← Thousand Miles
Privacy Policy
Last updated: September 2026
Thousand Miles is a health journal, not a medical provider, and the app is not a medical device.
This policy describes what leaves your device, what doesn't, and what we can and cannot read. Where something syncs, we say so plainly rather than describing the app as local-only.
The short version
- Your Apple Health data never leaves your phone.
- What you write — entries, notes, photos, the workouts you build — is encrypted on your phone before it is stored on our servers, with a key that only your devices hold. We cannot read it.
- We collect no analytics and sell nothing.
What we collect
- Account info — your email address, and if you use Sign in with Apple, the Apple-issued user identifier plus any name you choose to share. Apple may give us a private relay address instead of your real one; either is fine.
- Entries you log — workouts, meals, moods, body measurements, notes, effort ratings, and photos.
- Workouts you build yourself, and your workout schedule.
- Profile details — display name, activity status, goals, an optional profile photo, and an optional manual max-heart-rate value. Date of birth, biological sex and height are read from your Apple Health profile when it has them; you only type them in if it doesn't.
- Health data you grant read access to — sleep, heart rate, HRV, resting heart rate, workouts, steps, nutrition, and similar signals from Apple Health. This is read on your phone and is not collected by us; see below.
What syncs to our servers, and how
When you are signed in, these are stored on our backend (Supabase) so they survive a reinstall and reach your other devices. Each row is readable only by your account.
Encrypted on your phone before upload — we hold the ciphertext and cannot read it:
- Entries you logged yourself, including their notes, nutrition values and set-by-set weights.
- Notes, photos and effort ratings you add to entries that came from Apple Health.
- Photos attached to entries.
- Workouts you built yourself.
- Your display name and the goals you wrote down.
- Your activity status, a max heart rate you set yourself, and any date of birth, sex or height you typed in (ones read from Apple Health stay on your phone).
- Your app settings, including your sleep goal, and your nutrition goals.
- Your workout schedule and your profile photo.
The key is created on your phone and kept in your iCloud Keychain, so your other devices signed into the same Apple ID can read your journal and we cannot. If iCloud Keychain is off on a device, that device cannot read entries made elsewhere until it is on. A recovery code, made on your phone and shown to you once, can unlock your journal on a device without iCloud Keychain; we store only a copy of the key wrapped under that code, which we cannot open. If you lose every device, your iCloud Keychain and the code, we cannot recover your entries for you — we never had the key.
Stored as-is, because the server needs them to work or they are not your journal:
- When each row was last changed and whether it was deleted — this is how your devices agree on the latest version.
- The colour of your profile card.
- A daily count of AI nutrition estimates, used to cap usage.
- If you subscribe to Thousand Miles Plus: which plan you bought, its App Store transaction identifier, and when it renews or ends. This comes from Apple's signed receipt. We never see your payment details, because Apple handles payment.
Limits: each photo is reduced to a phone-screen size before upload, and single files are capped at 1.5 MB. Photo backup holds 200 photos without Thousand Miles Plus and 2 GB with it.
What never leaves your device
- Apple Health data itself — the workouts, sleep, heart rate and other measurements, and the date of birth, sex and height in your Health profile. These are read live and used on-device, and never uploaded; another device re-reads them from its own Health store instead. Anything you add on top (a note, a photo, an effort rating) is yours rather than Health's, and syncs encrypted as described above.
- Your readiness scores, morning check-ins and recaps. These are computed on-device from the data above.
AI nutrition estimates
When you ask Thousand Miles to estimate nutrition for a meal, the description you typed and the photo you attached (if any) are sent to Anthropic's Claude API through our server, which returns the estimate. This happens only when you tap Estimate — never automatically, and never for entries you log by hand. We send only that meal's description and photo, with no account identifier attached; our server keeps a count of estimates per account and does not store the meal, the photo or the answer, and its logs record only counts and error codes. Anthropic processes it as our service provider and does not use it to train their models. If you would rather not share a meal, enter the values yourself.
What we don't do
- We don't sell your data.
- We don't share your health data with advertisers or data brokers.
- We never use health data for advertising or marketing.
- We cannot read your encrypted entries, and we do not try.
Analytics
We currently collect no usage analytics. If that changes, it will be opt-in, off by default, controlled in Settings, and limited to anonymous behavioural signals — never your health data or the contents of your entries.
Retention
Data stays on our servers until you delete it. Deleting your account removes your rows, your stored photos and the encryption key on your devices immediately; backups age out within 30 days. Entries and photos you delete in the app are removed from our servers on the next sync.
Your controls
- Revoke Health access at any time in the iOS Health app.
- Delete your account from Settings → Delete Account. This removes your server-side data and signs you out.
- Export a copy of everything from Settings → Privacy → Export My Data.
- Ask us anything, or request a copy of your data, at privacy@thousandmiles.app.
Singapore (PDPA)
Thousand Miles is operated from Singapore, and personal data is handled under the Personal Data Protection Act 2012. Our Data Protection Officer can be reached at privacy@thousandmiles.app. You can ask us to access or correct the personal data we hold about you, or withdraw your consent, at the same address.
Where your data is held
Our backend runs on Supabase in Singapore, and AI estimates are processed by Anthropic. Anthropic may process data outside your country, including in the United States.
Children
Thousand Miles is not directed at children under 13, or the minimum age required in your region.
Changes
If we materially change this policy, we'll surface a summary in the app.