Last updated 24 August 2026
This explains what Myles Inc. collects, why, and who else sees it.
Two things worth saying first. Myles has no passwords, so there are none to store or leak. And your card details never reach our servers: payment is handled entirely by Stripe.
One cookie, used to keep you signed in. It is HttpOnly, Secure and SameSite=Lax, and it holds a random session identifier and nothing else. Signing out removes it. There are no advertising or analytics cookies.
We use a small number of providers, each for one job:
We do not sell your data or share it for advertising.
Account data is kept while your account exists. Sign-in tokens expire after 15 minutes and sessions after 30 days, and expired records are cleared automatically. If you close your account we delete your account data within 30 days, except where we must keep billing records for tax and accounting purposes.
Email support@runmyles.com to get a copy of your data, correct it, or have your account and data deleted. Depending on where you live you may have additional rights, and we will honour valid requests.
Data is encrypted in transit. Credentials are stored as one-way hashes. Access to production systems is limited to the operator. No system is perfectly secure, and we cannot guarantee absolute security.
Myles is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
If we change this policy materially we will tell you by email or in the application before it takes effect.