Speakey
Speakey Privacy Policy
Last updated: 2026-07-05
Privacy Policy
Effective date: July 5, 2026
This Privacy Policy explains how Speakey ("Speakey," "we," "us," or "our") handles information when you use the Speakey mobile application and its translation keyboard, together with any related services (the "Service"). Speakey is an AI translation keyboard: you install a system keyboard, type in any app, tap Translate, and the line you typed is replaced with its translation. The host app exists to onboard you, help you enable the keyboard in iOS Settings, and manage your settings and account.
We try to collect as little personal data as we can while still making the Service work, and we explain everything we do collect below in plain English.
If you have questions about this policy, email us at support@inshort.io.
1. Who we are
Speakey is the data controller for the personal data described in this policy. For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the "data controller."
Our infrastructure and the third-party processors we use are located in the United States, so your data is processed in the US (see Sections 5 and 9).
2. No account required
Speakey does not require you to create a traditional account. You do not give us a name, email, or phone number to use the app.
- Anonymous identity. When you first open Speakey we create an anonymous account using Firebase Authentication and store an opaque, device-level user identifier for it. This lets us keep your settings and preferences associated with your device, and lets the keyboard authenticate translation requests.
- We do not ask you to sign in with a name or email to use the keyboard.
3. Information we collect
3.1 Text you translate
When you tap Translate, the snippet of text you chose is sent over an encrypted connection to our translation backend — a Google Firebase Cloud Function that calls the Google Gemini model — which returns the translation to your device.
- The text is processed to perform the translation you requested and is not retained by us as a stored history after the translation is returned.
- We do not log, store, or transmit your keystrokes in the background. Text leaves your device only for the specific snippet you ask us to translate, at the moment you tap.
3.2 The Speakey keyboard and "Full Access"
Speakey's keyboard is a system keyboard you enable in iOS Settings → General → Keyboard → Keyboards. Because keyboards are a sensitive category, please read this carefully:
- You can type normally without granting Full Access. The keyboard works as a standard keyboard with no network connection until you turn on "Allow Full Access."
- "Full Access" is required only to translate. Translating text requires a network connection, and iOS only lets a keyboard reach the network when you grant Full Access. When you enable it and tap Translate, only the snippet of text you chose is sent to our translation backend (Section 3.1).
- What the keyboard does NOT do. We do not log, store, or transmit your keystrokes in the background, and we do not collect what you type in password fields. Text leaves your device only for the specific snippet you ask us to translate.
- What we record about keyboard use. When the keyboard has network access we record anonymous, aggregated usage events (for example, that a translation happened and the languages used) to measure and improve the feature. These events do not contain what you typed beyond the text needed to perform a translation you requested.
3.3 Information we collect automatically
- Device and app information. Device model, OS version, app version, language, time zone, and country (derived from IP).
- Usage events. Product events such as app opens, onboarding steps, keyboard-enable status, translations performed, and feature usage, collected via Firebase Analytics and PostHog (including sampled session replay of in-app screens). We use these to understand which features work and to improve the app.
- Crash and diagnostic data. Crash reports and basic performance metrics via Firebase Crashlytics.
- Push notification token. If you allow notifications, we register a device push token via Firebase Cloud Messaging so we can send you relevant updates. You can turn notifications off at any time in iOS Settings.
- Identifiers for advertising. If you grant App Tracking Transparency (ATT) permission, we and our partners may receive your iOS Identifier for Advertisers (IDFA) for install attribution and ad measurement. If you decline ATT, we do not collect the IDFA. See Section 6.
We do not knowingly collect any other categories of personal data, and we do not ask for sensitive information.
4. How we use your information
We use the information described above to:
- Provide the Service: authenticate your device, translate the text you submit, and return it to your keyboard.
- Improve the Service: understand how features are used, diagnose crashes and bugs, and prioritize fixes.
- Send notifications you have allowed.
- Measure marketing: attribute installs and conversions to advertising campaigns where you have granted ATT permission.
- Comply with legal obligations and protect the rights, safety, and property of users and the public.
5. Third parties we share data with
We share the minimum amount of data needed for each provider to do its job. We do not sell your personal data.
- Google Firebase (Authentication, App Check, Analytics, Crashlytics, Cloud Messaging, and Cloud Functions) — anonymous auth, app-integrity checks, analytics, crash reporting, push notifications, and the translation backend. Receives: anonymous account ID, app and device metadata, crash logs, usage events, push token, and the text you ask to translate. Policy: firebase.google.com/support/privacy and policies.google.com/privacy.
- Google Gemini API — performs the machine translation, called from our Firebase Cloud Function. Receives: the text you ask to translate. Policy: policies.google.com/privacy.
- PostHog — product analytics and sampled session replay. Receives: usage events, device metadata, and sampled recordings of in-app screens. Policy: posthog.com/privacy.
- Adjust — mobile attribution and analytics. Receives: device identifiers (incl. IDFA when allowed), install/event data, IP. Policy: adjust.com/terms/privacy-policy.
- Meta / Facebook SDK — ad attribution and conversion measurement. Receives: device identifiers (incl. IDFA when allowed), install/event data, IP. Policy: facebook.com/privacy/policy.
- RevenueCat — subscription and entitlement management, used to manage access should paid features be offered. Receives: anonymous user ID, device/platform metadata. Policy: revenuecat.com/privacy.
- Apple (SKAdNetwork) — provides privacy-preserving ad attribution. Receives: SKAdNetwork conversion signals. Policy: apple.com/legal/privacy.
We may also share information with professional advisors, with successors in the event of a merger or acquisition, or with authorities where required by law.
6. App Tracking Transparency (ATT) and advertising
On iOS we present Apple's App Tracking Transparency prompt before any tracking that requires it. If you choose "Ask App Not to Track":
- We will not access your device's IDFA.
- Adjust and the Facebook SDK will run in a limited mode that does not link your activity to your identity across other apps and websites.
- Core analytics (crash reporting, product event counts) still operate using non-tracking identifiers, because they are necessary to run the Service.
- Apple's SKAdNetwork may still provide privacy-preserving, aggregate install-attribution that does not identify you.
You can change your choice at any time in iOS Settings → Privacy & Security → Tracking.
7. Data retention
- Text you translate: processed to return the translation and not retained by us as a stored history.
- Anonymous account and settings: kept for as long as your anonymous account exists. You can delete your account in-app.
- Logs and analytics events: typically kept for up to 14 months, then deleted or anonymized.
When you delete your account, we delete or anonymize personal data within 30 days, except where we must keep it to comply with legal obligations.
8. Security
We use industry-standard measures to protect your data, including TLS in transit, encryption at rest with our cloud providers, scoped credentials for our third-party providers, and access controls for our team. No system is perfectly secure, however, and we cannot guarantee absolute security.
9. International data transfers
Speakey and its providers are based in the United States. If you use the Service from outside the US, your personal data will be transferred to and processed in the US. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data ("right to be forgotten").
- Object to or restrict certain processing.
- Receive a copy of your data in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
California residents have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right not to be discriminated against for exercising your rights. We do not "sell" or "share" personal information for cross-context behavioral advertising as defined by the CCPA, and we do not knowingly do so for consumers under 16.
To exercise any of these rights, use the in-app account-deletion option, or email support@inshort.io. We will respond within the time frames required by applicable law. To protect your account, we may need to verify your identity before acting on a request.
11. Children
Speakey is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We require users to be at least 13 years old, or the minimum age required to consent to the processing of personal data in their country, whichever is higher. If you believe a child has provided us with personal information, contact support@inshort.io and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, for significant changes, notify you in-app. Continued use of the Service after a change means you accept the updated policy.
13. Contact us
For privacy questions, requests, or complaints, contact:
- Email: support@inshort.io