a database on your phone, credential images are cached in the app’s files (so the QR still opens in airplane mode), and your sign-in credential lives in the iOS Keychain. Home Screen widgets and Live Activities keep a snapshot of what’s next on your phone. None of this leaves your phone except to sync with your own account.

A few technical records

Purchase verification record: which purchase your account was created with (Apple’s transaction identifier and environment), plus the credential we use to revoke Sign in with Apple when you delete your account. This is how one purchase maps to one account.

Hashed device identifier: when signing in, the app sends iOS’s identifier for vendor to confirm the proof of purchase came from this device. We store only a hash of it, used to retire old sign-in credentials when the same device signs in again. It only means something to Milespie and can’t be used to track you across apps.

Sign-in records: web sign-in sessions record the IP address and browser information at the time, and are deleted when the session expires or the account is deleted.

Daily usage counts: for the four features we pay Google for — place search, place details, route lookup and map thumbnails — we keep a daily count to stop abnormal usage. Counts, not content.

How to delete it

In the app, go to Settings → Account → Delete Account, or use the Account page on the web. Both do the same thing: permanently delete your account, all trips, the images in R2, the purchase verification record and sign-in records. This can’t be undone. We also ask Apple to revoke Milespie’s Sign in with Apple authorization.

Deleting your account doesn’t affect your App Store purchase: sign in with Apple again and the app re-verifies the purchase and opens a brand-new, empty account.

To leave on one device without deleting anything, use “Sign Out” in the app’s settings — your data stays.

The copy on your phone is cleared separately: delete the app, and iOS removes its local database and caches with it.

If this policy changes

Changes update the date at the top of this page. If a change concerns something substantive — what your data is used for — we’ll also send an email about it.

Contact

For questions, or to request access to or deletion of your data, email support@milespie.com. Milespie is built and run by Anderson Hu, an independent developer.

Privacy Policy · Milespie · Milespie