This is a pre-launch draft, written to accurately describe how Milea actually works today. Milea is
currently built by an individual developer and is not yet operated through an incorporated company —
this document has not been reviewed by a lawyer and should be treated as a good-faith draft, not final
legal advice, until it is.
Who we are
Milea is a mobile app that helps freelancers in the EU track business expenses and mileage, and prepare
those records for tax filing. Milea is not a licensed tax, legal, or financial advisor — nothing in the
app or this policy is tax advice.
What data we collect
Account data: the email address and display name you register or sign in with
(including via Google or Apple sign-in), your selected country and tax regime, and your
subscription status.
Records you create: expenses (vendor, amount, VAT, category, date), trips (origin
and destination addresses, distance, purpose), income entries, clients you tag records to, and any
corrections you submit after a record is locked.
Receipt photos: when you scan a receipt, the photo is read automatically to
extract the vendor, amount, date and VAT. The image is stored in your account only once you save
the expense.
Addresses and routes: addresses you type for a trip are looked up, and a driving
route is calculated, to work out the distance. Milea does not track your location in the
background.
Notification tokens: if you allow notifications, an identifier for your device so
reminders can reach it.
Feedback: messages you choose to send from inside the app.
Usage and diagnostics: basic app usage events and crash/error reports, used to
keep the app working and fix problems.
Why we collect it
To provide the core service (recording and organizing your expenses/trips for filing), to calculate
mileage and VAT figures using the rates for your selected country, to send the reminders you turn on,
and to manage your subscription. Financial records
are also retained to meet the record-keeping periods required by tax law in your selected country. Once
a month, we also aggregate the deduction rates users have set for each expense category, per country, to
improve the suggested default rates Milea offers — this produces only anonymised, country/category-level
totals (no individual user's data is identifiable in the result), and groups smaller than 20 users are
excluded entirely.
Where your data is stored
Records are stored locally on your device and synced to Google Firebase (Firestore, Cloud Storage
and Cloud Functions), hosted in the EU (europe-west3, Frankfurt). Milea is designed to work offline-first, with
your device holding a full local copy of your records.
Who we share data with
We use the following service providers to run Milea. They process data only to provide their service to us:
Google Firebase — hosting, authentication, database, file storage, push
notifications and app analytics.
Google Gemini API — reads the receipt photos you scan to extract their details.
Google Maps Platform — looks up trip addresses and calculates routes.
Sentry — receives crash and error reports so we can fix bugs.
Apple, Google Play and Stripe — process payments for paid plans. Milea receives
your subscription status, not your card or payment details.
Google / Apple — only if you choose to sign in with those providers.
We do not sell your data, and we do not share it with anyone else.
Data retention
Financial records (expenses, trips, filing periods) are retained for the period required by the tax
authority of your selected country, even if you ask us to delete your account — this is a legal
requirement, not a choice Milea makes. Account data not needed for that purpose (like your email) can
be deleted on request.
Your rights
If you're in the EU, you have the right to:
Access the personal data we hold about you.
Correct inaccurate data.
Export your data — the app's built-in Export feature lets you download your full records as a CSV
or PDF at any time.
Request deletion of data that isn't subject to a legal retention requirement.
Object to processing, and lodge a complaint with your local data protection authority.
Security
Data in transit is encrypted (HTTPS/TLS). Authentication is handled by Firebase Auth. Financial records
are locked at the database level once a filing period is submitted — after that point they can only be
amended by an appended correction, never overwritten.
Children
Milea is not directed at children and is not intended for use by anyone under 18.
Changes to this policy
If this policy changes, the "Last updated" date above will change with it.