Policies

Privacy Policy

Last updated: Effective:

At a glance

  • Everyday typing is processed on your device. Keystrokes and your local dictionary are never uploaded.
  • AI features process the text you tap them on in real time, only when you tap. We do not collect or keep that text; the result is cached encrypted for at most 10 minutes, only so you can fetch it again after a network drop.
  • Screenshot text recognition runs on your device. The screenshot itself is never uploaded, and clipboard history stays on your device.
  • Hartype collects nothing until you agree to this policy. If you don't agree, you can still type normally.
  • Sign-in is Sign in with Apple only. We never ask for your phone number, contacts, photos, location, microphone or camera.
  • You can delete your account at any time from the Me tab in the app. Your account and its data are deleted permanently.

Hartype Keyboard (“Hartype”, “the app”) is provided by the Hartype team (“we”, “us”). We know how much your personal information matters, and how sensitive a keyboard’s position is: everything you type in every app passes through it. This policy explains how we collect, use, store, share and protect your personal information, and the rights you have.

Please read this policy carefully before using Hartype. Points that most affect your rights are in bold. If you have any questions, contact us using the details at the end.

1. How we collect and use your information

We only collect what a feature needs to work. Below, feature by feature: what is used, why, and where it is kept.

The first time you open Hartype, we ask you to read and agree to this policy. Until you agree, Hartype collects nothing: crash reporting and the subscription service don’t start, the keyboard doesn’t read images on your clipboard or record clipboard history, and AI features are unavailable. You can decline and keep using basic typing.

1.1 Everyday typing (no network, no account)

Hartype’s input engine runs on your device. Your keystrokes, candidates, committed text, custom words and user dictionary are processed and stored only on your device. We do not collect them and have no way to read them.

The keyboard extension and the Hartype app share settings (layouts, color themes, input schemas, the persona list in My Keyboard and so on) through an iOS App Group container. That data also stays on your device.

Clipboard history. While the keyboard is showing, text you newly copy is added to clipboard history so you can use it again from Clipboard in the function panel. Clipboard history is kept only in the shared container on your device and is never uploaded. Hartype skips content that password managers mark as sensitive. Unpinned entries are deleted after the number of days you choose in Settings → Clipboard (1, 3, 7 or 30; 7 by default), and at most 200 are kept. Withdrawing your consent to this policy clears it.

1.2 AI replies (Reply, Say It), polish and translate

When you choose to tap the ✦ key, tap a persona or Read Them in Reply, tap Polish or a persona in Say It, or pick Translate in the function panel, we send the following to the Hartype server in real time, only to generate that result:

  • The text to process:
    • ✦ key: the selected text in the field, or all of it; if the field is empty, the text on your clipboard (for example, a message you copied);
    • Reply: their words in the “Them:” box (filled from your clipboard when Reply opens, or recognized from a screenshot by Read Them);
    • Say It: what you wrote in the keyboard’s own text box;
  • The mode (reply, screenshot reply, polish, translate), the AI persona you selected and how many options you want;
  • Who they are to you and the chat intimacy you set on the keyboard (intimacy is sent only after you have adjusted it), plus your AI reply language and app language;
  • Credentials used to verify your sign-in and your device’s integrity (see “Account and sign-in” below).

To generate the result, the server also reads the reply preferences in your account (see 1.5) so replies fit you better.

This is sent once, only when you tap. Hartype never reads or uploads what you type in the background. Requests are sealed end to end with HPKE and then sent over HTTPS.

Our server passes the prompt to a large language model inference service provided by the cloud provider we engage, and never forwards it to other AI companies. This text is processed in real time, only to complete the request; we do not collect or keep it. Specifically:

  • The text you send and the text the AI generates are not written to our database or to our logs;
  • So you can fetch the same result again after a network drop, the result is cached encrypted with AES-GCM for at most 10 minutes, then deleted;
  • Who they are to you, intimacy and reply language are only used to build that prompt and are not written to our database or logs;
  • To count your daily quota and our costs, we keep metadata about each generation: the mode, the persona ID, the number of tokens used, and a success or failure code. These records contain no text.

AI output is generated automatically and may be inaccurate or inappropriate. Please review it before sending.

1.3 Screenshot text recognition (Read Them)

When you copy a chat screenshot and use screenshot reply or Read Them, Hartype extracts the text on your device using Apple’s built-in text recognition (the Vision framework), and uses the position of each chat bubble to mark which lines they said and which you said. The screenshot itself never leaves your device. The recognized text is then handled as described in 1.2.

1.4 Account and sign-in

AI features and custom personas require an account. Hartype only offers Sign in with Apple. When you sign in we receive and keep:

  • The user identifier provided by Apple;
  • The email address and name you choose to share (this may be Apple’s Hide My Email address). If you don’t share them, we don’t receive them;
  • Device information: a device ID generated by the app, the device name, the platform (iOS) and your time zone at registration. The time zone decides when your daily quota resets;
  • Your sign-in session: session tokens are stored only as one-way hashes and are valid for 30 days by default;
  • Apple App Attest data, used to confirm that requests come from a genuine, unmodified Hartype app and to prevent abuse. We store the attestation key’s public key and a counter, none of your content.

The number of devices per account is limited; device information is used to manage and free up device slots.

1.5 Reply preferences (optional)

On first launch you can answer a few short questions: when you’d like Hartype to help, the tone you prefer, what you’ll use Hartype for most, and how the AI should help you. Every question has fixed options and can be skipped, and none asks for gender, age or other personal details. Your answers stay on your device by default and are synced to your account only after you sign in, as reply preferences that help AI match the way you express yourself. You can change them at any time in Settings → Assistant → Reply Preferences.

1.6 Custom AI personas

Personas you create under My AI Personas (name, description, speaking style and avatar category) are stored in your account and are visible and usable only by you. The speaking style is only used to build the prompt at generation time and is never logged.

1.7 Hartype Pro subscriptions

Purchases are made through the Apple App Store. We never see your bank card or your Apple payment details. To unlock benefits across your devices, we check your subscription status through RevenueCat and keep: the product ID, the status (active, grace period, expired and so on), the expiry date and the purchase environment. RevenueCat links purchases to your Hartype account ID.

1.8 Usage statistics and service logs

To keep the service stable, troubleshoot problems and improve our personas, we record:

  • Request logs: operation name, result code, duration and account ID;
  • Error logs: operation name, error class and error code, without error message text;
  • Persona usage: events such as insert, regenerate and close on a persona, with timestamps.

These logs do not contain prompts, your input or AI output, and are deleted automatically after 30 days.

1.9 Security and abuse prevention

To stop abuse, the server computes a keyed hash (HMAC) of the requesting IP address for rate limiting and security audit counters. The raw IP address is not stored in our database. Security audit counters are kept for 90 days.

1.10 Crash reports

If the app or keyboard crashes, we collect a crash report through Sentry, including the stack trace, device model, OS version, app version and the breadcrumbs leading up to the crash. Crash reports do not contain anything you typed. Sentry session tracking and performance monitoring are turned off; we use it only to find crashes.

1.11 Local network transfer (Wi-Fi upload of input schemas)

When you turn on Wi-Fi transfer in the app, Hartype starts a file server on your device that is reachable only on your current local network, so you can upload input schemas from a computer. Files travel directly between your device and your computer, never through our servers. The server stops when you leave the page or turn the switch off.

1.12 Data summary

The table below sums up the data we actually collect and keep from the items above, using the same categories as App Store App Privacy. Hartype never uses any data to track you across apps or for advertising.

CategoryDataPurposeLinked to you
Contact infoThe email and name you choose to share through Sign in with AppleAccount managementYes
IdentifiersUser ID (Apple user identifier, Hartype account ID), device IDAccount and device managementYes
PurchasesHartype Pro subscription historyUnlocking and syncing Pro benefitsYes
User contentCustom AI personasApp functionalityYes
Usage dataPersona usage, AI generation metadata (mode, persona, token counts, no text), request logsDaily quota, service stability, improving personasYes
DiagnosticsCrash reportsFixing problemsNo
Other dataReply preferences (questionnaire choices, synced after sign-in), time zone at registrationPersonalization, quota reset timeYes

We do not collect: your keystrokes or what you type, your local dictionary, clipboard history, screenshots, the text and results of AI requests, or who they are to you and the intimacy you choose for AI. AI request text is processed in real time when you tap and discarded afterwards, never written to our database or logs; results are cached encrypted for at most 10 minutes only so you can fetch them again after a network drop. Screenshots are recognized on your device and never leave it.

2. About the keyboard’s Full Access permission

iOS requires third-party keyboards to have “Allow Full Access” turned on before they can use the network, read and write the shared App Group container, or read the clipboard. Hartype asks for this permission only to:

  • Sync your keyboard settings and sign-in state with the main app;
  • Reach our server when you choose to use an AI feature;
  • Read the text or screenshot on your clipboard when you choose to use an AI feature: tapping ✦ with an empty text field, opening Reply (which fills the “Them:” box from your clipboard, again whenever the clipboard changes), and Read Them;
  • While the keyboard is showing, read text you newly copy and add it to clipboard history, which stays on your device.

With Full Access turned off, basic typing still works; only AI features and settings sync are unavailable. You can turn it on or off at any time in iOS Settings → General → Keyboard → Keyboards → Hartype.

In secure text fields such as password fields, and in apps that disallow third-party keyboards, iOS always switches to the system keyboard, so Hartype never sees that input.

3. Cookies and tracking

  • The Hartype app contains no advertising SDKs. It does not use the advertising identifier (IDFA), does not track you across apps, and never sells your data to anyone.
  • This website (hartype.com) is a static site. It sets no cookies and uses no third-party analytics.

4. How we entrust, share, transfer and disclose information

Processors. Hartype’s servers, database and large language model run with a cloud provider we engage. The provider may only process data on our instructions and to the extent necessary, and may not use it for any other purpose.

Third-party SDKs. Hartype contains no advertising, analytics or social sharing SDKs. Only two third-party SDKs in the app touch personal information:

SDKProviderPurposeData collectedPrivacy policy
RevenueCatRevenueCat, Inc. (United States)Checks App Store subscription status and syncs Pro benefits across devicesHartype account ID, subscription and transaction records, app and OS version, region and language settings, network addressrevenuecat.com/privacy
SentryFunctional Software, Inc. (United States)Collects crash reportsStack traces, device model, OS and app version, breadcrumbs before the crash, network address; no typed content, not linked to your accountsentry.io/privacy

Sign-in, device attestation, in-app purchase and on-device text recognition use Apple’s system features; that data is handled under Apple’s Privacy Policy.

Transfer. If a merger, acquisition or asset transfer requires moving personal information, we will require the new holder to remain bound by this policy, or ask for your consent again.

Public disclosure. We do not publicly disclose your personal information unless you give separate consent, or laws, regulations, courts or government authorities lawfully require it.

5. Where and how long we keep data

The Hartype server and database run on cloud infrastructure outside mainland China, preferentially in the Asia-Pacific region. RevenueCat and Sentry servers are in the United States. Some of your personal information may therefore be processed outside your country or region. We require these providers to protect it to a standard no lower than this policy, and transfer only the minimum data needed.

DataRetention
AI request text and generated resultsText is not stored; encrypted results cached for at most 10 minutes
Account, devices, reply preferences, custom personasUntil you delete your account, then deleted with it
AI usage counts and generation metadata (no text)Until you delete your account, then deleted with it
Subscription entitlement statusUntil you delete your account; Apple and RevenueCat keep transaction records under their own policies
Sign-in sessionsValid for 30 days by default, then kept for up to 30 more days for security review
Request logs, error logs, persona usage30 days; the account ID in logs is cleared as soon as you delete your account
Clipboard history (on your device only)Deleted after the 1, 3, 7 or 30 days you choose (7 by default); pinned entries stay until you delete them
Rate-limit and security audit counters (IP hashes)90 days
Crash reportsUnder Sentry’s data retention policy, then deleted automatically

After the retention period, we delete or anonymize the information.

6. How we protect your information

  • Encryption in transit: business data between the app and our server is sealed with HPKE (RFC 9180) and then sent over HTTPS;
  • Device attestation: Apple App Attest confirms requests come from the genuine app, and every request is checked against replay;
  • Data minimization: session tokens are stored only as hashes, IP addresses only as keyed hashes, AI text is never stored, and results are cached encrypted for 10 minutes at most;
  • Access control: production data can only be accessed by authorized staff through an authenticated admin console.

No system on the internet is 100% secure. If a personal information security incident occurs, we will inform you as required by law: what happened, the possible impact, the measures we have taken or will take, and what you can do to protect yourself.

7. Your rights

You have the following rights over your personal information:

  • Access and correction: view your account and custom personas on the Me tab, and edit or delete personas at any time; change your reply preferences in Settings → Assistant → Reply Preferences;
  • Withdrawing consent: withdraw your consent to this policy at any time in Hartype’s Settings → Privacy (this signs you out, stops crash reporting and clears clipboard history; afterwards only basic typing is available), turn off Hartype’s Full Access in iOS Settings, or stop Hartype from using your Apple Account under Settings → Apple Account → Sign-In & Security → Sign in with Apple. Withdrawal does not affect processing already carried out;
  • Deletion and account closure: on the Me tab, choose Delete Account and confirm with your Apple Account. Your account, signed-in devices, reply preferences, custom personas, AI usage records and subscription entitlement link are deleted permanently. Deleting your account does not cancel an App Store subscription. Cancel it in your Apple Account first to avoid further charges;
  • Signing out: signing out clears the credentials on your device and ends the session on our server;
  • Copies and complaints: email us to request a copy of your personal information or to raise an objection to how we handle it.

We will reply within 15 business days after verifying your identity.

8. Children

Hartype is intended mainly for adults. If you are under 14, please read this policy with a parent or guardian and use Hartype only with their consent. If we learn that we have collected a child’s personal information without guardian consent, we will delete it promptly. Parents and guardians can contact us using the details below.

9. Changes to this policy

We may update this policy from time to time. Updates are posted on this page with a new date at the top. For material changes (for example, to the purposes of collection, the types of data or the third parties involved), we will notify you prominently in the app, such as with a pop-up.

If this policy is provided in more than one language and the versions conflict, the Chinese version prevails.

10. Contact us

If you have any questions, comments or complaints about this policy or how we handle personal information, email support@hartype.com. We will reply within 15 business days.