Privacy policy
Privacy Policy
Last updated: August 11, 2026
Magic AI Keyboard (the “App”) is not a keyboard that continuously collects what you type. Normal typing runs on the device, and AI processing occurs only when you explicitly start an AI action.
This Policy explains how information is handled by the App, its Keyboard Extensions, the related website, and the managed AI service.
Scope and provider
This Policy applies to the App and related services provided by the operator of Magic AI Keyboard (“we,” “us”). Third-party terms and privacy policies also apply to their respective services.
Contact, disclosure, and deletion requests are accepted through the contact form at the end of this Policy.
Information handled on your device
- App language, reply language, writing preferences, keyboard settings, and consent state are stored in App Group.
- Screen context you review and share is stored in App Group and can be deleted by you.
- A development OpenAI API key is stored in Apple Keychain only if entered through a debug feature.
- Firebase ID and App Check tokens are stored temporarily in the shared Keychain for managed-AI authentication.
- Selected screenshots are processed on device for OCR or resizing; the App does not save the original image.
Account and usage records
The parent app requires Google or Sign in with Apple authentication. Through Firebase Authentication, we process an account identifier, authentication provider, and provider-returned information such as email address and display name. Normal typing in the Keyboard Extensions works without signing in.
To provide managed AI and prevent abuse, Firestore stores your plan, limit, remaining uses, reset time, request ID, action, processing status, provider model, error information, generated result, and timestamps. Input text is not stored in Firestore. A generated result is retained to prevent duplicate execution of the same request.
Optional survey
Google Forms opens only if you select Open Survey in the parent app. The form receives an auto-filled Firebase Auth UID needed to grant the reward and the answers you submit. The form does not collect your email address.
Apps Script sends only the UID—not your survey answers—to our Cloud Functions to grant the once-per-month Magic reward. Firebase Analytics does not receive the UID, form URL, or answers. Responding to the survey is optional.
Information sent for AI processing
When you run an AI tool, the information needed for that action may be sent to the OpenAI API through our Cloud Functions. The App does not continuously monitor or transmit keyboard input.
Rewrite, proofread, and tone actions do not include unrelated clipboard or screen context. The clipboard is not read when a menu appears; it is read immediately before an action that needs it. For screenshot replies, the image is not sent until you confirm the preview and tap generate. Requests specify store: false so inputs and outputs are not persisted in the OpenAI account for logs or distillation.
We do not use text or images sent for AI processing, or the resulting output, to train our own machine-learning models or to build a cross-user learning dictionary. Data is sent to OpenAI to run the action you selected and for OpenAI’s abuse prevention and safety monitoring. Whether API data may be used for model training is governed by OpenAI’s agreement and data controls (API customer data is generally not used to train models). See the link below. Temporary safety logs and retention on OpenAI’s side also follow those terms.
- Selected text, the current draft, your instruction, reply language, and writing preferences
- Clipboard text, only immediately before reply, summary, Ask, or similar actions that need it
- Screen context you reviewed and shared, or a reduced JPEG you confirmed before sending
- A random install identifier that is not derived from personal information (abuse prevention)
- OpenAI API data controls
Japanese Cloud Conversion
Japanese Cloud Conversion is enabled by default. Only when Full Access is available, the App sends the current phonetic reading in hiragana, subject to a length limit, to the Google Japanese Input CGI API. It does not send confirmed text, screen context, clipboard contents, or API keys.
Readings are sent only to retrieve conversion candidates. We do not store or log them, and we do not use them for our own training or learning dictionaries. Google’s handling is governed by Google’s terms and privacy policy. We do not provide readings to Google for the purpose of training our models.
If Full Access is unavailable, Cloud Conversion is disabled, or a request fails, conversion continues with the built-in on-device dictionary. On-device conversion also does not build a learning dictionary.
Product analytics
The parent app uses Firebase Analytics without advertising identifiers. It collects coarse product events such as screens and tabs, onboarding progress, setting categories, context-action categories and outcomes, and sign-in method and outcome.
Analytics events do not include keyboard input, phonetic readings, AI input or output, clipboard contents, full OCR text, email address, display name, or Firebase Auth UID. Analytics is not linked to the Auth UID and is not used for advertising or cross-company tracking.
Purposes of processing
- Authentication, managed-AI delivery, usage-limit management, and abuse prevention
- Running the rewrite, proofreading, summary, reply, and other actions you select
- Retrieving Japanese conversion candidates
- Improving quality through the optional survey and granting its response reward
- Improving quality, investigating failures, and maintaining security (without collecting typed content)
- Responding to inquiries and communicating important changes
- Not used to train our own machine-learning models or to build a cross-user learning dictionary
Service providers and international processing
The App uses Firebase Authentication, Cloud Functions, Cloud Firestore, Firebase App Check, Firebase Analytics, the OpenAI API, the Google Japanese Input CGI API, Google Forms, Google Apps Script, and Sign in with Apple. These providers may process information in locations outside your country, including Japan.
We review applicable agreements, security measures, and data-protection terms when selecting providers. We do not sell your information or share it with third parties for advertising.
Retention
Device settings and shared context remain until you delete them or remove the App. Shared authentication tokens and AI-sharing consent are removed from the device when you sign out.
Firebase Authentication information is kept until account deletion. Firestore usage records, request records, and generated results are kept until account deletion is completed or they are no longer needed to provide the service. Unless retention is legally required, associated data is deleted when the account is deleted. Removal from Firebase backups may take additional time.
Google Forms survey answers and UIDs are kept for as long as needed to improve the service and grant rewards, and are deleted when no longer needed or when the associated account is deleted.
OpenAI may normally retain API abuse-monitoring logs for up to 30 days under its settings and policies. Firebase Analytics data is retained under the configured Firebase retention settings and policies.
Your choices and deletion
- You can revoke Full Access and photo access in iOS Settings.
- You can delete shared context and sign out in the App.
- Builds that expose debug settings let you turn off Cloud Conversion.
- You can request deletion of your account and associated server data through the contact channel.
For account deletion, we will provide the information and secure steps needed to identify the relevant account after you contact us.
Security
The service uses HTTPS, and protects API keys and authentication tokens with Keychain. The App does not write input text or AI output to debug logs. Administrative access is restricted and administrative changes are recorded in an audit trail.
Changes and contact
We may update this Policy as needed. Updated Policy takes effect when posted on this page, or on a later effective date we specify. For material changes, we will update the date on this page and, when appropriate, ask you to review the current terms in the App.