Privacy Policy
Miles ("the app") is a personal travel log for iPhone, published by Thomas Gray. This page explains, in plain English, what stays on your device, what leaves it and why, and what we can see. The honest answer to that last one is: essentially nothing.
Last updated: 14 August 2026
Summary
- Your trip history is stored only on your iPhone, in a local database. There is no Miles account, no login, and no Miles server that holds your data.
- We never receive your trips, routes or places. We could not read your travel history even if we wanted to, because it never reaches us.
- The app sends analytics and crash reports (via Google Firebase) so we can fix bugs and improve the app. Analytics events never include coordinates or place names, and the log lines attached to crash reports are scrubbed of them before upload.
- To name places and answer questions like "which station is this?" or "what was the weather?", the app sends individual coordinate lookups to Apple's geocoding service and to open mapping and transport services. No Miles account or identifier travels with them.
- Private Areas let you draw zones around sensitive places. Trip start and end points inside a Private Area are left out of exports, shared images and the iPhone search index.
- You can export everything as CSV for free, and delete everything in two taps. Raw GPS points are pruned automatically after 7 days.
- We do not track you across other companies' apps or websites, we do not build advertising profiles, and we do not sell or share your data.
What stays on your phone
Everything that describes your travel lives only on your iPhone, in a local database (Apple's SwiftData), protected by your device's own encryption, passcode and biometrics:
- Location data: GPS coordinates recorded during detected trips
- Motion data: activity signals (walking, driving and so on) from your device's motion sensors
- Trip records: start and end points, distances, durations, transport modes and route paths
- Corrections: any changes you make to a trip's transport mode
- Learned patterns: route patterns and preferences derived from your trips
- Saved locations and Private Areas: the places and zones you define
None of these records is uploaded to us or synced to any server. If you delete the app, this data is deleted with it.
One qualification, so the sentence above stays exactly true: Miles does send anonymous diagnostics about how it classified a trip. Those include summary percentages of the motion activity for that trip (for example "82 % walking") and short codes naming which signals decided the result. They carry no coordinates, no place names and no routes, they are not linked to your identity, and they include no heart rate, no workout and no other Health measurement. One honest detail: if you grant Health access, both a matching workout and an elevated average heart rate can change which transport mode a trip is labelled with, and that label is included. They are described in full under Analytics and crash reports.
Optional permissions: extra data the app can read, all on-device
Beyond location and motion, Miles can use a few more data sources if, and only if, you grant the matching iOS permission. Every one of them is processed on your iPhone and none of it ever leaves the device:
- Health workout data (HealthKit): read-only. Your workouts help Miles classify trips more accurately (a logged run confirms a running trip). Miles never writes to HealthKit, and your health data never leaves the device.
- Calendar titles: read to add context to a trip (the meeting you were travelling to). Titles are matched on-device and never leave your iPhone.
- Photo library: Miles matches photos to trips by time and place, entirely on-device. Your photos are never uploaded anywhere.
- Microphone: voice memos you record on a trip are stored on-device alongside the trip and never leave your iPhone.
Decline any of these permissions and the related feature simply stays off; nothing else in Miles changes.
What leaves your phone
Three categories of network traffic exist, and this is all of them.
1. Analytics and crash data. The app uses Firebase Analytics and Firebase Crashlytics (services provided by Google). Firebase Performance Monitoring collection is switched off in the shipping app. What is sent: your device model, iOS version, app version, a device identifier created for analytics, and product interaction events (which screens are viewed, which features are used, subscription events, trip classification events such as mode and confidence). The app is designed to keep coordinates, routes and place names out of this data: analytics events never include them, and diagnostic log lines are scrubbed of coordinates, place names and route identifiers before they are attached to crash reports. See "Analytics and crash reports" below.
2. Coordinate lookups for app features. To name the places you visit, the app uses Apple's geocoding service: the coordinates of a trip's start and end are processed by Apple under Apple's privacy policy, just as they are in any maps app. To identify a station or flight, or fetch weather and elevation, the app also asks open mapping and transport services about specific coordinates. The open services used are OpenStreetMap Overpass, Open-Meteo (weather), Open-Elevation, Transitland, OpenSky, and regional public transport providers such as Transport for London, Deutsche Bahn, Entur and others. These are lookups, not uploads: the coordinates of an individual trip are used to answer the query, and no Miles account or identifier is attached, because none exists. Downloading an offline map pack reduces the lookups to the open mapping services.
3. Offline map pack downloads. You can optionally download offline geometry packs, which are hosted on Firebase Storage. A download is a plain file fetch: no user data is sent.
What we can see
Essentially nothing. Miles has no server that holds user data, no user database, and no accounts. There is nothing to log in to and nothing for us to look you up in.
What we do see is aggregate: anonymous style analytics dashboards (how many people used a feature, which iOS versions are common) and crash reports that tell us a crash happened on a given device model. We cannot see your trips, your map, your places or your history, and we cannot connect analytics data to you as a person.
Private Areas
Private Areas add an extra layer of discretion for places like home or work. You draw a zone, and any trip start or end point that falls inside it is omitted from:
- CSV exports
- Shared trip images
- The iPhone search index (Spotlight)
- Answers from Siri, and trips handed to Shortcuts
For context on that third and fourth point: Miles adds your trips to your iPhone's own on-device search index, so you can find a journey from Spotlight or ask Siri about it. That index lives on your device and is never sent anywhere. Trips touching a Private Area are left out of it entirely, and out of anything Siri says or passes to Shortcuts. If you would rather Miles did not do this at all, turn off Let Siri & Search see your trips in More.
Inside the app on your own device, your trips remain complete. Private Areas control what leaves the app when you export or share.
Analytics and crash reports
We use Firebase Analytics and Crashlytics to understand crashes and which features matter. Firebase Performance Monitoring collection is deactivated in the shipping app. The data sent is described above: device model, iOS version, app version, a device identifier used for analytics, product interaction events, and per-trip classification diagnostics (transport mode, confidence, distance, duration, timestamps, speed and signal-quality summaries, summary percentages of the trip's motion activity, and short codes naming which signals decided the classification). It is behavioural data about the app, not about your travel: analytics events include no GPS coordinates, routes or place names, and the diagnostic log lines attached to crash reports are scrubbed of coordinates, place names and route identifiers before they leave the device.
This matches the app's App Store privacy label: Precise Location is used only for App Functionality and is not linked to your identity; Device ID and Product Interaction are used for Analytics and are not linked to your identity; Crash Data is used for App Functionality and Analytics and is not linked to your identity. No data is used to track you across other companies' apps or websites.
Firebase processes this data in accordance with Google's data processing terms.
Data retention and deletion
- Trip records stay on your device until you delete them.
- Raw GPS points are pruned automatically after 7 days; only the simplified trip record is kept.
- Delete everything in two taps: the Delete All Data action in the app's settings permanently removes all trip data from your device. Deleting the app does the same.
- Analytics and crash data is retained by Google Firebase for limited periods under its standard retention settings. Because it is not linked to your identity, we cannot single out and delete "your" analytics records, and neither can anyone else.
Your choices and rights
You control the data, mostly because you are the only one holding it:
- Access: everything the app knows is visible inside the app.
- Export (portability): export your full trip history as CSV, free for everyone.
- Erasure: use Delete All Data in the app's settings, or delete the app.
- Permissions: revoke location or motion access at any time in iOS Settings. Miles will stop detecting new trips but will not lose your history.
- Reduce lookups: download an offline map pack to cut down coordinate lookups to external services.
For users in the European Economic Area and the UK: the legal basis for the processing described here is legitimate interest in providing and improving the service you asked for. Because your travel data never leaves your device and analytics data is not linked to your identity, most GDPR rights (access, portability, erasure) are satisfied directly by the in-app tools above. For anything else, contact us and we will do our best to help.
Children
Miles is not directed at children under 13, and we do not knowingly collect data from children.
Changes
If we change this policy, the new version will be posted on this page with an updated date. If a change ever means more data would leave your device, we will say so prominently in the app, not bury it here.
Contact
Questions about this policy or your data: miles.support.app@gmail.com