Miles
Credit CardsFeaturesPricingAppsDocsOpen Miles →Sign inTry free
  • Credit Cards
  • Features
  • Pricing
  • Apps
  • Docs
  • Open Miles →
  • Sign in
  • Try free

Security

Last updated: August 29, 2026

Miles stores your conversations, your wallet, and notes it keeps to remember your situation. This page explains how that data is protected and where the protection ends.

Miles is built and run by one person, Andy Assareh. This page says “I” because there is no company.

Encryption

Every account has its own encryption key. Your conversations, wallet, memory notes, point balances, certificates, credit tracking, and saved valuations are encrypted with your key before they are written to disk.

Your key is itself encrypted by a master key held in a separate hardened service. The application can ask that service to decrypt your data. It cannot read or copy the master key. If someone stole the machine, they would have ciphertext and no key to open it.

A few fields are stored readable because the service needs them: your email address, so you can sign in and I can reach you; billing identifiers, so payments can be reconciled; and timing and cost figures, which contain no content. The credit card dataset itself is public information.

Site analytics are kept in a separate file that is not encrypted: which pages were read, and where a visit came from. It is never joined to an account or a conversation, so there is nothing in it to tie back to you.

Deletion

Deleting your account destroys your key. Everything encrypted with it becomes permanently unreadable, including to me.

This covers backups too. A backup taken last week holds a copy of your data encrypted with the same key, so destroying the key makes that copy unreadable as well. Backups expire after seven days.

Where it runs

Miles runs on hardware I own and physically control. Traffic to the site is served through Cloudflare, which terminates TLS and handles your requests in transit. Backups replicate to Cloudflare R2. Your conversations are sent to an AI provider to generate each response; the providers are listed in the privacy policy.

Miles never has your bank credentials. It knows which cards you have because you entered them. It cannot see your transactions or move money.

There are no passwords. Sign-in is an emailed code or a passkey.

What encryption does not protect against

Encryption at rest protects against a stolen disk or a leaked backup. It does not protect against:

  • A compromised server. The running application is authorized to request decryption, so an attacker who controlled it could too. They could not take the master key with them, and every decryption request is logged.
  • Me. I operate the service, so I can access your data while your account exists. I read conversations only to debug a problem or when you ask for help. Nothing enforces that, and you should weigh it.
  • A legal order. I can be compelled by law to produce what I hold. The running service can decrypt, so encryption at rest does not change that.
  • Things you share. If you publish a wallet share link, anyone with the link can read it.
  • Your email account. Sign-in codes arrive by email, so whoever controls your inbox can sign in as you. A passkey avoids this, which is why Miles offers passkeys.

Recovery

The master key is backed up separately under its own seal. I verify backups by restoring them and checking that data encrypted before the backup still decrypts. The restore procedure is rehearsed.

Reporting a problem

If you find a security issue, email [email protected]. I will respond. There is no bug bounty, but I am glad to credit you.

Change Log:

August 29, 2026: Point balances, certificates, credit tracking, gift cards, and saved valuations are now encrypted per account too. They were readable on disk before today. Also noted that site analytics live in a separate unencrypted file that is never joined to an account.

August 10, 2026: Rewrote the page in plainer language. Nothing about the design changed.

August 1, 2026: Page added. Conversations, wallet contents, and remembered notes are now encrypted per account, and deleting an account destroys that account’s key.

Not affiliated with any bank or card issuer. Independently built by Andy Assareh. I don't sell your personal information. Miles uses AI and may occasionally get details wrong. Verify before acting.

Miles

The right call for every card decision. Miles reads your wallet and shows the math.

Features

Your next card, comparedKeep-or-cancel verdictsYour Card SnapshotWhich points to transferWhich card to useSee all features →

Resources

AboutFAQData changelogHow the data is maintainedHow Miles makes moneyConnect your AIWhat's possibleDevelopersDocsAppsPricing

Legal

Terms of ServicePrivacy PolicySecurity

Settings

© 2026 Andy Assareh9cb8780 Data: loading…