Effective date: August 3, 2026 · Last updated: September 8, 2026
Voicetation is a voice-input keyboard for iOS. This policy explains exactly what leaves your device, when, and who receives it. The short version: there are no accounts, no advertising, no tracking, and no data brokers. But this is a keyboard with AI features, and some of what you say and type is sent to servers to make those features work. The sections below say precisely which parts, and how to turn them off.
The two things most people want to know.
Your voice recordings are uploaded to be turned into text, and are not stored by us.
Text you type on the keyboard is not sent anywhere — unless you tap Rewrite or Translate yourself. Text from password fields is never sent, under any setting.
1. Data we process
Leaves your device
Audio recordings. When you tap the microphone and speak, the Voicetation app records audio and uploads it over an encrypted connection (HTTPS) to our server, solely to convert your speech to text. If your device has no network connection, transcription instead runs entirely on-device using Apple's speech engine and nothing is uploaded.
Transcribed text. Only when you tap Rewrite or Translate on the keyboard — the text you selected is then sent to be rewritten or translated. Nothing is sent automatically.
Dictation history excerpts and journal notes. Only if you use the optional Journal features — when you ask the journal a question, redacted excerpts of your recent dictations (if history saving is on) and your journal notes are sent along with the question; when the app extracts journal notes from your day, redacted excerpts of the new dictations are sent. See section 12.
Text you type on the keyboard. See section 3 — this is the part most keyboard privacy policies gloss over, so it has its own section.
Custom dictionary terms. Correct spellings you add — including the correct side of a replacement — are sent along with each recording as a short list of spellings the speech model should recognise. You can turn this off in the Dictionary tab, and the list is never sent when it is off. The misheard side of a replacement (wrong → right) is matched and replaced entirely on your device and is never sent.
Your transcription language setting. Sent with transcription requests so the right language model is used.
A per-installation device identifier. See section 5.
Stays on your device
Keyboard settings — keyboard language, haptics, fuzzy pinyin, swipe, and the rest.
Your personal typing dictionary. The pinyin keyboard learns which candidates you pick, and the English keyboard remembers words you told it not to autocorrect. This is stored locally and is never uploaded.
Which app you are typing in. So that the app can send you back where you came from after voice input, the keyboard reads the identity of the app you are currently using. This is held in memory on your device, is never written to storage, and is never transmitted to us or to anyone else.
Diagnostics. Timing and error information used to troubleshoot the keyboard is written to your device only.
Your dictation history (optional, off by default). If you turn on Save dictation history, a redacted copy of what you dictate is kept on your device for 30 days so the journal can write itself and answer questions about your day. See section 12.
Your journal conversations. Questions you ask your journal, and the answers, are saved on your device so you can revisit them. They are never uploaded on their own, and you can delete any conversation with a swipe.
Dictation usage statistics. The app shows counters like words dictated, speaking speed and streaks. These are plain numbers stored on your device — they contain no text and are computed locally.
Your journal notes. The Journal tab is a notebook of short notes: notes you add yourself (by voice or typing), plus notes the app extracts from your day's dictations when dictation history is on. Notes are stored on your device, kept until you delete them (they are yours — deleting your dictation history does not delete them), and — unlike dictation history — included in normal device backups so they survive moving to a new iPhone. Notes you add yourself are saved exactly as you wrote them, without redaction; auto-extracted notes are derived from the already-redacted history. See section 12.
Your latest unfinished dictation. If transcription fails, or iOS cannot confirm that the destination app accepted the text, Voicetation keeps one temporary recovery copy — audio or text — only on this iPhone for up to 24 hours. It is excluded from iCloud backup and deleted when insertion is confirmed, you copy or discard it, a newer recoverable dictation replaces it, or 24 hours pass. Password-field dictations never enter this recovery slot.
2. How audio is handled
Audio is uploaded to our own server (running on Cloudflare Workers — or, for Chinese-language transcription, a relay server we operate on Alibaba Cloud for lower latency), which forwards it to a third-party speech-recognition provider to produce the transcription. Speech models improve quickly, so we do not tie ourselves to a single one — your audio may be sent to any one of the providers listed in section 7, either directly or through the routing service OpenRouter. Section 7 is the complete list; we will update it before adding anyone new.
Where the provider or the routing service supports it, we request zero-retention routing — meaning the request is only sent to providers that do not keep or train on the data.
Our server holds audio only in memory for the duration of the request, and it is gone when the request ends. We do not store, archive, or reuse your audio. We have no database or file storage containing it.
If a transcription fails, the latest recording stays only on your device so you can retry it. It is uploaded again only when you tap Retry, and is deleted when recovery succeeds, you discard it, a newer recording replaces it, or 24 hours pass.
3. What the keyboard sends
The Voicetation keyboard connects to our servers directly when Full Access is granted and AI features are on. This is what it sends:
Feature
When
What is sent
Default
Typing correction (English keyboard)
Automatically, about two seconds after you stop typing
The text you have typed since the last sentence boundary, up to 300 characters
On
Cloud pinyin candidates (Chinese keyboard)
Automatically, once a pinyin string reaches 20 letters
That pinyin string, plus up to 30 characters of text preceding the cursor
On
Rewrite and Translate
Only when you tap ✨ or 🌐
The text you selected, or up to 3,000 characters before the cursor
Manual
Two things about this deserve to be stated plainly rather than buried:
The first two happen automatically. You do not tap anything.
Cloud pinyin candidates and Rewrite read text from the field you are typing in. That can include text that was already there and that you did not type — a message someone sent you, or something you pasted.
What is never sent:
Anything in a password field. This is enforced in the keyboard itself, in every one of the paths above, regardless of your settings.
Anything in a field marked as URL, email address, phone number, or numeric.
Anything while you are composing pinyin, or while a recording is in progress.
Anything at all, if Full Access is not granted — without it the keyboard cannot reach the network.
As of the current version, none of this happens automatically. Typing correction and cloud pinyin candidates are turned off in the app, so nothing you type is sent anywhere on its own. Rewrite and Translate only ever run when you tap them. Local pinyin, swipe input, English autocorrect, and next-word suggestions are all computed on your device and need no network at all.
4. Text processing and our AI providers
Text you send to Rewrite or Translate is forwarded by our server to a third-party provider that runs the language model doing the work. As with audio, this may be any one of the providers listed in section 7, either directly or through OpenRouter. Section 7 is the complete list; we will update it before adding anyone new.
Our own server holds this text only in memory for the duration of the request and never stores it.
What those providers do with it is their policy, not ours, and it is not all the same. Some — DeepSeek among them — retain API data under their own terms. We say this plainly rather than let "we don't store it" imply more than it means. Where zero-retention routing is available we request it, but we cannot promise it for every provider we may use. Each provider's policy is linked in section 7. If you would rather none of this happened, do not use Rewrite or Translate.
5. Device identifier and server logs
Each request carries a per-installation device identifier — Apple's identifier for vendor, which is specific to your device and to apps from us, and which resets if you delete the app.
We use it to rate-limit abuse of our service. Our request logs store only a short hash of it, together with which endpoint was called, the response status, and how long it took. Logs never contain your audio or your text.
This also lets us count roughly how many devices use the service each day. Beyond that, the app sends anonymous usage statistics described in the next section. There are no third-party analytics or advertising SDKs in the app.
It is not linked to any account, because there are no accounts. We still cannot tell who you are — but we want to be accurate rather than claim more anonymity than the design provides.
Device attestation. So that only genuine copies of this app can use our service, the app asks Apple's App Attest to vouch for your device. This produces a key identifier that we store, along with a counter and the short-lived access token we issue from it. It contains nothing about you or your device beyond "this is a real, unmodified installation of this app," and it is never used to track you or shared with anyone.
Logs are hosted by Cloudflare and retained according to their platform defaults.
6. Anonymous usage statistics
To understand which features get used and how reliably dictation works, the app sends us small anonymous usage events: app opens, things like "a dictation succeeded" or "recording failed to start", which onboarding step was observed, whether the keyboard could confirm that dictated text was inserted, and daily totals — dictations per day, keyboard sessions, and seconds dictated. We also record broad host-app categories and whether an operation could be confirmed, and our server records request status and timing buckets. These events contain no audio, typed or dictated text, original host-app identifiers, or free-form error messages.
These events contain only event names, fixed category values, counts, and duration buckets — never what you say or type. The pipeline rejects free-form text by design, both on the device and again on our server.
Events are grouped using hashes derived from Apple's identifier for vendor, so we can connect app events with server request outcomes without storing the original identifier in analytics. They are not linked to an account. We operate the analytics ourselves on Cloudflare, including our Journey service and its own iOS SDK; there is no advertising SDK or third-party analytics company. Analytics Engine data is retained for at most 92 days; Journey events are retained for at most 400 days. Journey events waiting to be sent on your device expire after 6 days.
You can turn this off any time in Settings › Advanced › Share anonymous usage statistics. Turning it off also deletes anything queued on your device.
Your audio recordings, if the provider is running the speech model. Transcribed text, typed text, pinyin, rewrite input, and — when you use the Journal's AI features — your journal notes, redacted dictation history excerpts and your questions, if it is running the language model.
Chinese-language voice audio and its transcription results pass through a relay server we operate on Alibaba Cloud (mainland China); held in memory only, never stored
Hosts our China relay server, which forwards Chinese speech recognition to the provider with lower latency
Any single request goes to one provider, not all of them. The list above is every provider we may use, so that we can move to a better model without waiting to rewrite this page — it is not a list of companies your data is broadcast to. We keep this list current: no provider receives your data before it appears here.
We do not sell or share your data with anyone else, and none of these parties receive it for their own advertising purposes.
8. Using your own API key
Voicetation has an optional mode where you supply your own API key. When it is on, your audio and text go directly from your device to the provider you configured, using your key. They do not pass through our servers, and we neither see nor log them. Your key is stored in the iOS Keychain on your device, never in plain text and never uploaded.
9. Downloadable language models
If you set the keyboard to Chinese, the app downloads a language model from our servers to improve on-device pinyin accuracy. These downloads carry no identifier and no information about you. The models run entirely on your device.
10. Permissions
Microphone — required to record your voice. Requested only when you first use voice input.
Keyboard Full Access — required so the keyboard can hand recording off to the main app, receive the transcribed text back, and reach our servers for the AI features described in section 3. Without it, the keyboard still types, swipes, autocorrects, and suggests words, all offline; only voice input and the AI features are unavailable.
11. Retention and your choices
Audio — held in memory during the request only; not retained by us.
Text — not retained by us; retention by whichever AI provider handled it is governed by that provider's own policy, and some do retain it (section 4).
Request logs — endpoint, status, timing, and a device hash; no content. Retained per Cloudflare platform defaults.
Everything on your device — settings, personal dictionary, learned words, diagnostics — is removed when you delete the app.
Dictation history — on your device only, off by default, 30-day rolling window; delete it any time in the app (section 12).
Journal notes — on your device, kept until you delete them, included in device backups; sent to an AI provider only when you ask the journal a question (section 12).
Because there are no accounts, we hold nothing that is identifiable to you as a person, and so there is no account to close and no profile to export or erase. You can stop all off-device processing at any time by not using voice input and not using Rewrite or Translate, or by deleting the app.
12. Dictation history, the Journal and Insights
The Journal tab is a notebook of short notes. You can add notes yourself at any time (by voice or typing). Separately, Voicetation can keep a history of what you dictate so the journal can also write itself from your day and so you can ask an AI assistant about it (“what did I talk about this week?”). History saving is off by default; nothing is recorded until you turn on Save dictation history in Settings.
History is stored on your device only. It lives in the app's local storage, is excluded from device backups, and is never uploaded on its own or synced anywhere.
History is redacted before it is saved. Email addresses and long numbers (phone numbers, card numbers, ID numbers, verification codes) are replaced with placeholders before anything is written. Dictation into password fields is never saved at all.
History is deleted automatically. Entries older than 30 days are removed, and you can delete the whole history at any time from the History page.
Journal notes are yours and permanent. Notes stay on your device until you delete them individually; deleting your dictation history does not delete them. Notes you add yourself are saved as written (no redaction); notes the app extracts are derived from the already-redacted history. Unlike history, notes are included in normal device backups so they survive moving to a new iPhone. Once a note is in your journal the app never edits or removes it on its own — auto-extraction only ever adds new notes, from dictations it has not looked at before.
Sent only when you ask, or when the app extracts new notes. When you ask a question — your question, your journal notes and (if history saving is on) redacted history excerpts (and, in an ongoing conversation, the previous questions and answers of that conversation) — or when the app extracts journal notes from your newest dictations on opening (past days are caught up once; today may be processed a few times over the day as you keep dictating) — the text is sent to our server, which forwards it to an AI provider (sections 4 and 7) to produce the answer. Our server holds it in memory for the duration of the request and never stores it. If you use your own API key (section 8), it goes directly to your configured provider instead and does not pass through our servers.
13. Children
Voicetation is not directed at children under 13, and we do not knowingly collect personal information from them.
14. Changes to this policy
If we change how data is handled, we will update this page and the date at the top. Material changes will also be reflected in the app's own privacy disclosures.