Milo eSIM

Privacy Policy

Effective date: 13 September 2026
Controller: TurnaWorks Ltd.
Contact: [email protected]

1. Who this applies to

This policy covers the Milo eSIM mobile app, this website, and our support correspondence. TurnaWorks Ltd. is the controller of the personal data described here.

Milo sells eSIM data plans. We are not a mobile network operator: connectivity is delivered by an eSIM connectivity partner and its network operators, and payments are handled by the app store you bought through.

2. What we collect

Account

Purchases and credits

We never receive or store your card number. Payments are processed by Google Play or the App Store, and we are told only that a purchase succeeded.

eSIMs and usage

Device and diagnostics

Support

3. Why we use it

PurposeDataLegal basis
Selling and delivering eSIM plans, and keeping your credit balance Account, purchases, eSIMsPerformance of a contract
Showing you your plans and usage across devices Account, eSIMsPerformance of a contract
Sending service notifications — your eSIM is ready, your data is running low, your plan is about to expireAccount, push token, eSIMs Performance of a contract, and consent for the notification permission
Answering support requestsSupport, account Performance of a contract, legitimate interest
Keeping the app working: crash reports, diagnostics, abuse prevention Device and diagnosticsLegitimate interest
Understanding how the app is used so we can improve it Device and diagnosticsLegitimate interest, or consent where required
Advertising and measuring our advertising Device identifiers, IP, app eventsConsent
Meeting legal, tax and accounting obligations PurchasesLegal obligation

4. Who we share it with

We share personal data only with the parties below, and only to the extent each of them needs it.

WhoWhat they receiveWhy
Our eSIM connectivity partner and its network operators eSIM identifiers and plan detailsTo issue eSIM profiles and carry your data
Google Play / Apple App StorePurchase transactions To take payment and process store refunds
RevenueCatCustomer ID, purchase and credit balance data To keep your credit balance and validate purchases
OneSignalCustomer ID, push token, device data To deliver notifications
Google Firebase (Analytics, Crashlytics) Device identifiers, IP address, app events, crash data Analytics and crash reporting
Meta (Facebook) advertising tools Device identifiers, IP address, app events, and where you have consented, contact data such as your email addressAdvertising and measurement
AuthoritiesWhatever a lawful request requires Where we are legally obliged

Depending on the setting, some of these act on our instructions as processors and some act as independent controllers of the data they receive. We do not sell your personal data.

5. Where your data goes

Our service providers operate internationally, including in the United States. Where data leaves the European Economic Area, the United Kingdom or Türkiye, we rely on the safeguards available under applicable law — in particular the European Commission's Standard Contractual Clauses, together with the technical measures those clauses require.

6. How long we keep it

When a retention period ends, data is deleted or irreversibly anonymised.

7. Your rights

Depending on where you live, you may have the right to access your data, have it corrected, have it deleted, restrict or object to how we use it, receive it in a portable form, and withdraw consent you have given. Withdrawing consent does not affect what we did while it was valid.

You can delete your account and its data from the app: Profile, then My account, then Delete account. For anything else, email [email protected].

If you think we have handled your data badly, you can complain to your local data protection authority.

8. How we protect it

Traffic between the app and our servers is encrypted in transit. Access to production systems is restricted to the people who need it. Our providers are bound by contract to protect what we pass them. No system is perfectly secure, and we do not claim otherwise — if you believe your account has been compromised, write to us and we will act on it.

9. Children

Milo is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.

10. Changes

We update this policy when what we do changes. The effective date at the top tells you when it last did. If a change materially affects you, we will say so in the app rather than hope you notice here.

11. Contact

TurnaWorks Ltd.
[email protected]