Milo
Your information

Privacy policy

Effective 12 September 2026

Milo | Personal Assistant is operated by ONICO LTD. This policy explains what the app and its cloud assistant do with your information. For privacy questions or requests, contact dan@onicogroup.com.

What you share

We process your account email and account identifier, the name and preferences you give your assistant, your messages, goals, task results, selected connections and usage records. Information you ask the assistant to work with can appear in its answers or files.

You choose whether to connect another service. Milo stores connection credentials so your assistant can use the access you approved, including while your phone is closed. OAuth sign-in takes place with the service provider; Milo does not ask for your Google password.

Google account data

When you connect Gmail, Milo can search and read relevant messages to answer your questions, summarise your inbox and prepare replies. Sending an email is available only if you separately enable sending. When you connect Google Calendar, Milo can read events to help with scheduling and planning. Creating events is available only if you separately enable changes.

Google data is used to provide the assistant features you request. Relevant content is processed by Milo’s cloud agent and its configured model provider to perform those tasks. Content may be included in a response, task result or file that you asked the assistant to create. Other connected services receive information only as needed for the actions you request through them.

Milo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to develop or train generalised AI or machine-learning models. Human access to Google data is limited to cases allowed by that policy, such as your explicit agreement to review specific data for support, security investigations, or legal requirements.

Optional iPhone context

Calendar, reminders, contacts and location access start off. Each category needs your permission. Calendar context is limited to the next 14 days and up to 300 events; reminders to up to 300 incomplete items; contacts to up to 1,000 permitted contacts with limited contact details. Location is approximate and rounded on the phone. Your language and time zone can accompany requests automatically.

By default, enabled context is attached to the request you send. A separate background-sync option lets the cloud assistant use a recent snapshot. These snapshots expire after 24 hours. Offline permission changes are queued on the phone and retried when it reconnects; an earlier snapshot may remain until then or until it expires. Information already sent to a running model cannot be recalled.

Voice dictation and text extraction from selected photos, scans and documents take place on the phone. The text you review and send becomes part of your message. Those features do not upload the original audio, image or document.

Cloud processing and protection

Milo runs on Google Cloud and uses Firebase for account services. Google’s Vertex AI processes the built-in assistant’s model requests. If you configure a different model provider or connect another app, that provider processes the information needed for the features you use under its own service terms and settings.

Connections use HTTPS. Stored account state, conversation history, connection credentials, iPhone-context snapshots and push-notification records are encrypted. Agent workspaces are separated by account and use encrypted cloud storage. Authorised service operators can administer the infrastructure. This is not end-to-end encryption: the cloud agent and model providers need to process the content of your requests.

Notifications and service operation

If you enable notifications, we store your installation identifier and Apple push token to deliver task alerts. Push payloads use generic review, completion or attention messages and do not include your task prompt or connected-account content. Apple processes notification delivery.

We process usage totals to enforce your allowance and operate the service. Purchase records are processed if you use paid features. Hosting and security systems may record operational information such as request timing, status and network addresses. This website does not use advertising cookies or third-party analytics scripts.

How long information stays

Conversation and task history is retained for one day by default. You can choose seven or 30 days in the app; older completed history is removed by the service’s regular cleanup. Active tasks may remain until they finish. Memory is off by default. If you enable it, the agent can retain learned preferences until you turn it off or delete the account.

Saved goals, account preferences and workspace files can remain until removed or your account is deleted. Per-request iPhone context is removed after execution or cancellation, with a maximum 24-hour expiry. Optional synced snapshots and queued notifications expire after 24 hours. Connection credentials remain until you disconnect or delete your account. Data already delivered to a connected provider, or retained by that provider under its own terms, is subject to that provider’s controls.

Purchases and billing records

Apple handles payment details. Milo receives signed transaction identifiers, product identifiers, purchase and expiry dates, refund status and an app account identifier to provide allowances, restore purchases and prevent fraud. We do not receive your card details. Usage records are linked to your account and are not used for tracking or advertising. After account deletion, we retain minimal transaction ownership and revocation records to prevent the same purchase being reused; financial records required by law may also be retained.

Your controls and deletion

You can pause your assistant, revoke permissions, change history retention and disconnect apps in Milo. Disconnecting removes the stored credentials and stops future access through that connection; it does not remove content already included in an earlier answer or saved file. You can also revoke Google access in your Google Account connections.

Use Your assistant → Delete account in Milo to delete your account and its service data, including stored credentials, conversations, goals, workspace files, device registrations and queued notifications. If you cannot access the app, contact us from your account email. We may need to verify account ownership before acting. You can also contact us to request access to or correction of your information, or raise a privacy concern.

Policy updates

We update this policy when the service or its data practices change. The effective date identifies the current version. We will explain material changes through the app or another appropriate channel before they take effect.