Keytrail
Privacy Policy
Keytrail is an iOS keyboard from ELJEE CO, operated by Luke Gregory in Australia. This policy explains what Keytrail processes, what is stored, and the choices available to you. Keytrail does not sell your data, show advertising, or track you across apps or websites.
What Keytrail processes
On your device
Instant spelling fixes, swipe decoding, your learned words, correction preferences, and keyboard settings are processed on your device. This functionality works without Full Access and does not send your typing to us.
Cloud correction
When Full Access is enabled and you use a cloud correction feature, Keytrail may send a short recent text fragment needed to correct what you just typed. Depending on the feature, this may be a completed word, clause, or sentence, together with limited correction context such as candidate words or corrections already made. Keytrail does not send your whole document, screen, or a stream of individual keystrokes.
Cloud correction is available during a limited onboarding demonstration and to signed-in users with an active Keytrail Pro entitlement. The request is sent over Transport Layer Security (TLS) to our Cloudflare-hosted correction service. Our service does not log or store the request text. It forwards the text to one of our model providers solely to generate corrections. Which provider serves a given request depends on how the correction is routed for speed and accuracy, and may change as we improve the service; the providers we use are listed under Service providers below.
Retention differs by provider. Anthropic's standard commercial API retention is up to 30 days, subject to limited exceptions for legal or usage-policy enforcement (see Anthropic's retention information). Cerebras states that it does not retain inputs and outputs associated with its inference services. Fireworks AI states that it does not log or store prompt or generation data for open models, and does not use API inputs to train its models, without explicit opt-in, which we have not given.
Some of the models we use are open-weight models originally published by other research organisations, including DeepSeek. Where we use such a model it is run for us by our provider on that provider's own infrastructure in the United States, under the terms above. Your text is not sent to the organisation that originally published the model.
Passwords and other secure fields are not available to third-party keyboards because iOS switches to the system keyboard for secure text entry. When Keytrail is set to Off, it does not send text for cloud correction.
What is stored
- Account identifier. When you use Sign in with Apple, our service derives a pseudonymous account identifier from Apple's account identifier. We do not receive your Apple password. A name or email address supplied during the sign-in exchange is not retained by our correction service.
- Subscription and purchase status. Apple and RevenueCat process subscription transactions. RevenueCat and our service associate entitlement status with the pseudonymous account identifier.
- Usage counters. Our service keeps pseudonymous request and cost counters to enforce rate and fair-use limits. These counters do not contain request text.
- On-device learning. Learned words, rejected corrections, and settings remain in Keytrail's local app group and may be included in your device backups.
- Optional correction diagnostics. If you enable "Share correction diagnostics", Keytrail uploads correction events such as word-to-fix pairs, accept or reject actions, timing, and build number. It also uploads the keyboard's layout dimensions for the layout in use, meaning the position and size of each key, together with the key height setting and the build tag. These events do not include full sentences or messages. They are stored under a random install identifier, not your account identifier, and expire automatically after 90 days. The setting is off by default. Turning it off deletes queued events that have not yet been uploaded.
- Technical crash reports. After a captured app or keyboard crash, that process can send a technical report to Sentry on its next launch. Reports contain the app build, affected process, operating-system version, device model and program stack frames. Exception messages, memory contents, typed text, account identifiers, screenshots and keyboard events are excluded, and Sentry is configured not to store IP addresses. Up to five pending reports are kept in that process's device cache and retried when networking is available; older pending reports may be removed. Crash reports are used only to diagnose failures and are retained by Sentry for 30 days. This reporting is separate from optional correction diagnostics.
- Feedback you send us. If you use "Send feedback" in the Keytrail app, we store the message you write, the category you pick, your app and build version, and a random install identifier. If you are signed in we also store a keyed hash of your account identifier, so we can connect a report to your subscription if you ask us to; we do not store your account identifier itself alongside the message. If you leave "Include recent correction log" switched on, a short list of recent word-to-fix pairs and timings is attached. It can include words you typed, so switch it off if your message concerns anything sensitive. Feedback is used only to diagnose and improve Keytrail, is never used for advertising, and expires automatically after 90 days.
Cloudflare may process ordinary network metadata, such as IP address and request timing, to deliver and protect the service under its own privacy terms. We do not use that metadata for advertising or cross-app tracking.
Service providers
- Apple provides Sign in with Apple and App Store subscription billing.
- RevenueCat validates purchases and manages subscription entitlements.
- Cloudflare hosts and protects the correction service.
- Sentry processes technical crash reports for error diagnosis.
- Anthropic processes text fragments to generate cloud corrections.
- Cerebras Systems processes text fragments to generate cloud corrections.
- Fireworks AI processes text fragments to generate cloud corrections.
These providers process data under their own contractual and privacy obligations. Keytrail does not permit them to use your data for Keytrail advertising or cross-app tracking.
Your choices and rights
- Use Keytrail without Full Access for on-device typing and instant corrections.
- Set Keytrail to Off or revoke Full Access to stop cloud correction requests.
- Turn optional correction diagnostics off at any time.
- Sign out to remove the local session from your device.
- Delete your account inside Keytrail at Settings > Account > Delete account. After you confirm with Sign in with Apple, Keytrail deletes the account's server-side records and its local account data, revokes the Keytrail session, and disconnects Sign in with Apple. So that any session token issued before the deletion is refused, our service keeps a short-lived, pseudonymous revocation marker, a keyed account identifier with a timestamp, for 31 days; it holds no text and expires automatically.
- Deleting your Keytrail account does not cancel or refund an App Store subscription, which Apple manages separately. The deletion screen links directly to Apple's subscription management.
- Ask us to access or correct account-related records, or for help with deletion, by emailing support@eljee.co. We may need information sufficient to locate the pseudonymous account or install identifier.
Depending on where you live, privacy laws may provide additional access, correction, deletion, or objection rights. Correction requests and service records may be processed in the United States and other locations used by our providers.
Children
Keytrail is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and contact
We may update this policy when Keytrail's data practices or providers change. The latest version will remain available at this URL.
Questions or privacy requests: support@eljee.co