PRIVACY POLICY

Your data stays yours

Last updated: July 2026

1. The short version

MileMori is local-only by default. If you continue without a database account, your survey answers, health inputs, stops, check-ins, route history, badges, and coach conversation history stay in your browser's local storage; downloading and keeping backups is your responsibility before clearing browser data or changing devices. If you create a username/password account in Settings, the same profile is copied to the configured Neon database for backup and sync. You can export everything as JSON or delete the local copy at any time in Settings.

2. What we process and where

On your device by default: birth date, sex selection, country, height/weight (BMI), lifestyle answers (smoking, alcohol, exercise, sleep, diet, stress), optional health answers (chronic conditions, treatment status, family longevity), interests and route-around preferences, stops, check-ins, habit transitions, points/badges, and coach chat history. Under privacy laws such as GDPR and other local frameworks, several of these may be special-category (health) data — which is why database backup stays opt-in.

Optional database account: cloud backup requires a separate explicit consent because the profile can contain health and lifestyle answers. If you consent and create an account, MileMori stores your username, a salted password hash, session records, the consent timestamp/version, and an AES-256-GCM encrypted copy of your profile in Neon Postgres. The profile encryption key is held separately in the application environment. Passwords are never stored directly.

Kervans and social plans (optional): when you use Together, MileMori stores Kervan membership, invite codes, stop suggestions, date/place options, votes, RSVP and event-day status, shared memory notes, notification state, blocks and reports in separate relational tables. These records are visible only to members of that Kervan, except short-lived invite codes you choose to share. They never contain your health survey, birth date, life-horizon estimate, private road calculation or coach chat. A planned meeting place is not live location: continuous location sharing is not collected.

GPS surprise (optional): if you enable it in Settings, your device location is read at most once a day and compared against your route entirely on your device — coordinates are never transmitted or stored anywhere except the resulting "moment" note in your local data. It is off by default.

Sent to third parties or processors: map tiles are fetched from CARTO/OpenStreetMap; place search and reverse geocoding use OSM Nominatim; road geometry uses OSRM servers; fonts load from Google Fonts. These requests contain coordinates and standard technical data (IP address, user agent) as any web request does — never your survey answers. If the AI coach proxy is configured, your coach message and a derived route snapshot pass through MileMori's serverless function and are sent to the configured AI provider (for example Anthropic, under its privacy terms, or another compatible provider) — never your raw survey answers. If you use the Feedback tab or the Contact form, your message, optional name and reply email, topic, and only the app context you leave checked (such as language, route label, app version, user agent) pass through MileMori's serverless function and are sent by email through Resend to the operator's inbox, together with the IP address carried by the request. MileMori does not store those coach, feedback, or contact requests server-side in this version.

3. Anonymous community stats (optional)

Anonymous statistics are off until you make a choice. If you allow them, MileMori can send a small set of anonymous, allowlisted events to its own serverless endpoint for product funnels, retention cohorts and community numbers. What is sent: a random install identifier, local calendar day, onboarding milestone names, route city names, route length, a broad age band, a 5-year horizon bucket, stop categories, and simple counters. Your choice can be changed in Settings.

What is never sent for community stats: your survey or health answers, your birth date, your exact age or horizon estimate, and the text of stops you write yourself — free-text stop titles stay on your device; only curated catalog suggestions are counted by title. If Neon is configured, the same allowlisted event details may also be stored in an analytics table for product statistics, including account-created and profile-sync events. If you turn off Settings → "Anonymous community stats", those account/sync records keep only a minimal opt-out marker instead of route or age-band details. Popular-lists are shown only after several travelers share an entry.

4. What we don't do

No mandatory account for the private road tools, no third-party analytics trackers, no advertising SDKs, no cookies set by us, and no selling of personal data. An account is required only for database backup/sync and private Kervan coordination. There is no public social feed, follower count, stranger discovery or continuous live-location service. The optional AI proxy is used only to answer coach requests. The optional contact and feedback endpoints are used only to deliver your message to the operator.

5. Your privacy rights

Access and portability: Settings → "Download my data" exports the private road profile as JSON. Local erasure: Settings → "Delete all my data" removes everything from this device immediately and irreversibly. Rectification: update any answer anytime from Profile; if you are signed into database backup, the updated local profile syncs to the account copy. Leaving a Kervan removes your membership; muting stops its social notifications; blocking hides that person's social activity. Deleting the database account permanently cascades through its profile, memberships, suggestions, votes, RSVPs, memories, blocks and notification records. For privacy questions, use the contact form and choose the "Privacy / legal" topic.

6. Children

MileMori is for users 18 and over. We do not knowingly serve minors; the age gate is the first onboarding step.

7. Database backup

Database backup remains opt-in and requires explicit health/lifestyle-data consent. Profiles are encrypted by the application before database storage. Multi-device writes use version checks: if two devices change the same road, MileMori stops and asks which copy to keep instead of silently overwriting one. Local-only stays available.

8. Changes & contact

Material changes will be announced in-app before they take effect. Privacy questions and product feedback: the contact form.