SilentMile Privacy Policy
Last updated: September 27, 2026
The short version
The app collects nothing. There is no SilentMile server, no SilentMile account, no SilentMile cloud, and SilentMile's own code makes zero network requests: not to us, not to analytics companies, not to Apple. iOS itself may contact Apple's location service when GPS starts (section 8); Airplane Mode stops that, and SilentMile keeps recording in Airplane Mode, GPS tracking included; the first GPS fix can take longer without Apple's assist. The only personal data we ever hold is an email you choose to send us (section 12).
Your workouts, routes, and heart rate data stay on your device, encrypted, until you export them or erase them yourself.
Every claim below describes how the software is built as of the date above, and you can check the network claims yourself rather than take them on trust (section 2 tells you how). We ask you to read the rest the same way: as a description of a design, not as a guarantee that nothing can ever go wrong on your phone. Where iOS imposes a limit on what we can say, we say so plainly (section 8), and section 9 explains what no app, ours included, can promise you. This policy is a plain-language notice. The contract is the Terms of Use, which contains our limited warranty that the app matches its described design, and the limits on our liability.
1. What SilentMile stores (on your device only)
SilentMile keeps your fitness data in a local SQLite database on your iPhone.
| Data | Where it lives | Sent to us or to any server? |
|---|---|---|
| GPS routes and track points | Encrypted local database | Never |
| Heart rate recordings | Encrypted local database | Never |
| Workout history (runs, rides, hikes, walks) | Encrypted local database | Never |
| Pace, distance, elevation, cadence, splits | Encrypted local database | Never |
| Personal records and goals | Encrypted local database | Never |
| Settings and preferences | Device only | Never |
| App lock PIN (as a salted PBKDF2 hash) and lockout state | Device Keychain only | Never |
| Database encryption key | Device Keychain only | Never |
2. What SilentMile does not do
- No network requests. SilentMile's code contains no networking calls. There is no maps SDK either. We removed MapKit entirely, and your routes are drawn on-device on a canvas from your own GPS points. This is why the app works fully in Airplane Mode.
- No account. No name, email, phone number, or sign-up of any kind.
- No analytics or telemetry. No Firebase, Mixpanel, Amplitude, or anything like them.
- No crash reporting. If SilentMile crashes, we do not find out unless you email us.
- No advertising identifiers. No IDFA, no ad SDKs, no tracking.
- No third-party services. The only third-party dependency is GRDB, a local SQLite library, in a build that includes SQLCipher for database encryption. Neither makes network calls. Their open-source licenses are acknowledged in the Terms of Use, and we will send you the current list of components on request.
- No in-app purchases. There is no StoreKit code in the app, so the binary never contacts Apple's purchase servers at runtime. You pay once on the App Store; the app itself never talks to a payment system.
- No home-screen widget. Widgets persist snapshots of your data outside the app's lock screen, so there isn't one. SilentMile also uses no app groups, so no other process shares its data container. The one on-device exception is an optional Live Activity: while you are recording, your elapsed time, distance, pace and heart rate can appear on the Lock Screen and in the Dynamic Island so you can glance without unlocking. It shows elapsed time, distance, pace, heart rate and cadence, never your location or route, is rendered on your device by iOS, is not registered by SilentMile for push updates (it is updated locally on your device), and is dismissed the moment the workout ends. Turn it off in Settings → Recording.
- Workout summaries stay on the phone. SilentMile can write a few plain sentences about each workout. On iPhones that support Apple Intelligence (iOS 26), this uses Apple's language model that runs entirely on the device; on other devices it uses simple rules. Either way the input is only your numbers (distance, time, pace, heart rate, splits, how the workout compares to your recent ones), never your location, route, workout name or notes, and nothing is sent to any server, Apple's included. The summary is stored in the same encrypted database as everything else. You can turn this off in Settings → Recording.
Check it yourself. We would rather you test the network claims than believe us. Put your iPhone in Airplane Mode and go record a workout: tracking, route drawing, splits, history and export all keep working, because nothing in the app ever needed the internet. If you want to go further, run a proxy or packet capture while using SilentMile and watch what your phone sends, or open Settings > Privacy & Security > App Privacy Report on your iPhone, which lists the network domains each app has contacted. Those tests show you the app's network behavior. They cannot show you encryption at rest, the Keychain protection class, backup exclusion or how Erase Everything works; for those you are relying on the written description in this policy and in the Terms of Use, backed by the limited warranty in the Terms. If you ever see SilentMile do something this policy says it does not do, email admin@lomalabsllc.com with what you saw and how to reproduce it (please do not send your workout data). We will investigate and, where a report is confirmed, fix the app or fix the description, whichever is wrong, within a reasonable time.
3. Encryption and app lock
Your data is protected in layers:
- Database encryption at rest. The entire SQLite database is encrypted with AES-256. The key is generated on your device and stored only in the iOS Keychain with
kSecAttrAccessibleWhenUnlockedThisDeviceOnly, so it never leaves the device and is not included in any backup. - iOS file protection on top. The database files also use iOS Data Protection, so the hardware additionally encrypts them while your iPhone is locked.
- App lock PIN. If you set a PIN, it is never stored anywhere. SilentMile derives a PBKDF2 hash using a random salt generated for your install, and keeps only that hash in the Keychain. Failed-attempt lockout state also lives in the Keychain, so it cannot be reset by editing app files. iOS does not remove Keychain items when an app is deleted, but SilentMile deletes its own old entries (encryption key, PIN hash and lockout state) on the next fresh install, so deleting and reinstalling starts you over with no data and no app lock. Even if one of those deletions failed, the old key would open nothing and no lock would be set.
- Biometrics. You can use Face ID or Touch ID instead of typing the PIN. Biometric matching is handled by iOS; SilentMile never sees your face or fingerprint data.
What these layers do and do not do. Encryption at rest protects your database from someone who copies the files without the key. The app lock protects against someone who has your unlocked phone in their hand. Neither protects against everything. If your iPhone is jailbroken, compromised by malware, unlocked and left with someone who knows your passcode, or affected by a flaw in iOS itself, the protections we build on top of iOS can be bypassed, and we would have no way to know. We describe the layers accurately, we keep them current as best we can, and we do not claim they are unbreakable. Section 9 says more about this.
4. Backups: your SilentMile data is excluded
SilentMile's database is deliberately excluded from iCloud backups and local device backups. The encryption key is likewise unrecoverable from any backup.
This is a privacy feature with a real cost, and we want you to understand it: if you lose or wipe your device, your SilentMile history is gone. No backup will restore it. If your history matters to you, export your workouts as GPX files periodically (section 6) and store them somewhere you trust.
5. Apple Health (HealthKit)
- Reading (with your permission): SilentMile can read heart rate, workouts, and related metrics from Apple Health to show your training data. Reads happen entirely on your device.
- Writing is opt-in and off by default. SilentMile will not save workouts to Apple Health unless you turn this on in SilentMile's settings and grant permission in iOS. When you turn it on, the iPhone app writes both phone-recorded and watch-recorded workouts.
- Apple Watch recording does not write to Health on its own. While you record on the watch, the watch app uses a HealthKit workout session to read heart rate and distance from the watch's sensors. When the workout ends, it discards that HealthKit workout instead of saving it, so the watch itself does not put workouts into Apple Health. If you have turned Health writing on, the iPhone app writes the watch workout after it arrives on the phone; if you have not, it stays in SilentMile's database.
- Why writing is off by default, and why it matters: data in Apple Health can sync to iCloud under your own Apple settings (Settings > [your name] > iCloud > Health). That sync is between your device and Apple, governed by Apple's terms, and outside SilentMile's control. If you enable Health writing, your SilentMile workouts may leave the device via your iCloud Health sync. If that trade is not acceptable to you, leave Health writing off. The app is fully functional without it.
- You can change HealthKit permissions any time in iOS Settings > Health > Data Access & Devices > SilentMile.
6. Export
You can export any workout as a standard GPX 1.1 file. The file is generated on-device, then iOS shows the standard share sheet and you decide where it goes. If you send it to iCloud Drive, email, or another service, that copy is governed by that service's privacy policy. That is your call to make, and yours only. Your data is never locked in: GPX imports into Strava, Garmin Connect, or anything else.
7. Apple Watch and Bluetooth sensors
- Watch sync is local only. The SilentMile watch app transfers workout data to your iPhone over WatchConnectivity, Apple's direct device-to-device channel. No server, no cloud relay. The watch reads heart rate and distance through a HealthKit workout session while recording and discards that HealthKit workout when it ends rather than saving it (section 5).
- Bluetooth sensors (heart rate straps, cadence sensors, power meters) connect over Bluetooth Low Energy directly to your device. Sensor data goes into the local encrypted database and nowhere else.
- The radio links are Apple's and Bluetooth's, not ours. WatchConnectivity and Bluetooth Low Energy are provided by iOS, watchOS and the sensor's firmware. We use them as designed and describe them as we understand them, but their security is theirs to build and theirs to keep. If either matters for your situation, weigh that before pairing anything.
- Both features are radio transmissions between your own devices, and both are optional. See section 8 if that matters for your situation.
8. Honest limits: assisted GPS and radio silence
Here is what our code does, and what iOS does around it:
- Assisted GPS. When any app uses GPS, iOS itself may contact Apple's location services to get a faster satellite fix. That traffic comes from the operating system, not from SilentMile, and no app can prevent it.
- The clean solution: Airplane Mode. GPS is receive-only: your phone listens to satellites and transmits nothing. In Airplane Mode, all cellular/Wi-Fi radio traffic stops, GPS keeps working, and SilentMile keeps working: tracking, history, exports. The first satellite fix can take a little longer without Apple's assist, and iOS turns Bluetooth off by default in Airplane Mode, so a strap or watch needs Bluetooth switched back on.
- If you need strict radio silence: run in Airplane Mode, and skip Bluetooth sensors and Watch sync, since those are radio emissions you would be opting into.
9. What no app can promise
Everything in this policy describes the software we ship, and you can verify its network behavior in an afternoon. Here is what this policy is not: a guarantee that your data is safe no matter what.
No software is free of defects, and none is immune to compromise. SilentMile runs on a phone we did not build, on an operating system we do not control, next to other apps you chose. If the phone is lost while unlocked, if iOS has a vulnerability, if you install something that should not be trusted, if you back up or screenshot or export data yourself, if your Health sync is on, or if there is a bug in our code that we have not found yet, your data may be exposed or lost, and nothing on this page would have prevented it.
So please read the statements in this policy for what they are: a description of how the app is designed, as accurate as we can make it on the date above, together with the tools to check the parts you can check. They are not a guarantee that nothing can go wrong. The Terms of Use put this in legal language: a limited warranty that the app matches its described design, with a fix-or-refund remedy, and a limit on what we can be held liable for beyond that (see the sections of the Terms titled "Our limited warranty, and what is not warranted," "Check it yourself," "Disclaimer of other warranties" and "Limitation of liability"). We would rather tell you that here, plainly, than have you find it in the fine print.
Our commitment is this: we will not add data collection, we will not quietly change the architecture, and if we learn that any claim on this page is wrong, we will fix the app or correct the claim. If the architecture ever changes in a way that matters, the Terms of Use change with it, and the app asks you to accept the new version before you continue.
10. Erasing your data
Settings > Erase Everything permanently deletes:
- The database files (all workouts, routes, records, goals)
- The encryption key and all SilentMile Keychain entries, including PIN hash and lockout state
- Workouts and routes that SilentMile wrote to Apple Health (only items SilentMile created; we cannot touch other apps' Health data)
- Caches, temporary files, and any generated export files
If any step fails, for example when iOS denies a Health deletion, SilentMile tells you exactly what could not be deleted instead of reporting false success.
Deleting the app removes the database and local files. iOS does not remove Keychain items when an app is uninstalled, so SilentMile cleans up after itself: on the next fresh install, when no database is present, it deletes its old encryption key, PIN hash and lockout state before doing anything else. Deleting and reinstalling therefore starts clean, with no data and no app lock, which is also the way past a forgotten PIN. Uninstalling does not remove workouts already written to Apple Health. If you want everything gone, use Erase Everything first, then delete the app.
There is no server copy to chase down. When it is gone, it is gone.
11. Children's privacy
SilentMile is not directed at children under 13. The Terms of Use require users to be at least 13, and a parent or guardian to accept the Terms for anyone under 18. SilentMile collects no personal information from any user of any age, because there is nothing to collect it with, which also means we cannot verify anyone's age.
12. Your rights, and the one thing we do hold: your email
The app sends no personal data to us or to anyone. We therefore have no user data to access, correct, port or delete: everything is on your device, under your control, and access, portability (GPX export) and erasure exist by default. If a privacy law where you live gives you rights over data a company holds about you, you are welcome to ask, and the honest answer will be that we hold none from the app.
If you email us. The one kind of personal data we do hold is correspondence you choose to send to admin@lomalabsllc.com: your email address, your name if you give it, and whatever you write, which for an arbitration opt-out or a refund request includes the approximate date you bought the app. We use it only to answer you and to keep a record of opt-outs, refunds and dispute notices where the Terms of Use require one. We do not share it, sell it or use it for marketing. A refund we pay ourselves needs a way to pay you, so we will ask for a PayPal address or similar and delete it once the refund clears. We keep ordinary correspondence only as long as we need it to help you, then delete it, and we keep opt-out, refund and dispute records for as long as the Terms make them relevant. You can ask us to delete your correspondence at any time, and we will unless we need it for one of those records. Please do not send us workout data; if you do, we delete it once your report is handled.
Our website. Our website runs no analytics and sets no cookies. Our hosting provider may keep standard server logs, which we do not use to identify anyone.
13. Changes to this policy
Updates will be reflected in the "Last updated" date above and noted in App Store release notes when significant. Because there is no account, we have no way to notify you individually, so the date at the top is the record. The core commitment, no network code in the app, is an architecture rather than a setting. We will not add data collection, and if the architecture ever changes the Terms change with it and the app asks you again. This policy is a plain-language notice, and the Terms of Use are the contract. If the two ever seem to disagree about what the app does, tell us, because one of them is wrong and we will fix it.
14. Contact
Email: admin@lomalabsllc.com
We are a small independent team and aim to reply within 5 business days.
Bottom line: SilentMile is built so that we never have your data. We cannot sell what we do not have, leak what we never received, or hand over what does not exist. What we cannot do is make your phone unbreakable, so treat this page as an honest description you are welcome to test, and read the Terms of Use for what that means if something goes wrong.