Privacy Policy
Effective [publication date]. OpenAI retention facts checked on September 28, 2026.
BardBoard is an iPhone keyboard and app made by James Hawkins ("we"). This policy explains what leaves your iPhone, where it goes, what is kept and for how long. The short version: your typing stays on your phone; text is sent only when you tap Bardify; our server does not store your messages; there are no accounts, no ads and no tracking.
What the keyboard does on your iPhone
Like any keyboard, BardBoard handles what you type. It also reads the text near your cursor, or your selection, so it can capture what Bardify will rewrite and check that it is safe to replace. This happens on your iPhone. Ordinary typing is never sent anywhere.
After a rewrite, the keyboard keeps the original text and the result in memory so Undo can restore your words. They are discarded when the keyboard closes and are never saved or logged.
Full Access
iOS lets a keyboard use the network only if you turn on Allow Full Access. Bardify needs it because the rewrite happens on our server. Without Full Access, BardBoard still works as a keyboard for typing; only Bardify is turned off.
When you turn it on, iOS warns that a keyboard with Full Access could transmit anything you type. That warning describes what iOS permits, not what BardBoard does. This policy describes what BardBoard does.
When text leaves your iPhone
Only when you tap Bardify (in the keyboard or in the app's playground). What is sent is exactly the captured text shown in the keyboard: your selection, or up to 300 characters before the cursor. It is sent over an encrypted connection (HTTPS) to BardBoard's server, which runs on Cloudflare. Our server sends the text to OpenAI, which writes the rewrite, and returns the result to your iPhone.
Cancel stops a result from being applied, but it cannot recall text that has already been sent.
What our server does with your text
The text and the rewrite exist in our server's memory only for the few seconds of the request. We do not store them, log them, or use them for anything else. We do not send your installation ID or any other identifier to OpenAI with the text.
What OpenAI does with your text
We send requests to OpenAI's API with storage turned off, so they are not saved for later retrieval. OpenAI does not use API data to train its models unless a customer opts in, and we have not. OpenAI does keep a copy of each request and reply for up to 30 days for abuse and safety monitoring, then deletes it, unless a longer period is required by law. We do not have a Zero Data Retention agreement with OpenAI, so this 30 day window applies. We will update this policy if that changes. See OpenAI's enterprise privacy page and privacy policy.
Because a rewrite is made from your words, please don't use Bardify on passwords, financial details, health information or anything you would not want processed by a third party. iOS already uses the system keyboard in password fields.
What our server keeps, and for how long
We keep only what is needed to run the service, enforce limits and honor subscriptions. None of it includes your message text, your name, your email address or your Apple Account.
| Data | Why | How long |
|---|---|---|
| Installation record: a random ID we assign to this copy of the app, plus the Apple App Attest key ID, public key and counter | To confirm requests come from a genuine copy of BardBoard | Until deleted (see "Deleting your data") |
| Access credential stored in your iPhone's Keychain | To authorize requests from the app and keyboard | Expires after 24 hours and is renewed when you open the app |
| Usage counts per installation (how many rewrites today and this month) | To enforce the daily and monthly limits | Daily counts 35 days; monthly counts about 2 months |
| Request records (installation ID, request ID, day, status) | To prevent a request from being charged twice | 7 days |
| Operational log lines: request ID, a pseudonymous installation reference (a keyed hash of the installation ID), the voice chosen, model, prompt version, timings, token counts, cost, outcome and error codes | To keep the service running, find errors and control cost | Up to 7 days, in Cloudflare Workers Logs |
| Hourly request counters keyed by a keyed hash of your IP address (the IP itself is not stored or logged) | To limit abuse | 2 days |
| Subscription record: Apple's original transaction ID, product, expiry date, environment and the time we last checked it, bound to your installation | To turn Pro on, apply the 3 device limit and handle refunds | Deleted 35 days after the subscription expires |
| Monthly list of active subscription IDs (Apple's original transaction ID) | To estimate revenue against our AI costs | About 13 months |
We never store or log message text, IP addresses, request headers, the signed Apple receipt itself, Apple's per-purchase transaction ID, or prices. Pseudonymous identifiers are not anonymous: they can be connected to one installation, so we treat them as personal data.
Who processes data for us
- Cloudflare hosts our server and stores the records and logs above. As our network provider it handles your IP address to deliver requests. Cloudflare's privacy policy.
- OpenAI writes the rewrites, as described above.
- Apple processes your payment, manages your subscription and provides App Attest. We never see your payment details or your Apple Account. Apple's privacy policy.
We share data with these providers only to run BardBoard. They are bound by their terms with us to protect it at least as well as this policy describes. We do not sell or rent data, and we do not share it with advertisers or data brokers.
What we don't do
- No accounts or sign-in.
- No advertising, and no tracking across other companies' apps or websites.
- No analytics, advertising or crash reporting SDKs in the app.
- No history of your rewrites, on your phone or on our server.
Deleting your data
Your message text is never stored by us, so there is nothing of it to delete on our side; OpenAI's copy is deleted automatically within 30 days. Usage counts, request records, logs and subscription records expire on the schedule above. To have your installation record deleted sooner, or to ask what we hold, email support@bardboard.app. Because there are no accounts, we will ask for details that let us find your installation, such as the approximate date you installed BardBoard and the date of any purchase. Deleting the app removes the credential and everything stored on your iPhone.
To stop a subscription, cancel it with Apple (see Support). Cancelling or deleting the app does not by itself delete server records; they expire as described above.
Your rights
Depending on where you live, you may have the right to access, correct, delete or object to the processing of your personal data, and to complain to a data protection authority. We process the data above to provide the service you asked for and, for logs and abuse limits, in our legitimate interest in keeping the service secure and affordable. Our providers process data in the United States and other countries. Contact us at support@bardboard.app to exercise any right.
Children
BardBoard is not directed to children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes, we will update this page and its effective date, and describe significant changes in the app's release notes.
Contact
James Hawkins. Email: support@bardboard.app.