Privacy Notice
What we collect, why we have it, how long we keep it and what you can make us do about it.
Last updated 5 September 2026
Who is responsible
The controller of the personal data described here is the company that operates Milesleft. Its registered name, company number, the part of the United Kingdom in which it is registered and the address of its registered office are published on the Legal Information page.
For anything about privacy, write to support@drewbradyco.shop or call +44 1204 854800. We answer within one working day and complete rights requests within one month.
What we collect and why
Photographs of socks
Two photographs per pair: the whole sock laid flat, and a close frame of the heel and toe. They are measured on your device to produce four visual indicators, and are stored so that you can reopen a read-out later.
We do not accept photographs of feet, of any other part of the body, or of people, and there is no upload facility for one anywhere in this service — this is an absence of a feature, not a filter applied afterwards. If you upload something other than a sock, delete it from your account; we do not want it and have no use for it.
Lawful basis: performance of our contract with you.
What you write about a pair
The approximate number of wears and any note you add. A note is checked for words about how your feet feel before anything is analysed; where it contains them, the analysis is skipped and you are pointed to a clinician. That check happens in your browser.
Lawful basis: performance of our contract with you.
Account data
Your email address, a hashed password, your plan and your monthly allowance usage. Lawful basis: performance of our contract with you, and our legitimate interest in securing accounts.
Billing data
Where you subscribe to a paid plan, our payment processor handles your card details. We never see or store a full card number. We keep the record of what you were charged and when, because tax law requires it. Lawful basis: performance of our contract, and our legal obligations.
Technical and usage data
Server logs containing IP address, browser type and the pages requested, kept for 30 days for security and troubleshooting. If — and only if — you accept optional cookies, aggregate analytics about which parts of a read-out get used. Lawful basis: our legitimate interest in keeping the service secure and working, and your consent for the optional analytics.
What we never do
- We do not use anything you upload, or anything you write, to train, fine-tune, evaluate or benchmark any model — ours or anyone else’s.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not build advertising profiles.
- We make no automated decision that produces a legal or similarly significant effect on you.
- We reach no conclusion about your health, and we hold no health data. A read-out describes fabric.
How long we keep things
- Photographs: 30 days from the read-out, then deleted automatically. You can delete them sooner from your account.
- Read-outs (the figures, without the photographs): until you delete them, or until you delete your account.
- Account data: until you delete your account, then removed within 30 days, including from backups.
- Billing records: six years after the end of the relevant financial year, because tax law requires it.
- Server logs: 30 days.
Deleting your account deletes your read-outs and your photographs with it. Deletion from live systems is immediate; it works through backups within 30 days.
Who we share it with
Only processors acting on our instructions, under a written contract, and only as far as needed: our hosting and database provider, our payment processor, our email provider, and the provider of the vision model that reads the four indicators. We do not sell data to anyone.
We disclose personal data to a public authority only where the law requires it, and we will tell you unless we are legally prevented from doing so.
Sending data outside the United Kingdom
Some of our processors operate outside the United Kingdom. Where personal data is transferred out of the UK, we rely on either the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment, unless the destination is covered by UK adequacy regulations. For transfers out of the EEA we use the European Commission’s standard contractual clauses. Ask us and we will tell you which mechanism applies to which provider.
Your rights under UK GDPR
You have the right to:
- be told what we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data erased;
- have our processing restricted while a question about it is resolved;
- receive your data in a portable form, or have it sent to someone else;
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent at any time, where we rely on consent.
Exercise any of them by writing to support@drewbradyco.shop. We do not charge for this and we complete requests within one month.
Complaining to the ICO
If you are not satisfied with how we have handled your personal data or a request about it, you have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data protection regulator. The ICO can be reached at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You do not have to raise it with us first, though we would rather you did.
If you are in California
Under the California Consumer Privacy Act as amended, you have the right to know what personal information we collect and why, to a copy of it, to correction, to deletion, and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for a do-not-sell request to switch off. We will not treat you differently for exercising any of these rights. Write to support@drewbradyco.shop to use them.
If you are in the EEA
Where the EU General Data Protection Regulation applies to our processing, you have the same set of rights described above and the right to complain to the supervisory authority in the country where you live or work.
Children
The service is for people aged 18 or over. It is not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe a child has an account, tell us and we will delete it and everything in it.
Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and is logged. Passwords are stored hashed and salted; nobody here can read yours. If a breach ever puts your rights at risk we will tell you and the ICO within the time the law allows.
Cookies
Strictly necessary cookies keep you signed in and hold your place while you assess a pair. Nothing optional is set unless you say yes, and the accept and reject buttons are the same size and equally prominent. The detail is in the cookie notice.
Changes
If we change this notice we will update the date at the top, and where the change matters we will tell you by email before it takes effect.