This document is a working foundation, not a final legal policy. Every item marked [TO BE CONFIRMED] must be verified against the production app, App Store configuration, and applicable law before release.
1. Overview
MileLedger is an iOS app designed to help users organize expected, missing, claimed, and credited loyalty miles or points. This Privacy Policy explains what information may be handled when you use the app and how that information is intended to be treated.
The legal identity and contact details of the person or entity responsible for MileLedger are [TO BE CONFIRMED]. No company address or registration details are stated in this draft.
Current privacy summary
| Area | Current understanding | Status |
|---|---|---|
| Loyalty accounts | MileLedger does not automatically connect to or access loyalty accounts. | Confirmed product behavior |
| Entries and attachments | The current app implementation stores app records and supporting files locally on the user's device. | [TO BE CONFIRMED] for release build |
| Cloud synchronization | No cloud synchronization claim is made in this draft. | [TO BE CONFIRMED] |
| Analytics and crash reporting | No practice is stated because the production configuration is not yet known. | [TO BE CONFIRMED] |
| Purchases | The app code includes Apple StoreKit-based purchase functionality. Final products, entitlements, and related data handling are not yet documented here. | [TO BE CONFIRMED] |
2. Information handled by the app
Information you choose to enter
Depending on how you use MileLedger, app records may include partner or program names, categories, booking or service dates, expected and credited mileage amounts, claim dates, status information, reference numbers, order or ticket details, notes, and other optional fields. The exact production data fields are [TO BE CONFIRMED].
You may also choose to add supporting files such as receipts, screenshots, images, or confirmations. These files may contain personal information depending on what you select. You should avoid storing passwords, payment-card numbers, or other information that is not needed for mileage tracking.
Profile and preference information
The current app design includes local preferences and may include an optional display name, current miles balance, templates, reminder settings, and app-language choices. The final set of profile and preference fields is [TO BE CONFIRMED].
Device permissions
MileLedger may request access only when a feature requires it, for example notifications for reminders or access needed to select or save an attachment. The final permission prompts and exact purpose strings in the release build are [TO BE CONFIRMED].
Automatically collected information
Whether the production app or website will use analytics, diagnostic tools, server logs, cookies, or crash reporting has not been finalized. No such collection should be claimed or omitted from a final policy until verified. [TO BE CONFIRMED]
3. How information is used
Information entered into MileLedger is intended to support the app's core functions, including:
- creating and organizing mileage or points entries;
- calculating expected credit and claim-related dates based on information you provide;
- showing statuses, summaries, timelines, and statistics;
- keeping notes and supporting attachments with an entry;
- providing optional reminders when enabled; and
- supporting purchase or entitlement features, if included in the final release.
Any additional purposes, including product analytics, support diagnostics, marketing, or personalization, are [TO BE CONFIRMED].
4. Storage, retention, and security
Local storage
The current technical implementation stores MileLedger records in the app's local data store and saves imported attachments in the app's document directory on the device. This statement must be retested against the final release build. [TO BE CONFIRMED]
Backups and device services
Device backups, iCloud device backup behavior, operating-system services, or future synchronization features may affect how locally stored data is copied or restored. The final backup and synchronization behavior is [TO BE CONFIRMED].
Retention and deletion
The current app design allows entries and attachments to be removed through app features, but exact deletion behavior, backup persistence, purchase records, and any support records are [TO BE CONFIRMED]. A final policy should state how long each relevant category is retained.
Security
Reasonable technical measures should be used to protect information handled by MileLedger. No method of electronic storage is guaranteed to be completely secure. Specific security measures and any developer-access scenarios are [TO BE CONFIRMED].
5. Third-party services and disclosures
MileLedger does not automatically access your loyalty-program accounts. The app is not presented as being affiliated with any airline, hotel group, retailer, or loyalty program unless expressly stated.
Apple services and in-app purchases
If paid features or subscriptions are offered, payment processing is expected to occur through Apple's App Store systems. Apple handles information under its own terms and privacy policy. What purchase status or transaction information MileLedger receives and retains is [TO BE CONFIRMED].
Service providers
Any providers used for website hosting, support email, analytics, crash reporting, customer support, or other production functions must be listed here before publication, along with the relevant data and purpose. [TO BE CONFIRMED]
Legal disclosures and transfers
The circumstances in which information could be disclosed for legal compliance, protection of rights, a business transfer, or similar reasons — and any international transfer mechanisms — are [TO BE CONFIRMED].
6. Your choices and rights
You can choose which optional details and attachments to add, whether to enable reminders, and whether to remove records through available app controls. You can manage device permissions in iOS Settings.
Depending on where you live and which production data practices apply, you may have legal rights relating to access, correction, deletion, restriction, portability, or objection. The applicable legal bases, request process, identity-verification steps, response periods, and complaint authority are [TO BE CONFIRMED].
Children's privacy
The intended minimum age, any age-gating requirements, and whether MileLedger is directed to children are [TO BE CONFIRMED]. The app should not knowingly collect children's personal information in a manner inconsistent with applicable law.
7. Changes and contact
This policy may be updated when MileLedger's features, production services, or legal requirements change. The effective date, notice process, and method for presenting material changes are [TO BE CONFIRMED].
Privacy contact email (placeholder): support@mileledger.app