Privacy policy
Privacy Policy
Last updated: September 30, 2026
Magic AI Keyboard (the “App”) is not a keyboard that continuously collects what you type. Its Keyboard Extension is dedicated to AI actions, and AI processing occurs only when you explicitly start an AI action.
This Policy explains how information is handled by the App, its Keyboard Extensions, the related website, and the managed AI service.
Scope and provider
This Policy applies to the App and related services provided by the operator of Magic AI Keyboard (“we,” “us”). Third-party terms and privacy policies also apply to their respective services.
Contact, disclosure, and deletion requests are accepted through the contact form at the end of this Policy.
Information handled on your device
- App language, reply language, writing preferences, keyboard settings, and AI data-sharing consent are stored in App Group.
- Screen context you review and share is stored in App Group and can be deleted by you.
- A development OpenAI API key is stored in Apple Keychain only if entered through a debug feature.
- Firebase ID and App Check tokens are stored temporarily in the shared Keychain for managed-AI authentication.
- Selected screenshots are processed on device for OCR or resizing; the App does not save the original image.
Account and usage records
Adding the keyboard and using on-device controls such as globe, delete, space, and return work without signing in. You sign in with Google or Sign in with Apple only when you choose account-based features such as managed AI, usage tracking, or the optional survey. Through Firebase Authentication, we process an account identifier, authentication provider, and provider-returned information such as email address and display name.
Immediately after sign-in, one screen explains what is and is not sent to the OpenAI API and why, and asks for explicit consent. Until you consent, keyboard-derived text and images are not sent to OpenAI.
To provide managed AI and prevent abuse, Firestore stores your plan, limit, remaining uses, reset time, request ID, action, processing status, provider model, error information, generated result, and timestamps. Input text is not stored in Firestore. A generated result is retained to prevent duplicate execution of the same request.
Optional survey
Google Forms opens only if you select Open Survey in the parent app. The form receives an auto-filled Firebase Auth UID needed to grant the reward and the answers you submit. The form does not collect your email address.
Apps Script sends only the UID—not your survey answers—to our Cloud Functions to grant the once-per-month Magic reward. Firebase Analytics does not receive the UID, form URL, or answers. Responding to the survey is optional.
Information sent for AI processing
When you run an AI tool, the information needed for that action may be sent to the OpenAI API through our Cloud Functions. The App does not continuously monitor or transmit keyboard input.
Rewrite, proofread, and tone actions do not include unrelated clipboard or screen context. The clipboard is not read when a menu appears; it is read immediately before an action that needs it. For screenshot replies, the image is not sent until you confirm the preview and tap generate. Requests specify store: false so inputs and outputs are not persisted in the OpenAI account for logs or distillation.
We do not use text or images sent for AI processing, or the resulting output, to train our own machine-learning models or to build a cross-user learning dictionary. Data is sent to OpenAI to run the action you selected and for OpenAI’s abuse prevention and safety monitoring. Whether API data may be used for model training is governed by OpenAI’s agreement and data controls (API customer data is generally not used to train models). See the link below. Temporary safety logs and retention on OpenAI’s side also follow those terms.
- Selected text, the current draft, your instruction, reply language, and writing preferences
- Clipboard text, only immediately before reply, summary, Ask, or similar actions that need it
- Screen context you reviewed and shared, or a reduced JPEG you confirmed before sending
- A random install identifier that is not derived from personal information (abuse prevention)
- OpenAI API data controls
Product analytics
The parent app uses Firebase Analytics without advertising identifiers. It collects coarse product events such as screens and tabs, onboarding progress, setting categories, context-action categories and outcomes, and sign-in method and outcome.
Analytics events do not include keyboard input, phonetic readings, AI input or output, clipboard contents, full OCR text, email address, display name, or Firebase Auth UID. Analytics is not linked to the Auth UID and is not used for advertising or cross-company tracking.
Purposes of processing
- Authentication, managed-AI delivery, usage-limit management, and abuse prevention
- Running the rewrite, proofreading, summary, reply, and other actions you select
- Improving quality through the optional survey and granting its response reward
- Improving quality, investigating failures, and maintaining security (without collecting typed content)
- Responding to inquiries and communicating important changes
- Not used to train our own machine-learning models or to build a cross-user learning dictionary
Service providers and international processing
The App uses Firebase Authentication, Cloud Functions, Cloud Firestore, Firebase App Check, Firebase Analytics, the OpenAI API, Google Forms, Google Apps Script, and Sign in with Apple. These providers may process information in locations outside your country, including Japan.
For incident response, we send operational information such as API names, fixed error codes, timestamps, and server-generated correlation IDs to Discord. Notifications do not include input text, AI output, screen context, UIDs, email addresses, or authentication tokens. Notifications are retained until the operator deletes them from Discord.
We review applicable agreements, security measures, and data-protection terms when selecting providers. We do not sell your information or share it with third parties for advertising.
Retention
Device settings and shared context remain until you delete them or remove the App. Shared authentication tokens and consent to third-party sharing with OpenAI are removed from the device when you sign out.
Firebase Authentication information is kept until account deletion. Firestore usage records, request records, and generated results are kept until account deletion is completed or they are no longer needed to provide the service. Unless retention is legally required, associated data is deleted when the account is deleted. Removal from Firebase backups may take additional time.
Google Forms survey answers and the auto-filled random Firebase Auth UID are kept for as long as needed to improve the service and grant rewards. The form does not collect your email address. After account deletion, the Firebase Authentication and Firestore records that map that UID to an account are removed. You can use the contact form if you also want the form response itself deleted.
OpenAI may normally retain API abuse-monitoring logs for up to 30 days under its settings and policies. Firebase Analytics data is retained under the configured Firebase retention settings and policies.
Your choices and deletion
- You can revoke Full Access and photo access in iOS Settings.
- You can delete shared context and sign out in the App.
- While signed in, choose Get Started > Account > Delete Account to initiate deletion of the Firebase Authentication account and related Firestore data. If you use Sign in with Apple, the App also revokes Apple's authorization token.
Account deletion runs after an in-app confirmation and cannot be undone. You can also use the contact form to request deletion of voluntarily provided information outside the account, such as the survey response itself.
Security
The service uses HTTPS, and protects API keys and authentication tokens with Keychain. The App does not write input text or AI output to debug logs. Administrative access is restricted and administrative changes are recorded in an audit trail.
Changes and contact
We may update this Policy as needed. Updated Policy takes effect when posted on this page, or on a later effective date we specify. For material changes, we will update the date on this page and, when appropriate, ask you to review the current terms in the App.