Milestone
Last updated September 9, 2026
Milestone has no account and no server of ours. Your projects, recordings, photos, notes, and tasks live in a database on your iPhone, and — if you're signed in to iCloud — sync through your own private iCloud container, which only your devices can read. The app makes no network requests of its own; the only traffic it causes is Apple's sync.
Everything the app keeps is held with Apple's SwiftData framework, on your device:
Recordings and photographs are stored as files belonging to the app rather than inside the database itself, and they never enter your camera roll unless you put them there. Deleting the app removes its local copy of all of this.
So that a project reads the same on your iPhone and your iPad, Milestone syncs through CloudKit — Apple's service, using your own iCloud account. Your data goes to the private database of the app's iCloud container, which is reachable by your devices signed in to your Apple Account and by nobody else. I have no console, no key, and no ability to read it.
Nothing is sent to any server of mine, because there isn't one. If you're not signed in to iCloud, or iCloud Drive is off, or the network is gone, Milestone opens local-only and keeps everything on the device — the entry is saved either way, and Settings ▸ iCloud will tell you which of the two is happening.
To remove what iCloud holds, delete the data in the app or turn Milestone off under iOS Settings ▸ your name ▸ iCloud. Apple's handling of what sits in your account is covered by Apple's privacy policy.
Voice notes. Milestone transcribes a recording with Apple's Speech framework so you can search what you said. It asks for on-device recognition whenever your device and language support it, which is the usual case on a modern iPhone. Where they don't, iOS completes the recognition through Apple's speech service instead — that is Apple's processing, not mine, and it never reaches me. Turning Transcribe voice notes off in Settings ▸ Search stops it entirely.
Photographs. Words in a photo are read, and the picture is classified for what it's of, using Apple's Vision framework. This runs on your iPhone — the image is not uploaded anywhere. Read photos in Settings ▸ Search switches it off.
Both run quietly in the background, on entries you capture here and on entries that arrive from your other devices. What they produce is text stored with the entry, and it syncs the same way the entry does.
Finding entries that are close in meaning. Alongside exact matches, search offers a few entries whose wording is related to what you typed. The comparison is made with Apple's NaturalLanguage word embeddings, which are part of iOS and run on your iPhone — your query is not sent anywhere, and it isn't stored.
Suggestions while you capture. The composer may offer a title, a nudge that what you wrote reads like a task, or a due date it noticed in your own words. These are worked out on the device from the text already in front of you, by plain rules rather than by any service, and nothing is written until you tap the suggestion. Ignored suggestions leave no trace.
iOS asks your permission the first time each one is needed, and Milestone uses them for exactly one thing apiece: the camera takes the photographs you capture, the microphone records your voice notes, speech recognition transcribes those recordings, and photo library access lets you attach a picture you already took. Nothing is read from your library except the specific photo you pick.
Declining any of them leaves the rest of the app working, and every one can be withdrawn later in iOS Settings ▸ Milestone.
Milestone contains no analytics, no advertising, no crash reporting, and no third-party SDKs. It ships with no outside dependencies at all. Nothing about you or your work is collected, shared, sold, or disclosed to anyone, because none of it ever reaches me in the first place.
All of it is yours and all of it is in your hands. Settings ▸ Data ▸ Start fresh deletes every project, entry, photo, and recording; the deletion cannot be undone, and it syncs to your other devices along with everything else. Deleting a single entry removes its media with it.
Removing Milestone from your iPhone deletes its local database. What sits in iCloud is removed by turning the app off under iOS Settings ▸ your name ▸ iCloud, or by managing that storage in your Apple Account. There is nothing for me to delete on your behalf, and no request to fulfil, because I hold nothing.
Milestone is not directed at children under 13, and we do not knowingly collect personal information from children. As described above, we do not collect personal information from anyone.
If this policy changes, we'll update the date at the top of this page. Continued use of Milestone after a change means you accept the updated policy.
Questions about this policy, or about what Milestone does with what you capture? Reach out directly.
ericfan.apps@gmail.com