Privacy Policy

Effective date: [PLACEHOLDER — effective date] · Last updated: July 2026

This is the honest version. MileBack reads airline emails to find miles you flew but were never credited. To do that we ask for read-only access to your inbox — so you deserve to know, in plain language, exactly what we touch, what we keep, and what we throw away. No dark patterns, no buried clauses.

"MileBack," "we," "us," and "our" refer to [PLACEHOLDER — legal entity name], operator of the MileBack app and getmileback.com. This policy covers the mobile app and this website.

What we access

When you connect Gmail, we request a single Google permission: Gmail read-only (the gmail.readonly restricted scope), plus your name and email address to create your account. Read-only means exactly that: we can read messages, and we can do nothing else. We cannot send, delete, label, or change anything in your inbox.

You can also feed MileBack flights without Gmail at all — by forwarding airline emails to a MileBack address, or uploading an email export. Whichever path you use, the handling below is identical.

We only look at messages that appear to be airline itineraries, receipts, or boarding-pass confirmations. We are not interested in the rest of your inbox and do not build a profile of it.

What we extract and store

We read the airline emails, pull out the facts about your flights, and store only that structured flight metadata. Concretely, the fields we keep for each flown leg are:

  • Airline (marketing and operating carrier) and flight number
  • Departure date, origin airport, and destination airport
  • Fare class and cabin
  • Flight distance (when we can determine it)
  • The loyalty program the leg maps to, and whether a frequent-flyer number was present
  • Our estimated miles and dollar-value range for the leg
  • Our confidence rating and which extractor produced it
  • A masked/hashed ticket number reference — never the raw ticket number
  • A hashed booking reference (PNR) used only to group legs of the same trip — never the raw PNR

We also store a few things tied to your account: your MileBack account ID and email, your locale/currency preferences, per-scan counts (how many emails were considered and parsed — counts only, never content), your loyalty membership numbers (encrypted at the application layer, never in plaintext, and never a password), the claims you file, and your subscription/entitlement status.

What we never store

These are architectural commitments, not just promises:

  • Raw email bodies and subjects. The full text of your emails is processed in memory while we extract flight facts, then discarded. It is never written to disk, never queued, never logged, and never backed up. No column in our database can hold email body or subject text.
  • Passwords. We never ask for, receive, or store any password — not your Google password, not your airline password.
  • Airline account credentials. We never touch your frequent-flyer login. We help you file claims; we never log into airline accounts on your behalf.
  • Raw OAuth tokens. The Google token that authorizes reading your mail is held in an encrypted vault and referenced indirectly; the raw token is never stored in our application database and never logged.

What Google requires us to say — and we mean it

MileBack's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, that commitment means: we use Gmail data only to provide the miles-recovery features you see in the app; we do not sell it; we do not transfer it except as needed to run those features; we do not use it for advertising; no human at MileBack reads your email; and we do not use your email content to train general or shared AI/ML models. Where an AI model helps extract flight details from an email, it runs on a zero-retention basis for inference only — your content is not retained by the model provider and is not used to improve their models.

Who else touches your data (third-party processors)

We keep the list of companies who process your data short and purposeful. We do not sell data to anyone, and none of these are advertising networks or data brokers.

ProcessorWhat they receiveWhy
SupabaseYour account and the flight metadata aboveDatabase and authentication hosting
AnthropicEmail text, in memory only, on a zero-retention API tier, when needed to extract flight detailsAI extraction fallback when structured parsing isn't enough — inference only, no training, no retention
RevenueCatYour account ID and purchase/entitlement statusManaging subscriptions and the founding-member entitlement
StripeYour email and payment details (handled by Stripe)Founding-member checkout on the web
PostHog & Google Analytics 4De-identified, bucketed usage events — never your routes, values, membership numbers, or any email-derived contentFirst-party product analytics (funnels, retention). No ad tracking.

What we never do

  • We never sell your data.
  • We never show you ads or use your data for advertising or retargeting.
  • No human at MileBack reads your email.
  • We never use your email content to train shared or general AI models.

Our business model is simple: we make money when you subscribe. That's the whole model.

Retention and deletion

You can delete your account at any time. In the app: go to Settings → Privacy → Delete account. From the web: use our account deletion page — it works even if you don't have the app installed.

Deletion removes everything that identifies you: your account, your connections, your flight metadata, your claims, your membership numbers, and your subscription record, in that order, and revokes our Gmail access. The only thing we keep is de-identified calibration statistics that carry no user ID and cannot be linked back to you — we use them to keep our estimates honest.

You can also disconnect your inbox without deleting your account. Disconnecting revokes our Gmail access and stops future scans; deletion removes your data entirely.

Your rights (GDPR / CCPA)

Wherever you live, you can see what we hold, correct it, export it, delete it, and revoke inbox access. If you're in the EU/UK (GDPR) or California (CCPA/CPRA), you additionally have the right to know what we collect and why, to request deletion, to data portability, and to not be discriminated against for exercising these rights. We do not sell or "share" personal information as those laws define it, so there is nothing to opt out of on that front. To exercise any right, email privacy@getmileback.com.

Contact

Questions about privacy? Email privacy@getmileback.com. Postal mail: [PLACEHOLDER — mailing address].