Privacy Policy
Last updated: July 16, 2026
1. Introduction
Miles ("we," "our," or "us") is a language learning app for iPhone. It teaches the 1000 most useful words in whichever language you're learning, glossed in the language you already speak, through a guided path, quizzes, and a practice mode that targets the words you keep missing. Miles also includes voice conversations with an AI companion ("Magic Miles"), so you can practice speaking out loud. This Privacy Policy explains what data we collect, what we don't, and how it flows between your device and the services that make the app work.
The short version: your learning lives on your device and syncs to your own account so it follows you across devices. Your account and that synced data are held by Google Firebase. Voice conversations are powered by OpenAI, which needs your microphone during a call. We use PostHog for privacy-respecting product analytics tied to your account. We don't sell ads, we don't track you across other companies' apps or sites, we don't use an advertising identifier, and Miles has no camera, location, or contacts access.
2. How Your Data Flows
Understanding the data flow is the clearest way to understand our privacy model:
- On your device (your working copy):Your progress (which of the 1000 words you've learned and when), your daily streak, your rank, your bookmarked words, and your settings (the languages you picked, your daily goal, sound and notification toggles) are stored on your device using local storage (AsyncStorage). This is the app's primary, offline-capable copy.
- Device ↔ Firebase (your account and sync):To use Miles you create an account. Authentication is handled by Google Firebase Authentication, which stores your email address, your display name, the sign-in provider you used, a profile photo URL if your provider supplies one, and a generated user ID (UID). So your learning follows you across devices, we also sync a copy of your profile (your languages, goal, and daily targets), your progress (words learned, streak, active days, bookmarked words), and Magic Miles' memories and chosen coach style to Google Firestore under your account. Each account can only read and write its own data.
- Device ↔ Apple / Google (sign-in): If you sign in with Apple or Google, the provider handles authentication and returns a token to Firebase Auth. We never see your Apple or Google password. If you sign in with email and password, Firebase Authentication stores and verifies those credentials; we never see your password in plain text.
- Device ↔ OpenAI (voice conversations):When you start a Magic Miles voice call, your microphone audio is streamed in real time to OpenAI's Realtime API to power the conversation, and OpenAI transcribes your speech so the companion can respond honestly to what you actually said. Before each call, our server sends OpenAI the context it needs: your first name, your reason for learning, the topic you picked (including any custom topic you type), a handful of words you're practicing, and short memories from earlier calls. We do not record or store your call audio, and OpenAI processes it under their API terms.
- Device ↔ RevenueCat ↔ Apple (subscriptions): When you upgrade to Miles Pro, the purchase is processed by Apple. RevenueCat sits between the app and the App Store to tell us whether your Pro entitlement is active. RevenueCat receives your Firebase user ID and the store receipt Apple returns. We never see your Apple ID or payment method.
- Device ↔ PostHog (analytics): We use PostHog to understand how features are used and where people get stuck. The app sends a small set of deliberate product events tied to your account, plus your email and display name as profile properties. There is no tap-by-tap autocapture, no screen recording, and no advertising use.
3. Information We Collect
Account information
- Email address (if you sign up with email or Google; Apple may relay a private email)
- Your display name, if you set one or your sign-in provider supplies it
- A Firebase Authentication user ID (UID), generated when you sign up
- The sign-in provider you used (Apple, Google, or email)
- The profile photo URL your sign-in provider supplies, if any
Learning progress and settings (created by you, synced to your account)
- Which of the 1000 words you have marked learned, and when
- Your daily streak, last active day, and active days
- The words you've bookmarked
- The language you speak and the language you're learning
- Your daily word goal, your daily call-minutes goal, and your sound and notification toggles
This is stored on your device and synced to your account (Firestore) so it moves with you across devices. Deleting the app removes the local copy; deleting your account removes the synced copy (see Data Retention & Deletion).
Voice conversations (Magic Miles)
- Your microphone audio during a call, streamed live to OpenAI to run the conversation. We do not record or store it; the audio is processed transiently to generate the companion's replies.
- Session context we send OpenAI at the start of each call: your first name, your reason for learning, the topic you chose or the custom topic text you type, a few words you're practicing, and short memories from earlier calls.
- Memories: short facts the companion saves about you during a call (for example, a goal or a preference you mention) so future calls feel continuous. These are stored on your device and synced to your account, and reused on later calls. You can clear them by deleting your account.
- The words practiced in a call, so they can be added to your learning.
Subscription state
- Whether your Miles Pro entitlement is active (true/false), as reported by RevenueCat and the App Store
Product analytics
We send PostHog a small set of deliberate events so we can see how the app is used and improve it, for example: onboarding started and completed, account created, a paywall viewed or dismissed, a purchase completed, and a voice call started and ended (with its duration). These events are tied to your account, and your email and display name are attached to your analytics profile. We do not autocapture your taps, we do not record your screen, and this data is never used for advertising.
Sound and pronunciation
Miles plays short bundled sound effects for right/wrong quiz feedback, and uses your device's built-in text-to-speech to read words aloud when you tap to hear pronunciation. This is separate from voice calls and involves no microphone.
What we do NOT collect
- No camera or photo access. Miles has no camera feature.
- No location data of any kind
- No contacts, calendar, or health data
- No advertising identifier (no IDFA), no ad networks, no retargeting
- No cross-app or cross-site tracking of any kind
- No session recording or screen replay
- No recording or storage of your voice-call audio
- We never sell your personal information
4. Microphone
Miles requests microphone access for one reason: the Magic Miles voice conversation feature. Your microphone is used only during an active call, to stream your speech to OpenAI so the companion can hear and respond. Audio is not recorded or stored by us, and the microphone is never used outside of a call. If you never start a voice call, the microphone is never used.
5. Tracking & Advertising
Miles does nottrack you across other companies' apps or websites. Our analytics (PostHog) is first-party: it measures how you use Miles itself, not your activity elsewhere. We do not participate in ad networks, retargeting, or audience-building of any kind, and we do not use Apple's IDFA (Identifier for Advertisers). Accordingly, the App does not present an App Tracking Transparency (ATT) prompt, because no cross-app or cross-site tracking occurs.
6. Third-Party Services
The App relies on the following services, each with their own privacy policies:
- Google Firebase (Authentication and Firestore): stores your account, verifies your sign-in, and holds the synced copy of your profile, progress, and Magic Miles memories. Data is stored in Google Cloud in the United States.
- OpenAI: powers Magic Miles voice conversations via the Realtime API. It receives your live call audio and the session context described above, transcribes your speech, and generates the companion's voice. OpenAI processes data in the United States.
- Apple: handles Sign in with Apple, App Store distribution, and Miles Pro in-app purchase billing.
- Google Identity: handles Sign in with Google.
- RevenueCat: reports your Miles Pro entitlement (active/expired) to the app. RevenueCat receives your Firebase user ID and the store receipt, and processes data in the United States.
- PostHog: our product analytics. It receives the deliberate events described above along with your email and display name, keyed to your account, and processes data in the United States. We do not enable session replay or autocapture.
Miles does not use any advertising or crash-reporting service.
7. Data Retention & Deletion
The local copy of your learning and settings lives on your device; deleting the app removes it.
Your account and its synced data stay until you delete them. To delete your account, use the in-app account deletion option, or email support@moetalaat.com from the address on the account. Deletion removes your Firebase Authentication record (email, display name, provider, and photo URL) and all of your data stored under your account in Firestore (your synced profile, progress, and Magic Miles memories). This is irreversible and invalidates all sessions.
We do not record or store your voice-call audio, so there is nothing to delete on that front. To have your analytics profile removed from PostHog, email us and we will delete it.
8. Legal Basis for Processing (GDPR)
If you are located in the EEA, United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contractual necessity (Art. 6(1)(b) GDPR): creating and maintaining your account, syncing your learning across your devices, running the voice conversation feature, and confirming your Pro entitlement.
- Legitimate interest (Art. 6(1)(f) GDPR): basic account security and abuse prevention, and understanding how the app is used (product analytics) so we can improve it.
9. International Data Transfers
Firebase, OpenAI, RevenueCat, and PostHog process data in the United States. If you use Miles from outside the U.S., your data is transferred to and processed in the U.S. These providers offer Standard Contractual Clauses for cross-border transfers.
10. Your Rights
You have the right to:
- Access the personal information stored in your account (your email, name, and provider are visible in the app)
- Delete your account and the personal information tied to it at any time
- Request a copy of your data, or removal of your analytics profile, by emailing us
EEA/UK residents (GDPR): you also have the right to data portability, the right to restrict or object to processing, and the right to lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA):you have the right to know what personal information we collect, the right to delete it, and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share your personal information.
11. Children's Privacy
Miles is a learning app suitable for teens and adults, but it is not directed to children under the age of 13 (or 16 in the EEA), and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.
12. Security
Authentication is handled by Firebase Auth, and your sign-in tokens are kept in your device's secure local storage. Your synced data in Firestore is protected by per-account security rules, so only your account can read or write it. Voice calls use a short-lived session key minted by our server; our permanent OpenAI key never ships in the app. All traffic between the app and our providers uses HTTPS. No system is perfectly secure, but we hold little about you: your account record holds your email, name, and sign-in provider, and the synced data is your own learning and settings.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced on this page and, if significant, in the app. Continued use of Miles after changes constitutes acceptance.
14. Contact
Questions, requests, or anything else, write to support@moetalaat.com.
15. Summary
In short: Miles keeps your learning on your device and syncs a copy to your own account (held by Firebase) so it follows you across devices. Your account holds your email, name, and sign-in provider. Magic Miles voice calls are powered by OpenAI, which needs your microphone during a call and receives some context to run the conversation, but we never record or store the audio. We use PostHog for first-party product analytics tied to your account, including your email and name. RevenueCat tells us whether Pro is active. There are no ads, no IDFA, no camera, no location, and no cross-app tracking. Delete your account and everything on our side is gone.
