Privacy Policy
Last updated: April 2, 2026
Mylestone ("we", "our", or "us") is a progress-tracking platform for individuals, professionals, and organizations. This Privacy Policy explains what personal data we collect, how we use it, when it becomes visible to other people, and the rights and choices available to you.
1. Scope
This Policy applies to the public website, account registration and sign-in flows, public profiles, public milestone pages, social and community features, organization workspaces, professional-client collaboration features, support communications, and the related APIs, tokens, and integrations we make available.
Some areas of the Service are public by design, while others are private, organization-only, or visible only to specific collaborators. Visibility depends on the feature and on the settings you choose.
Mylestone is in a closed alpha. Registration is not open to the public, so the personal data we process is limited to data belonging to invited alpha participants and data generated by ordinary visits to the public website.
2. Categories of Personal Data We Collect
Depending on how you use the Service, we may collect the following categories of data:
- Account and authentication data: name, email address, username, login and security data, password-reset and verification events, two-factor settings, and profile identifiers. If you sign in through Google, Apple, Facebook, or X (Twitter), we may receive profile data made available by that provider.
- Profile and preference data: display name, bio, avatar, locale, region, appearance preferences, privacy settings, professional profile information, specialties, disclaimers, pricing guidance, and availability notes that you choose to provide.
- Milestone and content data: milestone titles, descriptions, categories, cover images, target dates, status, visibility settings, steps, notes, long-form text, links, uploaded assets, generated videos, templates, bookmarks, and related metadata.
- Community and interaction data: follows, follow requests, saved items, comments, replies, reactions, mentions, feed activity, notifications, blocks, reports, and moderation-related submissions.
- Professional and collaboration data: professional-client relationship records, proposals, revision history, accepted proposal terms, private comments, touchpoints, scheduling details, and outcome summaries created through professional or coaching workflows.
- Organization and admin data: organization memberships, invitations, role or capability settings, auto-join or SSO-related data, admin actions, branding settings, forms, webhooks, audit-log data, and organization export requests.
- Billing and subscription data: subscription status, package or plan data, invoice history, billing addresses or tax fields where provided, and payment-method data handled by Stripe. We do not store full card numbers.
- Support and communication data: messages sent through the contact form, support emails, notification delivery events, bounced-email handling, and related correspondence.
- Technical, device, and usage data: IP address, browser type, device information, server logs, route navigation, page views, request metadata, errors, performance data, and interaction data generated when you use the Service.
- Push and token data: web-push subscription data, API tokens, and other credentials or identifiers used to enable authorized agent or integration access.
3. How We Use Personal Data
We use personal data to:
- Create, secure, and manage user accounts, organization workspaces, and sign-in flows.
- Host milestones, profiles, public pages, directories, feeds, and other user-visible experiences according to the visibility settings and collaboration model of the product.
- Deliver social and collaboration features such as follows, comments, mentions, private professional-client workflows, organization mentorship, and touchpoint scheduling.
- Provide AI-assisted milestone creation, step analysis, video generation, and related tools.
- Process subscriptions, manage billing, and handle invoices or subscription lifecycle events.
- Send transactional, service, safety, billing, collaboration, and notification-preference emails and, where enabled, web-push or in-app notifications.
- Respond to contact requests, support issues, abuse reports, and moderation workflows.
- Detect, prevent, and investigate abuse, fraud, policy violations, suspicious activity, or harmful content.
- Generate data exports, support account deletion requests, maintain audit logs, and comply with legal obligations.
- Operate, troubleshoot, measure, and improve the performance, reliability, and security of the Service.
4. Legal Bases
Where the GDPR applies, we rely on the following legal bases. Which one applies depends on the feature and the data involved.
- Article 6(1)(b) — performance of a contract: creating and maintaining your account, hosting your milestones, profile, and public pages, delivering collaboration and organization features, and processing subscriptions and invoices.
- Article 6(1)(f) — legitimate interests: keeping the Service available and secure, rate limiting, abuse and fraud prevention, server logs and error diagnostics, content moderation, and establishing or defending legal claims. Our interest is operating a functioning and safe service. You may object at any time under Article 21.
- Article 6(1)(c) — legal obligation: retaining billing and tax records and responding to lawful requests from authorities.
- Article 6(1)(a) — consent: optional analytics and telemetry cookies, and any other processing we specifically ask you to agree to. You can withdraw consent at any time with effect for the future.
- Article 9(2)(a) or (e) — special categories: a milestone you write may contain data about health, beliefs, or similar sensitive matters. We process such data only on the explicit consent you give by entering it, or because you have manifestly made it public by publishing the milestone. Please do not enter sensitive data you do not want processed.
5. AI, Video, Moderation, and Similar Processing
The Service includes AI-assisted features such as milestone field suggestions, step analysis, and milestone recap video generation. To deliver those features, we may process text, images, videos, milestone metadata, and related content through third-party AI or safety providers.
We also use content-moderation and abuse-handling processes, including text moderation, image moderation, and user-generated reports. Reported content, including certain private collaboration content, may be reviewed by authorized admins or moderators when necessary to investigate a report, enforce policies, or protect users.
We use AI providers as processors under Article 28 GDPR. We do not permit them to use your content to train their general-purpose models, and we do not give consent on your behalf for any broader use.
The only AI provider currently enabled is OpenAI. For users in the EEA the contracting party is OpenAI Ireland Ltd. Content sent through the OpenAI API is not used to train OpenAI's models. Inputs and outputs are retained for up to 30 days for abuse monitoring and are then deleted. No other AI provider is active; should that change, this Policy will be updated before the change takes effect.
6. Visibility, Profiles, and User Sharing Choices
The Service includes both public and non-public spaces. The visibility of your data depends on the feature and on your settings.
- Public content: your public profile, public professional profile, public milestones, public milestone steps, and public organization pages may be visible to anyone who can access the relevant URL or public directory.
- Private-account and follow controls: if your account is private, follow requests and certain profile visibility rules may limit who can see your activity.
- Organization workspaces: data inside organization workflows may be visible to organization admins, mentors, staff, or members according to the organization features, roles, and permissions in use.
- Professional-client collaboration: proposal history, private comments, touchpoints, and related collaboration records are intended for the relevant participants and authorized staff, but reported content may be disclosed to authorized reviewers when needed for safety or policy enforcement.
7. Sharing and Disclosure
We do not sell your personal data. We may disclose data in the following situations:
- To other users, organizations, or collaborators: where the product feature itself requires disclosure, for example public profiles, public milestones, social interactions, professional-client collaboration, or organization-managed workflows.
- To service providers and processors: including providers for hosting, database and authentication services, payments, email delivery, web push, CAPTCHA, telemetry, moderation, AI processing, video generation, storage, background jobs, and similar operational services.
- To organization admins and operators: when they manage an organization workspace, invitations, member access, compliance, audit trails, exports, or other organization-level functionality.
- For safety, abuse, moderation, and legal reasons: including where needed to investigate reports, protect users, enforce policies, respond to lawful requests, or establish, exercise, or defend legal claims.
- In connection with a business transaction: such as a merger, acquisition, financing, restructuring, or sale of assets.
The providers currently engaged are Supabase (database, authentication, file storage, and authentication emails), Vercel (hosting and, subject to your consent, web analytics), and OpenAI (AI-assisted features). Further providers for payments, email delivery, CAPTCHA, telemetry, and content moderation are integrated in the product but are not enabled in the current deployment. We will name any additional provider here before it begins processing personal data.
8. Cookies, Local Storage, Telemetry, and Similar Technologies
We use cookies, local storage, and similar technologies for authentication, security, preferences, and service operation. These technologies may include the following:
Essential Technologies
Required for authentication, session management, security, rate limiting, and core site functionality. Without these technologies, important parts of the Service may not work.
Functional Technologies
Used to remember settings such as theme, language, and similar product preferences.
Analytics and Telemetry
If enabled for a deployment, we may use Vercel Web Analytics to understand aggregated visit and route-usage patterns, and we may also use deployment-specific telemetry such as Azure Application Insights for performance, reliability, and error diagnostics.
Analytics cookies remain optional and can be controlled from the cookie banner and the signed-in privacy settings for the current browser.
Analytics and telemetry are switched off until you consent. Nothing is loaded and no analytics identifier is set before you accept in the cookie banner; declining leaves only the essential technologies described above in place. You can change or withdraw your choice at any time from the cookie banner or, when signed in, from your privacy settings.
Third-Party Technologies
Third parties may set or use their own cookies, storage, or similar technologies when they provide services such as payments, authentication, analytics, CAPTCHA, email-delivery, or other infrastructure and communication functions.
9. Data Retention
We retain personal data for as long as needed to provide the Service, maintain your account, operate organization or collaboration features, meet legal obligations, resolve disputes, and enforce our agreements.
- Account and product data are generally retained while your account or relevant workspace remains active.
- When you request account deletion through the product, live account data may be deleted or deactivated from our primary application systems, subject to logs, queued jobs, safety records, and any retention required by law.
- Personal data export archives are generated on request, delivered by email, and currently expire after a short period. The current implementation stores export files for roughly 48 hours and issues signed download links that are valid for roughly 1 hour.
Runtime logs generated by our hosting provider are retained for one day and then deleted automatically. The database plan currently in use includes no automated backups, so data deleted from the live systems is not retained in a backup copy. Billing and invoice records are kept for the statutory periods, which in Germany are ten years under Section 147 AO and Section 257 HGB. If backups are enabled in future, this Policy will be updated to state their retention period before that change takes effect.
10. International Transfers
Our providers process personal data outside your country of residence. Where a transfer leaves the EEA, we rely on the safeguards required by Chapter V GDPR.
Personal data is currently processed in the United States. The transfers and the safeguard relied on for each are set out below.
- Supabase (database, authentication, file storage) — United States, region us-east-1: Supabase is not certified under the EU–US Data Privacy Framework. The transfer is based on the Standard Contractual Clauses incorporated into the Supabase Data Processing Addendum under Article 46(2)(c) GDPR, together with Supabase's Transfer Impact Assessment.
- Vercel (hosting and, with your consent, web analytics) — United States: Vercel is certified under the EU–US Data Privacy Framework, and relies on the Standard Contractual Clauses as a fallback.
- OpenAI (AI-assisted features) — Ireland and the United States: the contracting party for users in the EEA is OpenAI Ireland Ltd.; onward processing may take place in the United States. OpenAI is certified under the EU–US Data Privacy Framework, and relies on the Standard Contractual Clauses in its Data Processing Addendum as a fallback.
You can ask us for a copy of the safeguards relied on for any of these providers.
11. Security
We use administrative, technical, and organizational measures intended to protect personal data, including encryption in transit, access controls, and service-level security safeguards. No system is completely secure, and we cannot guarantee absolute security. We recommend using strong credentials and enabling two-factor authentication in your account settings.
12. Your Rights
If you are located in the European Economic Area, the United Kingdom, Switzerland, or in another jurisdiction with similar rights, you may have the right to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent where processing is based on consent.
You may also have self-service options within the product, including privacy settings, notification preferences, data export requests, and account-deletion functions. To exercise rights that are not available through the product, contact us at privacy@mylestone.app. You may also have the right to lodge a complaint with your local data-protection authority.
You can lodge a complaint with the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.
The supervisory authority competent for the controller is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany (www.datenschutz-berlin.de).
13. Children's Privacy
The Service is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we learn that we have collected such data without a valid legal basis, we will take steps to delete it. If you believe a child has provided personal data to us, contact us at privacy@mylestone.app.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. For material changes, we may also provide notice through the Service or by email where appropriate.
15. Contact and Controller Information
For privacy-related questions, requests, or complaints, contact us at privacy@mylestone.app.
Data Controller: Raanan Weber
Zimmermannstr. 6, 12163 Berlin, Germany
Data Protection Officer: None appointed. At the scale of the closed alpha the thresholds in Article 37(1) GDPR and Section 38 BDSG are not met. This will be reassessed before the Service opens to the public.