Privacy
syntax keyboard · Last updated 2026-09-04
This page describes what the syntax iOS keyboard does with your information. It matches what the code actually does. If a future change ever makes this page wrong, the change is the bug — not this page.
What syntax never does
syntax never records, transmits, buffers, or analyzes anything you type. Turning on Full Access does not change this. There is no analytics, no tracking, no advertising, and no crash-reporting SDK in this app.
What leaves your device, and when
A request leaves your device only when you do one of three things:
- Sign in. Your email address is sent to Supabase, our sign-in provider, which emails you a one-time code.
- Generate an image. When you confirm an
@image"..."prompt, that prompt is sent to api.yoursyntax.app so the image you asked for can be made. - Open the image menu. The list of available models is fetched from api.yoursyntax.app and cached for five minutes, so this does not happen as you type.
There is no background sync, no polling, and no other network activity.
Who receives it
- Supabase receives your email address to send your sign-in code and keep you signed in.
- Our gateway (api.yoursyntax.app, running on Google Cloud Run and served through Firebase Hosting) receives your generation prompts — with your account token if you are signed in, and without any account identifier if you are not.
- fal.ai receives your prompt, through the gateway, to run the image model that makes your image.
Supabase and fal.ai handle this data under their own privacy policies, which protect it at least as well as this page promises. Cloudflare manages the DNS and email routing for yoursyntax.app but does not receive your app data.
This website itself loads no analytics and no trackers.
What stays on your device
- Keystrokes — never collected, never sent anywhere.
- Contacts —
@contactreads your contacts on-device to find the person you mean and inserts their card into your text. Contacts are never transmitted or stored by us. - Clipboard history — stored only in this device's local App Group storage. Never uploaded, never synced. You can delete any entry, or clear all of it, in the syntax app. Text that looks like a secret — an API key, token, or private key — is filtered out before it is ever saved.
- Your session — if you sign in, your sign-in session is stored in the App Group on this device.
How long it stays
- Clipboard history stays on your device until you delete it.
- Your sign-in session stays on your device until you sign out or delete your account.
- Supabase keeps your account record (your email address) until you delete your account.
- Our gateway does not keep a copy of your prompt after your image is made; it keeps ordinary request logs (time, status, network address) and a per-generation cost line. fal.ai handles prompts and generated images under its own privacy policy.
Your rights
Depending on where you live (including under GDPR, UK GDPR, and CCPA/CPRA), you may have the right to access, correct, delete, or export the personal data we hold, and to object to or restrict how it is used. The only personal data we hold is your email address and account id if you signed in. To exercise any of these rights, email support@yoursyntax.app. We will respond within 30 days.
Children
syntax is not directed at children under 13, and we do not knowingly collect personal information from children under 13. The app requires no personal information to function.
Full Access, in plain words
iOS asks you to grant "Full Access" before any third-party keyboard can use the network. syntax needs it for exactly three things: sending your @image prompt when you confirm it, reading and writing the system pasteboard for the clipboard features, and looking up contacts for @contact. Core typing, letter alternates, and read-aloud all work with Full Access off. Nothing you type is ever sent, with Full Access on or off.
The App Group
The keyboard extension and the syntax app share a small, private storage area on your device called an App Group. It holds your clipboard history and your sign-in session. It is stored on this device, and its contents are never sent to any server.
The privacy manifest, in plain words
Apple requires apps to file a privacy manifest — a machine-readable list of the data an app handles. Ours declares exactly three things: your email address and your account id (when you sign in) and your generation prompts (when you generate an image). All three are used only to make the app work, none is used to track you, and tracking is switched off entirely. Contacts and pasteboard contents are not in the manifest because Apple only counts data that leaves the device — and yours never does.
For the technically curious
The manifest (PrivacyInfo.xcprivacy) declares NSPrivacyCollectedDataTypeEmailAddress, NSPrivacyCollectedDataTypeUserID and NSPrivacyCollectedDataTypeOtherUserContent, each linked to the user, NSPrivacyCollectedDataTypeTracking false, purpose AppFunctionality. NSPrivacyTracking is false and NSPrivacyTrackingDomains is empty. The only accessed-API entry is UserDefaults (CA92.1). Apple does not require an NSPrivacyAccessedAPITypes entry for CNContactStore or UIPasteboard, so none is declared.
Deleting your account
Open the syntax app, then Settings, then Delete account (visible when you are signed in), and confirm. The app asks the gateway to delete your account, then signs you out and clears the account data in the App Group. If the deletion route is not yet live on the gateway, the app tells you so plainly and never pretends it succeeded — in that case, email support@yoursyntax.app and we will delete it for you. You can also email that address at any time to request deletion. Deleting your account removes it from our records; we will confirm by email when it is done.
Changes to this page
If we ever change how syntax handles data, we will update this page and the date at the top in the same release, and we will update the App Store privacy details to match.
Contact
Questions about privacy: support@yoursyntax.app