MilesVault

Privacy Policy

Last updated: July 31, 2026

MilesVault (“we”, “us”) is a rewards-tracking app that turns your credit-card statements into a ledger of the points and miles you earn, helping you track and optimise your card rewards and airline miles across your loyalty programmes. It is operated by Ameya Karve as an individual. This policy explains what we collect, why, and what we do with it. Questions or requests: support@milesvault.com.

Information we collect

  • Account & identity. When you sign in with Google, we receive the name, email address, profile picture, and account identifier Google provides. Google is the identity provider for MilesVault.
  • Optional Discord connection. If you choose to connect Discord, we receive your Discord user ID and your roles in the Double Dip server to verify membership-based access. If you are not already in the server, the connection can add you to it. We do not request access to your messages or other servers.
  • Subscription information. We keep your selected plan, subscription status, billing period, and payment-provider references. Razorpay processes the payment; MilesVault does not receive or store your full card or bank-account details.
  • Financial information you provide. The statements and transaction emails you upload or forward — including merchant names, amounts, dates, account and card identifiers, and reward balances — which we extract into your ledger.
  • Feedback. Messages and optional screenshots you submit through the in-app feedback button.
  • Connected messaging. If you pair WhatsApp, we process the phone number, messages, and delivery metadata needed to provide the concierge in that channel.
  • Operational logs. Standard technical logs (e.g. request metadata) used to run and secure the service.
  • Privacy-first product analytics. We record coarse events such as page views, feature use, successful or failed operations, and performance measurements. We do not put statement contents, ledger entries, account names, transaction amounts, chat text, exact travel searches, full URLs, IP addresses, or user agents into product analytics. Signed-in events use a one-way keyed identifier; signed-out activity is kept only as aggregate counts and is not stitched into a visitor profile. MilesVault does not set an analytics cookie or store an analytics identifier in your browser.

How we use your information

  • Authenticate you and decide whether you may access the service.
  • Read your statements and use AI to draft ledger entries for you to review and approve — nothing is recorded without your approval.
  • Maintain your ledger and show your balances, spending, and rewards.
  • Respond to your feedback and improve the product.
  • Measure aggregate acquisition, activation, feature adoption, reliability, and performance so we can improve MilesVault.

Where your data is processed and stored

Your data is processed and stored on Cloudflare’s global network (including Durable Objects, R2, and D1). AI features are routed through Cloudflare AI Gateway and may use Cloudflare Workers AI or an external model provider, including providers reached through OpenRouter. External routes are configured for zero data retention where the provider supports it. The relevant statement, ledger context, or message is sent to the selected model only when needed to provide the feature.

Google handles sign-in; Razorpay handles subscription payments; Discord handles the optional membership connection; and Meta/WhatsApp handles messages when you pair that channel. Their processing is governed by their own terms and privacy policies.

Sharing

We do not sell your data. We share it only with the infrastructure and service providers needed to run the feature you use — including Cloudflare, Google, Razorpay, AI model providers, and, when you connect them, Discord and Meta/WhatsApp — or where required by law.

Retention and deletion

We keep your data until you delete it or ask us to. You can remove captured statements and ledger entries within the app, delete your account and associated data from Settings, or email support@milesvault.com for help.

Raw product-analytics events are retained for up to three months. Daily aggregate and cohort counts may be retained longer because they no longer contain the keyed user identifier.

Security

We use reasonable technical measures to protect your data. No system is perfectly secure, and MilesVault is currently in beta — please keep that in mind.

Your rights

You may access, correct, or delete your information at any time, in-app or by contacting us.

Children

MilesVault is not intended for anyone under 18.

Changes

We may update this policy; we’ll revise the “Last updated” date above when we do.

Contact

support@milesvault.com

PrivacyTermssupport@milesvault.com© 2026 MilesVault