← Thousand Miles

Privacy Policy

Last updated: September 2026

Thousand Miles is a health journal, not a medical provider, and the app is not a medical device.

This policy describes what leaves your device, what doesn't, and what we can and cannot read. Where something syncs, we say so plainly rather than describing the app as local-only.

The short version

What we collect

What syncs to our servers, and how

When you are signed in, these are stored on our backend (Supabase) so they survive a reinstall and reach your other devices. Each row is readable only by your account.

Encrypted on your phone before upload — we hold the ciphertext and cannot read it:

The key is created on your phone and kept in your iCloud Keychain, so your other devices signed into the same Apple ID can read your journal and we cannot. If iCloud Keychain is off on a device, that device cannot read entries made elsewhere until it is on. A recovery code, made on your phone and shown to you once, can unlock your journal on a device without iCloud Keychain; we store only a copy of the key wrapped under that code, which we cannot open. If you lose every device, your iCloud Keychain and the code, we cannot recover your entries for you — we never had the key.

Stored as-is, because the server needs them to work or they are not your journal:

Limits: each photo is reduced to a phone-screen size before upload, and single files are capped at 1.5 MB. Photo backup holds 200 photos without Thousand Miles Plus and 2 GB with it.

What never leaves your device

AI nutrition estimates

When you ask Thousand Miles to estimate nutrition for a meal, the description you typed and the photo you attached (if any) are sent to Anthropic's Claude API through our server, which returns the estimate. This happens only when you tap Estimate — never automatically, and never for entries you log by hand. We send only that meal's description and photo, with no account identifier attached; our server keeps a count of estimates per account and does not store the meal, the photo or the answer, and its logs record only counts and error codes. Anthropic processes it as our service provider and does not use it to train their models. If you would rather not share a meal, enter the values yourself.

What we don't do

Analytics

We currently collect no usage analytics. If that changes, it will be opt-in, off by default, controlled in Settings, and limited to anonymous behavioural signals — never your health data or the contents of your entries.

Retention

Data stays on our servers until you delete it. Deleting your account removes your rows, your stored photos and the encryption key on your devices immediately; backups age out within 30 days. Entries and photos you delete in the app are removed from our servers on the next sync.

Your controls

Singapore (PDPA)

Thousand Miles is operated from Singapore, and personal data is handled under the Personal Data Protection Act 2012. Our Data Protection Officer can be reached at privacy@thousandmiles.app. You can ask us to access or correct the personal data we hold about you, or withdraw your consent, at the same address.

Where your data is held

Our backend runs on Supabase in Singapore, and AI estimates are processed by Anthropic. Anthropic may process data outside your country, including in the United States.

Children

Thousand Miles is not directed at children under 13, or the minimum age required in your region.

Changes

If we materially change this policy, we'll surface a summary in the app.