Privacy Policy
Last Updated: March 2026
1. Overview
This Privacy Policy explains how aInspired ("we", "us", "our") collects, uses, and protects your information when you use the aInspired keyboard application ("App"), the website at ainspired.app ("Website"), and all related services (the "Service").
We designed aInspired with a privacy-first approach: keystroke data never leaves your device, voice and text data processed in the cloud is handled ephemerally, and we collect only what is necessary to provide the Service.
2. Data We Collect
2.1 On-Device Data (never leaves your device)
- Keystroke patterns — used by the on-device n-gram language model for next-word predictions. Never transmitted anywhere.
- Personalized word frequencies — your typing habits stored locally to improve suggestion accuracy.
- Preferences and settings — theme choices, keyboard layout preferences, provider selections.
- Spell-check dictionary — local dictionary used for on-device spell checking.
The keyboard automatically excludes password fields and other secure input fields from personalized learning (PII detection gate).
2.2 Cloud-Processed Data (ephemeral)
- Voice recordings — sent to your selected speech-to-text provider (Groq, OpenAI, Deepgram, or Google) for transcription. Processed in real-time and not stored long-term by us.
- Text for phrase correction — sent to your selected LLM provider (Claude, OpenAI, Groq, Gemini, Mistral, or Fireworks) for grammar and style corrections. Processed ephemerally.
- Chat messages — sent to your selected AI provider for conversational responses. Processed ephemerally.
- Meme prompts — text descriptions sent to generate memes. Not stored after generation.
Before sending text to cloud providers, our PII detection system scans for sensitive information (credit card numbers, Social Security numbers, API keys, passwords) and blocks the request if PII is detected.
2.3 Account and Billing Data
- Google account info — your email address, display name, and profile photo, collected when you sign in with Google.
- Device identifier — a randomly generated UUID that identifies your device for quota tracking.
- Usage quotas — counts of AI correction, voice transcription, and chat requests for billing purposes.
- Subscription status — your plan tier and billing cycle, managed by Stripe.
We never see or store your payment card numbers. All payment processing is handled by Stripe under their privacy policy.
2.4 Automatically Collected Data
- Crash reports — anonymized error data to help us fix bugs and improve stability.
- Website analytics — basic page view data via Cloudflare Analytics (no cookies, no personal data).
3. How We Use Your Data
- Provide and improve keyboard predictions and autocomplete (on-device only)
- Process voice transcription requests through your selected provider
- Process text correction and chat requests through your selected AI provider
- Manage your account, subscription, and usage quotas
- Send transactional emails (billing receipts, account notifications)
- Diagnose and fix technical issues via crash reports
- Display ads to free-tier users (via Google AdMob)
We do not sell your personal data. We do not use your keystroke data, voice recordings, or chat messages to train AI models.
4. Third-Party Data Processors
We share data with these third-party services only as necessary to provide the Service:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Sign-In | Authentication | Email, name, photo |
| Stripe | Payment processing | Email, payment details |
| Cloudflare | Infrastructure, CDN, edge compute | Request metadata, account data |
| Groq | STT + LLM processing | Voice audio, text |
| OpenAI | STT + LLM processing | Voice audio, text |
| Anthropic (Claude) | LLM processing | Text |
| Google Gemini | STT + LLM processing | Voice audio, text |
| Mistral | STT + LLM processing | Voice audio, text |
| Deepgram | STT processing | Voice audio |
| Fireworks AI | LLM processing | Text |
| Google AdMob | Ad delivery (free tier) | Device identifiers (with consent) |
BYOK users: when using your own API keys, requests go directly to your chosen provider. Your data does not pass through our servers.
5. Data Retention
- On-device data — stored indefinitely until you uninstall the App or clear its data.
- Cloud-processed data (voice, text, chat) — processed ephemerally by AI providers. We do not retain copies.
- Account data (email, name, device ID) — retained while your account is active. Deleted within 30 days of account deletion.
- Usage quota data — retained for billing cycle reconciliation, then aggregated and anonymized.
- Billing records — retained as required by tax and financial regulations (typically 7 years).
6. Advertising and Tracking
Free-tier users see ads served by Google AdMob. AdMob may collect device identifiers (such as Android Advertising ID) to serve and measure ads.
- Personalized ads require your explicit consent. You can opt out at any time in the App settings.
- Non-personalized ads are served by default if you decline personalization.
- Paid subscribers (Basic, Pro, BYOK) do not see ads and no ad-related data is collected.
7. Cookies
The Website uses minimal cookies:
- Session cookie — maintains your login state. Expires when you close your browser or after 30 days.
- Consent preference — remembers your cookie/ad consent choice.
We do not use marketing cookies, analytics cookies, or third-party tracking cookies on the Website.
8. Data Security
We protect your data through:
- Encryption in transit — all network communication uses TLS 1.2+.
- On-device PII detection — automatically blocks cloud requests containing sensitive data (credit cards, SSNs, API keys, passwords).
- Secure field exclusion — the keyboard does not learn from password fields or other secure input fields.
- HMAC token authentication — device-to-server communication uses cryptographic tokens, not plain API keys.
- Infrastructure isolation — our backend runs on Cloudflare Workers with edge-level security.
9. International Data Transfers
Your data may be processed in the United States and other countries where our third-party providers operate. When data is transferred outside the European Economic Area (EEA), we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Provider certifications (e.g., Cloudflare's GDPR compliance framework)
10. Your Rights
Depending on your location, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your personal data and account.
- Portability — receive your data in a structured, machine-readable format.
- Restrict processing — request that we limit how we use your data.
- Withdraw consent — withdraw consent for ad personalization or other consent-based processing at any time.
- Object — object to processing based on legitimate interest.
To exercise any of these rights, email privacy@ainspired.app. We will respond within 30 days.
11. GDPR (European Users)
If you are in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) applies. Our legal bases for processing your data are:
- Contract performance — processing necessary to provide the Service you subscribed to (transcription, corrections, chat, billing).
- Consent — personalized advertising and optional data collection. You can withdraw consent at any time.
- Legitimate interest — crash reporting, fraud prevention, and service security, balanced against your privacy rights.
- Legal obligation — retaining billing records as required by tax law.
You have the right to lodge a complaint with your local Data Protection Authority if you believe we are not handling your data correctly.
12. CCPA (California Users)
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights:
Categories of personal information we collect:
- Identifiers — email address, name, device UUID
- Commercial information — subscription tier, purchase history
- Internet activity — usage quota counts, crash reports
- Audio data — voice recordings (processed ephemerally, not stored)
Your California rights:
- Right to know — what personal information we collect and how we use it.
- Right to delete — request deletion of your personal information.
- Right to opt out of sale — we do not sell your personal information.
- Non-discrimination — we will not discriminate against you for exercising your rights.
13. Children's Privacy
aInspired is a general-audience application. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA). If you believe a child has provided us with personal data, please contact us at privacy@ainspired.app and we will promptly delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you through the App or by email. We encourage you to review this page periodically.
15. Contact Us
For privacy-related questions, requests, or complaints:
aInspired
Email: privacy@ainspired.app