Voicetation Privacy Policy
Effective date: August 3, 2026 · Last updated: August 16, 2026
Voicetation is a voice-input keyboard for iOS. This policy explains exactly what leaves your device, when, and who receives it. The short version: there are no accounts, no advertising, no tracking, and no data brokers. But this is a keyboard with AI features, and some of what you say and type is sent to servers to make those features work. The sections below say precisely which parts, and how to turn them off.
The two things most people want to know.
Your voice recordings are uploaded to be turned into text, and are not stored by us.
Text you type on the keyboard is not sent anywhere — unless you tap Rewrite or Translate yourself. Text from password fields is never sent, under any setting.
1. Data we process
Leaves your device
- Audio recordings. When you tap the microphone and speak, the Voicetation app records audio and uploads it over an encrypted connection (HTTPS) to our server, solely to convert your speech to text. If your device has no network connection, transcription instead runs entirely on-device using Apple's speech engine and nothing is uploaded.
- Transcribed text. Only when you tap Rewrite or Translate on the keyboard — the text you selected is then sent to be rewritten or translated. Nothing is sent automatically.
- Dictation history excerpts. Only if you turn on the optional Insights feature (off by default) and ask it a question — redacted excerpts of your recent dictations are sent along with the question. See section 12.
- Text you type on the keyboard. See section 3 — this is the part most keyboard privacy policies gloss over, so it has its own section.
- Custom dictionary terms. Correct spellings you add — including the correct side of a replacement — are sent along with each recording as a short list of spellings the speech model should recognise. You can turn this off in the Dictionary tab, and the list is never sent when it is off. The misheard side of a replacement (wrong → right) is matched and replaced entirely on your device and is never sent.
- Your transcription language setting. Sent with transcription requests so the right language model is used.
- A per-installation device identifier. See section 5.
Stays on your device
- Keyboard settings — keyboard language, haptics, fuzzy pinyin, swipe, and the rest.
- Your personal typing dictionary. The pinyin keyboard learns which candidates you pick, and the English keyboard remembers words you told it not to autocorrect. This is stored locally and is never uploaded.
- Which app you are typing in. So that the app can send you back where you came from after voice input, the keyboard reads the identity of the app you are currently using. This is held in memory on your device, is never written to storage, and is never transmitted to us or to anyone else.
- Diagnostics. Timing and error information used to troubleshoot the keyboard is written to your device only.
- Your dictation history (optional, off by default). If you turn on Save dictation history, a redacted copy of what you dictate is kept on your device for 30 days so the Insights feature can answer questions about it. See section 12.
- Your Insights conversations. Questions you ask about your history, and the answers, are saved on your device so you can revisit them. They are never uploaded on their own, and you can delete any conversation with a swipe.
- Dictation usage statistics. The Insights tab shows counters like words dictated, speaking speed and streaks. These are plain numbers stored on your device — they contain no text and are computed locally.
- Daily journal entries. If dictation history is on, the app caches a short auto-extracted journal for each day (a few short notes about what happened) on your device so it displays instantly without re-analysing. Deleted together with your history.
- Your latest unfinished dictation. If transcription fails, or iOS cannot confirm that the destination app accepted the text, Voicetation keeps one temporary recovery copy — audio or text — only on this iPhone for up to 24 hours. It is excluded from iCloud backup and deleted when insertion is confirmed, you copy or discard it, a newer recoverable dictation replaces it, or 24 hours pass. Password-field dictations never enter this recovery slot.
2. How audio is handled
- Audio is uploaded to our own server (running on Cloudflare Workers — or, for Chinese-language transcription, a relay server we operate on Alibaba Cloud for lower latency), which forwards it to a third-party speech-recognition provider to produce the transcription. Speech models improve quickly, so we do not tie ourselves to a single one — your audio may be sent to any one of the providers listed in section 7, either directly or through the routing service OpenRouter. Section 7 is the complete list; we will update it before adding anyone new.
- Where the provider or the routing service supports it, we request zero-retention routing — meaning the request is only sent to providers that do not keep or train on the data.
- Our server holds audio only in memory for the duration of the request, and it is gone when the request ends. We do not store, archive, or reuse your audio. We have no database or file storage containing it.
- If a transcription fails, the latest recording stays only on your device so you can retry it. It is uploaded again only when you tap Retry, and is deleted when recovery succeeds, you discard it, a newer recording replaces it, or 24 hours pass.
3. What the keyboard sends
The Voicetation keyboard connects to our servers directly when Full Access is granted and AI features are on. This is what it sends:
| Feature | When | What is sent | Default |
Typing correction (English keyboard) |
Automatically, about two seconds after you stop typing |
The text you have typed since the last sentence boundary, up to 300 characters |
On |
Cloud pinyin candidates (Chinese keyboard) |
Automatically, once a pinyin string reaches 20 letters |
That pinyin string, plus up to 30 characters of text preceding the cursor |
On |
| Rewrite and Translate |
Only when you tap ✨ or 🌐 |
The text you selected, or up to 3,000 characters before the cursor |
Manual |
Two things about this deserve to be stated plainly rather than buried:
- The first two happen automatically. You do not tap anything.
- Cloud pinyin candidates and Rewrite read text from the field you are typing in. That can include text that was already there and that you did not type — a message someone sent you, or something you pasted.
What is never sent:
- Anything in a password field. This is enforced in the keyboard itself, in every one of the paths above, regardless of your settings.
- Anything in a field marked as URL, email address, phone number, or numeric.
- Anything while you are composing pinyin, or while a recording is in progress.
- Anything at all, if Full Access is not granted — without it the keyboard cannot reach the network.
As of the current version, none of this happens automatically. Typing correction and cloud pinyin candidates are turned off in the app, so nothing you type is sent anywhere on its own. Rewrite and Translate only ever run when you tap them. Local pinyin, swipe input, English autocorrect, and next-word suggestions are all computed on your device and need no network at all.
4. Text processing and our AI providers
- Text you send to Rewrite or Translate is forwarded by our server to a third-party provider that runs the language model doing the work. As with audio, this may be any one of the providers listed in section 7, either directly or through OpenRouter. Section 7 is the complete list; we will update it before adding anyone new.
- Our own server holds this text only in memory for the duration of the request and never stores it.
- What those providers do with it is their policy, not ours, and it is not all the same. Some — DeepSeek among them — retain API data under their own terms. We say this plainly rather than let "we don't store it" imply more than it means. Where zero-retention routing is available we request it, but we cannot promise it for every provider we may use. Each provider's policy is linked in section 7. If you would rather none of this happened, do not use Rewrite or Translate.
5. Device identifier and server logs
- Each request carries a per-installation device identifier — Apple's identifier for vendor, which is specific to your device and to apps from us, and which resets if you delete the app.
- We use it to rate-limit abuse of our service. Our request logs store only a short hash of it, together with which endpoint was called, the response status, and how long it took. Logs never contain your audio or your text.
- This also lets us count roughly how many devices use the service each day. Beyond that, the app sends anonymous usage statistics described in the next section. There are no third-party analytics or advertising SDKs in the app.
- It is not linked to any account, because there are no accounts. We still cannot tell who you are — but we want to be accurate rather than claim more anonymity than the design provides.
- Device attestation. So that only genuine copies of this app can use our service, the app asks Apple's App Attest to vouch for your device. This produces a key identifier that we store, along with a counter and the short-lived access token we issue from it. It contains nothing about you or your device beyond "this is a real, unmodified installation of this app," and it is never used to track you or shared with anyone.
- Logs are hosted by Cloudflare and retained according to their platform defaults.
6. Anonymous usage statistics
- To understand which features get used and how reliably dictation works, the app sends us small anonymous usage events: things like "a dictation succeeded" or "recording failed to start", which onboarding step was completed, and daily totals — dictations per day, keyboard sessions, and seconds dictated.
- These events contain only event names, fixed category values, counts, and duration buckets — never what you say or type. The pipeline rejects free-form text by design, both on the device and again on our server.
- Events are grouped by the same short, non-reversible device hash as our request logs (previous section) and are not linked to any account or identity. The data goes only to our own server — no third-party analytics service — and is retained for at most 92 days.
- You can turn this off any time in Settings › Advanced › Share anonymous usage statistics. Turning it off also deletes anything queued on your device.
7. Third parties
| Who | What they may receive | Why |
| AI model providers — any one of:
OpenAI,
Anthropic,
Google,
xAI,
DeepSeek,
Alibaba Cloud (Qwen),
Volcengine (Doubao Speech),
Together AI,
Mistral |
Your audio recordings, if the provider is running the speech model. Transcribed text, typed text, pinyin, rewrite input, and — when you use Insights — redacted dictation history excerpts and your questions, if it is running the language model. |
Speech recognition; rewriting, translation |
| OpenRouter | Whatever is being sent to a provider it routes to | Routing layer in front of the providers above |
| Cloudflare | All traffic passes through; request logs; hosts our downloadable language models | Our server platform |
| Alibaba Cloud (infrastructure) | Chinese-language voice audio and its transcription results pass through a relay server we operate on Alibaba Cloud (mainland China); held in memory only, never stored | Hosts our China relay server, which forwards Chinese speech recognition to the provider with lower latency |
Any single request goes to one provider, not all of them. The list above is every provider we may use, so that we can move to a better model without waiting to rewrite this page — it is not a list of companies your data is broadcast to. We keep this list current: no provider receives your data before it appears here.
We do not sell or share your data with anyone else, and none of these parties receive it for their own advertising purposes.
8. Using your own API key
Voicetation has an optional mode where you supply your own API key. When it is on, your audio and text go directly from your device to the provider you configured, using your key. They do not pass through our servers, and we neither see nor log them. Your key is stored in the iOS Keychain on your device, never in plain text and never uploaded.
9. Downloadable language models
If you set the keyboard to Chinese, the app downloads a language model from our servers to improve on-device pinyin accuracy. These downloads carry no identifier and no information about you. The models run entirely on your device.
10. Permissions
- Microphone — required to record your voice. Requested only when you first use voice input.
- Keyboard Full Access — required so the keyboard can hand recording off to the main app, receive the transcribed text back, and reach our servers for the AI features described in section 3. Without it, the keyboard still types, swipes, autocorrects, and suggests words, all offline; only voice input and the AI features are unavailable.
11. Retention and your choices
- Audio — held in memory during the request only; not retained by us.
- Text — not retained by us; retention by whichever AI provider handled it is governed by that provider's own policy, and some do retain it (section 4).
- Request logs — endpoint, status, timing, and a device hash; no content. Retained per Cloudflare platform defaults.
- Everything on your device — settings, personal dictionary, learned words, diagnostics — is removed when you delete the app.
- Dictation history — on your device only, off by default, 30-day rolling window; delete it any time in the app (section 12).
- Because there are no accounts, we hold nothing that is identifiable to you as a person, and so there is no account to close and no profile to export or erase. You can stop all off-device processing at any time by not using voice input and not using Rewrite or Translate, or by deleting the app.
12. Dictation history and Insights
Voicetation can optionally keep a history of what you dictate, so you can ask an AI assistant about it (“what did I talk about this week?”). This is off by default; nothing is kept until you turn on Save dictation history in the app's AI tab.
- Stored on your device only. The history lives in the app's local storage, is excluded from device backups, and is never uploaded on its own or synced anywhere.
- Redacted before it is saved. Email addresses and long numbers (phone numbers, card numbers, ID numbers, verification codes) are replaced with placeholders before anything is written. Dictation into password fields is never saved at all.
- Deleted automatically. Entries older than 30 days are removed, and you can delete the whole history at any time from the Insights page.
- Sent only when you ask, or when the app writes your daily journal. When you ask a question — or when the app generates a day's journal on opening (a past day is analysed once; today's journal may be refreshed a few times over the day as you keep dictating) — the redacted excerpts are sent with the question (and, in an ongoing conversation, the previous questions and answers of that conversation) to our server, which forwards them to an AI provider (sections 4 and 7) to produce the answer. Our server holds them in memory for the duration of the request and never stores them. If you use your own API key (section 8), they go directly to your configured provider instead and do not pass through our servers.
13. Children
Voicetation is not directed at children under 13, and we do not knowingly collect personal information from them.
14. Changes to this policy
If we change how data is handled, we will update this page and the date at the top. Material changes will also be reflected in the app's own privacy disclosures.
15. Contact
Questions about this policy: truant.wz@gmail.com