TRUST & SAFETY

Privacy Policy

Last Updated: June 2026

Introduction

Noetic is an AI-powered keyboard extension for iPhone and iPad. We take your privacy seriously. Privacy is not an afterthought at Noetic — it is a core principle built into every decision we make. This Privacy Policy explains what information we collect, how we use it, and how we protect it.

By using Noetic, you agree to the collection and use of information in accordance with this policy. If you do not agree with our practices, please do not use our app.

This notice is available in English. Upon request, we can provide it in any of the 22 scheduled languages of India. Please email us to request a translated copy.

Information We Collect

Device Identifier (UUID): When you first launch Noetic, we generate a unique identifier and store it in your iPhone's Keychain. This identifier persists across app reinstalls and is used to track your account and sync your preferences across devices. We use this to enforce our two-device policy.

Email and Display Name: If you choose to sign in with Google or Apple, we receive your email address and display name from the sign-in provider. These are stored to identify your account and send you important notifications.

Anonymous Crash Reports: We use Firebase Crashlytics to automatically collect crash reports when the app encounters an error. These reports contain no personally identifiable information — only stack traces, device model, and iOS version. This helps us improve app stability.

Anonymous Usage Statistics: We track aggregate usage metrics such as the number of actions performed and total words processed (as a count only — never the actual text). These statistics help us improve the app and manage credit allocation.

Information We Do NOT Collect

We are built from the ground up to respect your digital boundary. Because iOS architecture enforces strict sandboxing, we cannot read password fields or access system-sensitive APIs.

  • Keystrokes & typing logs Never Collected
  • Passwords & credit card inputs Never Collected
  • Private message history Never Collected
  • GPS location tracking Never Collected
  • Contacts & address book Never Collected
  • Photos & camera access Never Collected
  • Microphone & voice records Never Collected

Why Full Access is Required

iOS requires that custom keyboards request "Full Access" in order to make network requests. This is a system-level requirement, not specific to Noetic. Full Access in iOS does NOT grant access to your passwords, messages, or private data — iOS enforces strict sandboxing between keyboard extensions and system-sensitive APIs.

We require Full Access for one reason only: to send text to our AI processing backend over HTTPS for features like grammar fixing, tone rewriting, translation, and summarization. Without Full Access, the keyboard has no internet connectivity and our AI features cannot function. Standard QWERTY typing is processed entirely locally on your device and is never transmitted or stored.

We are technically incapable of reading password fields or accessing messaging app content. iOS's security model prevents this at the operating system level.

How Your Text Is Processed

When you tap a Noetic action button (Fix, Tone, Assist, Summarize, or Translate), the text you have selected is sent to our AI processing backend. This happens only on your explicit action — never passively in the background.

During transmission, your text is encrypted using HTTPS/TLS. Once processed by our AI model, the result is sent back to your keyboard. The original text is not stored or logged. It is processed and immediately discarded.

We do not use your text for training our AI models. Your writing is processed for inference only and treated as ephemeral.

Third-Party Services

We partner only with security-first services to operate the keyboard features:

  • OpenAI (AI text processing — grammar, tones, summarization) Active
  • Google Generative AI (AI text processing — translation, advanced tools) Active
  • Supabase (Database, Auth, and APIs) Active
  • Firebase Crashlytics (Anonymous stability diagnostics) Active
  • Google AdMob (Optional rewarded ad support) Active
  • Apple StoreKit (Subscription billing system) Active

Your text is sent to these AI providers only when you explicitly tap an action button. It is processed for inference only and immediately discarded. These providers do not use your text to train their models under our agreements. While these providers do not use your text to train their models, they may temporarily retain API request data for up to 30 days for abuse monitoring and safety purposes, in accordance with their own data processing agreements.

Account Limits & Data Retention

Two-Device Limit: Noetic accounts are linked to a maximum of 2 devices. This policy is enforced using Apple DeviceCheck tokens to prevent credit abuse and fraud.

Data Retention: Your device ID remains in your Keychain. If you delete the Noetic app, all local data is removed. If you wish to permanently delete your account, please email us.

Your Rights (Global & Regional Privacy Frameworks)

Noetic is available globally. Depending on your location, you have specific data protection rights under regional laws. We respect and support these rights for all our users in their respective jurisdictions through manual request and system controls:

EU & UK Users (GDPR / UK GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights as a Data Subject under GDPR. We respond to all inquiries within 30 days:

  • Right to Access your personal data Provided via Email Request
  • Right to Rectification (correction of inaccurate data) Managed via Google/Apple Settings or Email
  • Right to Erasure (Right to be Forgotten / Account deletion) Supported (In-App or Email Request)
  • Right to Data Portability (receive data in a structured format) Fulfilled via Email (JSON Export)
  • Right to Object or Restrict processing Supported (Deactivate app or delete account)
  • Right to lodge a complaint with a supervisory authority Supported (Contact your local DPA)

California Users (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act. We respond to all inquiries within 45 days:

  • Right to Know what personal data is collected and accessed Provided via Email Request
  • Right to Delete personal data Supported (In-App or Email Request)
  • Right to Opt-Out of the sale or sharing of personal data We Do NOT Sell Personal Data
  • Right to Non-Discrimination for exercising privacy rights Guaranteed

India Users (DPDPA, 2023)

Under the Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal. We respond to all inquiries within 14 days:

  • Right to Access your personal data Provided via Email Request
  • Right to Correction of inaccurate data Managed via Google/Apple Settings or Email
  • Right to Erasure (account deletion) Supported (In-App or Email Request)
  • Right to Withdraw Consent at any time Supported (Turn off Full Access / Delete app)
  • Right to Nomination Supported via Email Request

To exercise any of these rights, email us at noeticaikeyboard@gmail.com.

Withdrawing Consent

You can withdraw your consent at any time through any of the following methods:

  • Disable "Allow Full Access" in iOS Settings Instant
  • Delete the Noetic app from your device Instant
  • Email us to delete your account and all data Within 14 days

Withdrawing consent will not affect the lawfulness of processing carried out before the withdrawal.

Grievance Officer & Contact

If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact our Grievance Officer:

Grievance Officer: Shrishant Karadi
Email: noeticaikeyboard@gmail.com

We will respond to all privacy inquiries within the statutory timelines (14 days for DPDPA, 30 days for GDPR, 45 days for CCPA). If you are not satisfied with our response, you may escalate your concern to the Data Protection Board of India (DPBI) or your local Data Protection Authority.