Back to Milo

Privacy Policy

Last updated: March 30, 2026

Introduction

Welcome to Milo ("we," "our," or "us"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your information.

Milo is a smoking cessation support app designed to help you on your journey to quit smoking. This Privacy Policy explains how we handle your personal information when you use the Milo mobile application (the "App").

Information we collect

Information you provide directly

Account & Profile: First name (for personalization).

Smoking & Health: Quit date and time, cigarettes per day, cost per pack, years smoking, reasons for quitting, fears and concerns, past quit attempts.

Craving & Usage: Craving events (intensity, triggers, time, location context), tools used, outcomes, mood and energy check-ins.

AI Coach Conversations: Messages you send to Milo. Conversation history is stored locally and reset daily.

Information collected automatically

Usage information (features used, app performance, error logs), device type, OS version, app version, and unique device identifiers for anonymous authentication.

How we use your information

Progress tracking: Days quit, cigarettes avoided, money saved, health milestones, achievements and streaks.

AI Coach:When you chat with Milo, your messages are sent to Google's Vertex AI (Gemini) service. To provide personalized coaching, we also send context including your first name, quit status, smoking history, reasons to quit, craving patterns, mood, and progress stats. We do NOT send your email, phone number, exact location, or linked account details. The AI does not provide medical advice.

Notifications: Local notifications (if enabled) for milestones and reminders.

Analytics: We use PostHog (EU servers, Frankfurt) for product analytics, session recording, and feature management to understand feature usage and improve the app. Some events include health-related data points (craving intensity, mood scores) for product improvement only. Not used for advertising or sold to third parties.

Session Replay: We record anonymized session replays to improve the app experience. These recordings capture screen layouts, navigation paths, and interaction patterns. Personal content (chat messages, names, email addresses) is automatically masked and not visible in recordings. You can opt out of session recording in the app settings.

Third-party services

  • Google Firebase — Authentication (anonymous by default), Cloud Firestore (data backup and sync), Cloud Messaging (push notifications). US servers.
  • Google Vertex AI / Gemini — AI Coach processing. Google may use data to improve their AI services per their privacy policy.
  • PostHog — Product analytics, session replay, feature flags. EU servers (Frankfurt). No PII sent. Open source (github.com/PostHog/posthog).
  • Google Sign-In / Apple Sign-In — Optional account linking for data backup. We receive only authentication identifiers.
  • Apple — Payments via App Store.

Data storage and security

Most data is stored locally on your device. Data is also synced to Google Cloud Firestore for backup and multi-device access, associated with your anonymous Firebase user ID.

We use AES-GCM encryption (via iOS CryptoKit) for sensitive local data, HTTPS/TLS for data in transit, iOS Keychain for encryption keys, and Firebase security rules to prevent unauthorized access.

Your rights and choices

  • Export: Profile > Data & Privacy > Export my data (JSON file)
  • Delete:Profile > Data & Privacy > Delete all data (permanent, removes local data, Firestore data, and Firebase account)
  • Notifications: Toggle on/off in Profile > App Settings
  • AI Coach: Optional. Don't use it if you prefer no AI processing.
  • Subscription: Manage in Apple Account Settings.

Children's privacy

Milo is not intended for anyone under 17. We do not knowingly collect information from children under 17.

Health disclaimer

Milo is not a medical device or healthcare provider. Health milestones are based on published research (WHO, CDC, AHA, U.S. Surgeon General) and represent general population estimates. The AI Coach provides encouragement and strategies, not medical advice. Always consult a doctor for medical advice.

Data retention

Local: Until you delete it or uninstall. Cloud: Until you delete your account. AI conversations:Reset daily on device; subject to Google's retention policies for messages sent to their service. Analytics:Per PostHog's retention policies (1 year on free tier, 7 years on paid).

International transfers

Your information may be transferred to and processed in the United States (Firebase, Google Cloud). Analytics and session replay data is processed on PostHog's EU servers (Frankfurt, Germany).

For users in the EEA

Under GDPR, you have the right to access, correct, delete, export, and object to processing of your data. Contact [email protected] to exercise these rights.

Changes to this policy

We may update this policy. We will update the date at the top and may notify you in the app for significant changes.

Contact

Questions? [email protected] or [email protected]