Privacy Policy

Effective October 1, 2026

We collect what you choose to log so Me & Milo can work for you. We don’t sell your data, we don’t show ads, we don’t use tracking or analytics SDKs, and you can export or delete your data at any time from Settings.

Who we are

This Privacy Policy explains how [COMPANY LEGAL NAME] (“[COMPANY LEGAL NAME],” “we,” “us” or “our”) collects, uses, shares and protects personal information when you use the Me & Milo mobile app for iPhone and Android and any related websites or services that link to this policy (together, the “Service”).

Me & Milo is a wellness and tracking companion for adults who use GLP-1 medications. It is not a healthcare provider, and we are not a “covered entity” or “business associate” under HIPAA. Your information is still important to us, and this policy describes the protections we apply.

Because much of what you log in Me & Milo is health information, we also publish a separate Consumer Health Data Privacy Policy that explains your rights under state consumer health data laws such as Washington’s My Health My Data Act. You can find it in the app under Settings and at https://meandmilo.app/health-data-privacy. If that policy gives you more protection for consumer health data, it controls.

If you have questions, contact us at [privacy@yourdomain.com] or [COMPANY MAILING ADDRESS].

The short version

Information you give us

Account information. When you create an account, we collect your email address and a password. Your password is stored only as a salted, one-way hash, never in plain text. You may also give us your name or nickname.

Medication information. The name of your medication, your dose, your shot day and time, your dose history, injection sites, your step-up (titration) plan, and your supply and refill details.

Body and activity information. Your weight and goal weight, workouts, and steps (if you connect a health source, described below).

Food and hydration. Food logs, meal photos you take or choose, nutrition estimates (such as calories and protein), and water intake.

How you’re feeling. Side effects and symptoms and how severe they are, daily check-ins (such as hunger, “food noise,” energy and mood), journal notes and non-scale wins.

Progress photos. Photos you add to track your progress. These are stored on the device where you add them only. They are not uploaded to our servers or sent to our AI provider.

Chat messages. Messages you send to Milo, the in-app AI cat, and Milo’s replies.

Support messages. If you email us, we receive your email address and whatever you choose to include in your message.

Some of this information is health information, which many state laws treat as “sensitive personal information” or “consumer health data.” We collect it only because you choose to log it and only to provide the features you use.

Information from connected services

You can choose to connect other services. Each connection is optional, and you can turn it off at any time.

Apple Health (iPhone) and Health Connect (Android). With your permission, Me & Milo reads your weight and step count, and writes the weight and protein you log in Me & Milo back to Apple Health or Health Connect. You control these permissions in the Health app (iPhone) or Health Connect settings (Android).

Fitbit. If you sign in with Fitbit (through Google’s health data service), Me & Milo reads your daily step count only. We don’t receive your Fitbit password. You can disconnect in Me & Milo or revoke access in your Google account settings.

App stores and subscriptions. If you subscribe, Apple (App Store) or Google (Google Play) processes your payment. We (and our subscription management provider, described below) receive information about your subscription status, such as which plan you have, whether you’re in a free trial, and renewal and expiration dates. We never receive your card number or other payment details.

Information collected automatically

We keep this short, because we collect very little automatically.

How we use your information

We use personal information only for these purposes:

We do not use your information for advertising, we do not build advertising profiles, and we do not use your health information to make decisions that produce legal or similarly significant effects about you. We use sensitive personal information only for the purposes permitted by law, such as providing the Service you requested.

AI features

Some features use artificial intelligence provided by Anthropic (the maker of Claude). Before any of your information is sent for AI processing, Me & Milo asks for your permission, and nothing is sent unless you tap Allow.

When you use an AI feature, we send only what that feature needs: the message you type, a meal photo you choose to analyze, a short summary snapshot of your recent logs (for example, recent doses, weight, food and symptoms) so Milo’s reply is relevant to you, or the data you choose to include in a doctor-visit summary.

In production, these requests go through our own backend server, which forwards them to Anthropic. Anthropic processes this data as our service provider, only to generate a response for you. Under Anthropic’s commercial terms, data sent through its API is not used to train its AI models by default.

Progress photos are never sent for AI processing.

You can keep using Me & Milo’s tracking features without AI. You can withdraw your AI consent at any time in Settings → Safety → AI features. After you withdraw, no new information will be sent to Anthropic.

AI output can be wrong or incomplete, and it is not medical advice. See our Terms of Service for more.

Apple Health and Health Connect data

We treat data we get from Apple Health (HealthKit) and Health Connect with extra care:

Our use of information received from Health Connect complies with the Health Connect Permissions policy, including its Limited Use requirements.

How we share information

We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising (targeted advertising). We share personal information only in these limited ways:

Where your data is stored and how we protect it

Your account (your email address and a salted, one-way hash of your password) and the information you log are stored on our servers in the United States, hosted by Amazon Web Services. This is what lets you sign in on more than one device, including Me & Milo on the web, and see the same information everywhere.

Each device you sign in on also keeps a copy of your logs, so Me & Milo is fast and works offline: in the app’s private storage on your phone, or in your browser’s storage for this site on the web. Your sign-in session is kept in your device’s secure storage (the iOS Keychain or Android Keystore), or in your browser’s storage on the web. Signing out removes this copy and your session from that device.

Progress photos and meal photos stay on the device where you took them. They are not uploaded to our servers (a meal photo is sent to our AI provider only when you ask Milo to analyze it, as described above).

We use reasonable administrative, technical and physical safeguards designed to protect your information, including encryption in transit (TLS) and encryption at rest on our servers, access controls that limit access to people who need it, and hashing of passwords.

No system is perfectly secure. Please use a strong, unique password and keep your device locked. Anyone with access to your unlocked device may be able to see the information stored in Me & Milo. If we learn of a security breach affecting your personal information, we will notify you as required by law.

How long we keep information

We keep your information for as long as your account is active or as needed to provide the Service to you.

Your choices and controls

You can do most things yourself, directly in the app:

Collecting health information is essential to how Me & Milo works, so you can’t use the app without it. To withdraw your consent to our collection of your health information entirely, delete your account.

Your US state privacy rights

Depending on where you live, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, you may have some or all of these rights regarding your personal information:

We honor these rights for all our users in the United States, regardless of which state you live in, to the extent reasonably possible.

Additional information for California residents

This section supplements this policy for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA).

Categories we collect. In the past 12 months we have collected: identifiers (email address, name you provide, account ID, IP address); customer records (email address); commercial information (subscription status and history); internet or other electronic network activity (limited technical request information); audio, electronic or visual information (meal photos and progress photos you add); and sensitive personal information (account login credentials, and health information such as medication, doses, weight, symptoms, food and mood). We do not collect geolocation, biometric information used for identification, or government ID numbers. We do not draw inferences to create a profile about your preferences or characteristics other than to provide the features you use.

Sources. Directly from you; from Apple Health, Health Connect and Fitbit when you connect them; from Apple, Google and RevenueCat (subscription status); and from your device automatically (technical request information).

Purposes. The business and commercial purposes described in “How we use your information.”

Disclosures. In the past 12 months we have disclosed identifiers, commercial information, network activity, visual information and sensitive personal information to our service providers for business purposes, as described in “How we share information.” We have not sold or shared personal information (as those terms are defined in the CCPA), and we have no actual knowledge of selling or sharing the personal information of anyone under 16.

Sensitive personal information. We use and disclose sensitive personal information only to provide the Service you request and for other purposes permitted under the CCPA regulations (such as security and integrity). We do not use it to infer characteristics about you. Because of this, we don’t offer a separate “Limit the Use of My Sensitive Personal Information” link, though you can always contact us.

Retention. See “How long we keep information.”

Authorized agents. You may use an authorized agent to make a request for you. We may ask the agent for proof that you gave them signed permission and may ask you to verify your identity directly.

Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.

How to exercise your rights

The quickest way to access, export or delete your data is in the app (Settings → Privacy & legal → Export my data, and Settings → Account → Delete account). You can also email [privacy@yourdomain.com] with the subject line “Privacy request,” or write to us at [COMPANY MAILING ADDRESS].

Verification. To protect you, we need to confirm that a request really comes from you. We will usually do this by asking you to send the request from the email address on your account or to confirm a code we send to it. We will only use the information you give us for verification to verify your request.

Response times. We will confirm receipt of your request within 10 business days and respond within 45 days. If we need more time (up to an additional 45 days), we will tell you why. We don’t charge a fee unless requests are clearly unfounded, excessive or repetitive, as permitted by law.

Appeals. If we decline to take action on your request, we will explain why. You can appeal by replying to our decision or emailing [privacy@yourdomain.com] with the subject line “Privacy appeal” within a reasonable time. We will respond to your appeal in writing within 45 days (or 60 days where the law allows), explaining what we did and why. If you are not satisfied with the result of your appeal, you may contact your state Attorney General.

Global Privacy Control. Because we don’t sell or share personal information or engage in targeted advertising, there is nothing for a browser opt-out signal to switch off. We would honor such signals as required by law if our practices ever changed.

Children

Me & Milo is only for adults 18 and older. It is not directed to children under 18, and we don’t knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we will delete the account and its data. If you believe a minor has given us information, please contact [privacy@yourdomain.com].

Users outside the United States

Me & Milo is intended for people in the United States, and our Service is operated from the United States. If you use Me & Milo from outside the United States, your information will be processed in the United States, where data protection laws may differ from those in your country.

Changes to this policy

We may update this policy from time to time, for example when we add features. When we do, we will change the effective date above. If we make material changes, we will notify you in the app or by email before the changes take effect. If a change would let us use or share your health information in a materially different way, we will ask for your consent first.

Contact us

Questions, requests or complaints about privacy:

For general app support, email [support@yourdomain.com].