Privacy, in plain words.
Effective September 6, 2026 · Includes Smart Correction Beta in build 3
There is no Idio account, advertising SDK, tracking SDK, cloud keyboard inference, or keyboard data upload. Optional research can still store sensitive information locally. This policy explains that distinction.
Who this policy covers
This policy covers Idio Keyboard, its containing iPhone/iPad app, and getidio.com, operated by Idio's developer. Contact support@getidio.com for privacy questions or requests.
Everyday typing
Idio sends the characters you choose to the app you are typing in through Apple's keyboard APIs. It transiently examines a bounded portion of available cursor context for field-requested capitalization and uses field traits for Return labels. With Smart Correction, research capture and Shadow Mode off, it does not retain ordinary typing or train a language profile. Builds 1–2 are manual-only. Build 3 adds the optional behavior below; no build generates replies, predictions or tone rewrites.
The receiving app controls its own handling of the text. Idio cannot read an entire document or identify the host app through public keyboard APIs. iOS substitutes its own keyboard for secure/password fields, phone-pad fields and apps that disallow third-party keyboards. Idio does not record microphone audio.
Optional Smart Correction Beta
In build 3, Smart Correction is off by default. If you enable it in Settings, Idio processes a short rolling span of its own input (up to 160 UTF-16 units and 12 tokens), transient touch evidence and available cursor anchors on-device. A conservative, policy-authorized minimal edit may repair the last completed word after a space. Host fields that disable autocorrection or request literal/specialized entry are excluded. Opening keyboard research controls pauses correction.
Immediate, verified Backspace reversion stores a negative correction pair and retained word privately in the keyboard, so the same pair resists future correction. Continued typing, silence and uncertain outcomes are not saved as acceptance. This profile does not store sentence history, raw touches, event timestamps or document identifiers, and is not shared with the app. It is bounded to 512 token entries, 256 correction pairs and a 512 KiB file. Existing consented keyboard research statistics can inform ranking read-only.
The app saves only enablement and a reset generation in a protected, backup-excluded shared settings file, bounded to 1 KiB. The keyboard reads it on activation even without Full Access. Reopen after changing settings. Turning correction off stops this processing but does not erase saved negative evidence; use reset to remove it.
Optional research and personalization
In keyboard research controls, key capture and Shadow Mode require separate consent and show recording status. They stop when the keyboard closes, the research panel closes, or character pages change. Please use invented test text.
- Key capture: key identities and displayed case, touch coordinates and phases, key bounds/layout, timestamps, press duration and inter-key intervals. Local analytics derive per-key offsets and statistical motor patterns.
- Shadow Mode: bounded text typed through Idio, proposed reconstructions and explicit edits, component scores, timing, boundary order and a random research session identifier. Available cursor anchors are used transiently for reconciliation, not stored as host-document history. Shadow proposals never change text.
- Language learning: explicit preservation and narrowly verified manual replacements can update local token, correction-pair, phrase and protected-vocabulary counts. Contextual and motor diagnostics can include recent words, inferred speed and possible typing modes—not verified finger identity. Unknown outcomes and silence are not acceptance.
- App research: playground counts are saved only through explicit Save actions. Generating candidates, entering a span and using demos do not save those inputs. Consented calibration trials can retain prompted targets, raw/final text, available touch records and evaluation results. A Local JSON action writes an app-private report, not an upload.
Key labels and overlapping word/phrase counts may reveal or reconstruct text. These records are sensitive, not anonymous. Research exists to improve on-device typing, not to profile users for advertising.
Full Access and local sharing
Full Access is optional. Typing, Smart Correction and keyboard-private capture work with it off. The keyboard owns a private store. With Full Access on, it can write an inspection copy into an App Group container shared with the Idio app on that device. This may include history captured earlier with Full Access off. The app's separate language-playground profile is not merged into that keyboard store.
Apple's permission grants broader capabilities, including potential networking. Idio does not use network or cloud services. Switching Full Access off does not erase a previously shared copy. The keyboard can read available shared clear requests without Full Access, but cannot write a shared acknowledgement while it is off.
Storage and retention
Research, Smart Correction profile and settings files use atomic local writes, iOS complete file protection and backup exclusion. Those protections depend on the platform and do not make a device immune to screenshots, unauthorized access or compromise.
- Telemetry snapshots retain up to 500 key interactions, 24 shadow records and 48 feedback events. Each raw shadow span is bounded to 160 UTF-16 units and 12 tokens.
- Language profiles are bounded to 512 tokens, 256 correction pairs and 512 context entries, with additional capped preservation/protection counts and up to 256 processed feedback receipts. Counts are not an unlimited event history, but may contain personal vocabulary.
- Calibration studies are bounded to 192 trials and 32 MiB. App playground profiles and reports are separate from keyboard captures.
- Temporary session context expires or is discarded when context becomes uncertain or the keyboard closes. Saved diagnostic copies remain under the snapshot retention rules.
Stored research and Smart Correction reversion evidence remain until cleared or displaced by their bounds. There is no general automatic time-based deletion of saved profiles or reports. If storage is unavailable or corrupt, Idio reports the problem rather than treating a failed read as an empty dataset.
Clear or reset your data
In Idio → Settings, Clear all research data attempts to clear app studies/reports, playground counts, app-private telemetry and shared telemetry, and requests private keyboard deletion, including Smart Correction reversion learning. Reset keyboard learning & research has the same broad scope. Reopen the Idio keyboard to complete its private deletion.
Clear playground language profile deletes only the app playground's counts. In the keyboard, … → Clear telemetry clears keyboard-private capture, shadow history, live research learning and Smart Correction reversion learning, and attempts shared clearing. If shared storage is not writable, use the app's clearing control too. A failed clear should be retried; some data may remain. Full Access-off acknowledgement is unavailable. Copies you retrieved outside Idio must be deleted separately.
The app covers its content while inactive, but cannot prevent screenshots. Removing Idio may remove local app data according to iOS behavior; use the explicit controls first if you want to verify clearing.
No sale, advertising or hidden keyboard upload
Idio does not sell typing data, use it for advertising, send it to a language-model provider or operate a server that receives keyboard research stores. Apple may process installation, diagnostics and voluntarily submitted TestFlight feedback under its own policies. Those platform services are separate from Idio's local stores.
This website and support email
This website uses Cloudflare for HTTPS hosting and delivery. Cloudflare necessarily processes request information such as IP address, requested URL, browser information and security signals to deliver and protect the site. We do not add analytics scripts, tracking pixels, advertising, cookies or visitor accounts. Cloudflare's infrastructure processing is not keyboard data processing.
If you email support, your email address, message and any attachments are processed by Cloudflare Email Routing and our email provider to deliver and answer your request. Support correspondence is separate from on-device data and may be retained to resolve the issue and maintain support history. Request deletion by emailing us; we will explain any information that must be retained. Avoid sending passwords, real conversations, raw research files or other unnecessary sensitive data.
Service providers may process website requests or support messages in other countries. See Cloudflare's privacy policy and our email provider's privacy policy.
Your questions and choices
You can decline research, leave Smart Correction and Full Access off, clear local data and stop using the keyboard. We cannot remotely retrieve or delete your device-local typing records. Contact support@getidio.com for help or applicable access/deletion requests concerning support correspondence. Idio has no age-based accounts and does not use research for advertising to children.
Changes to this policy
We will update this page and its effective date if behavior changes. Material changes to collection or sharing will be disclosed before relying on new consent. Future product plans are not descriptions of current collection.