Privacy Policy

Last updated 24 August 2026

This explains what Myles Inc. collects, why, and who else sees it.

Two things worth saying first. Myles has no passwords, so there are none to store or leak. And your card details never reach our servers: payment is handled entirely by Stripe.

What we collect

What we do not collect

Cookies

One cookie, used to keep you signed in. It is HttpOnly, Secure and SameSite=Lax, and it holds a random session identifier and nothing else. Signing out removes it. There are no advertising or analytics cookies.

Who else sees your data

We use a small number of providers, each for one job:

We do not sell your data or share it for advertising.

How long we keep it

Account data is kept while your account exists. Sign-in tokens expire after 15 minutes and sessions after 30 days, and expired records are cleared automatically. If you close your account we delete your account data within 30 days, except where we must keep billing records for tax and accounting purposes.

Your choices

Email support@runmyles.com to get a copy of your data, correct it, or have your account and data deleted. Depending on where you live you may have additional rights, and we will honour valid requests.

Security

Data is encrypted in transit. Credentials are stored as one-way hashes. Access to production systems is limited to the operator. No system is perfectly secure, and we cannot guarantee absolute security.

Children

Myles is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

Changes

If we change this policy materially we will tell you by email or in the application before it takes effect.

Contact

support@runmyles.com