PrivacyJuly 1, 20263 min read

Privacy and AI Keyboards: What to Ask Before Installing One

A keyboard sees everything you type. That is not sinister, it is how input methods work. But it does mean six questions are worth asking before you enable one.

Article cover: What to Ask Before Installing an AI Keyboard

Enabling a keyboard is one of the higher-trust things you can do on a phone. Android tells you as much, with a warning dialog that most people click past.

The warning is not wrong. A keyboard is an input method: the system routes every text field through it. That is not a loophole, it is the entire mechanism, and it applies to the default keyboard that shipped with your phone too.

But "it sees your typing" and "it sends your typing somewhere" are very different claims, and the gap between them is where you should be paying attention. Six questions.

1. When does text leave the device?

This is the question. Everything else is detail.

A good answer is specific and conditional: text leaves when you trigger an AI action, and what leaves is the text you are working on. A bad answer is a vague gesture at "improving our services."

The distinction you want confirmed is between ordinary typing - which should stay local, because it needs to - and AI actions, which are a deliberate thing you do.

2. What exactly gets sent?

"The selected text" and "the conversation" and "the contents of the field" are three different scopes.

None of them is automatically wrong. A reply assistant genuinely cannot draft a contextual reply without context. But you should be able to find out which one applies, and it should be proportionate to the feature.

3. Is it retained after the request?

Processing text and storing text are separate decisions.

The good version: the request is served and the content is not kept. The version that requires more thought: content is retained for a period, for abuse prevention or quality work. That can be legitimate - but it should be stated, with a duration.

4. Is there a private mode?

Sometimes you are typing something you do not want the keyboard to remember at all. A recovery phrase. A medical detail. Somebody's address.

A private or incognito mode - one that stops the keyboard keeping history for that session - is table stakes. Check that it exists and that you know how to reach it quickly, because you will want it in a hurry rather than after a settings hunt.

5. What permissions does it ask for, and do they make sense?

Permission requests should map to features you can actually see.

Clipboard access for clipboard history is coherent. A microphone permission on a keyboard with no dictation feature is not. If a permission does not correspond to something the app visibly does, that is worth a pause.

6. Does it degrade gracefully?

If the AI is unavailable - no network, service down, allowance used up - can you still type?

The answer should be an obvious yes. An AI keyboard should be a keyboard first. If the intelligence layer failing takes your ability to type with it, the architecture is wrong.

What good looks like

You are not looking for a product that promises to see nothing. That product cannot exist, because seeing your typing is definitionally what a keyboard does.

You are looking for one that is precise about the boundary: what stays on the device, what leaves and when, what is kept and for how long, and what you can switch off.

Precision is the signal. Vagueness in a privacy policy is rarely accidental - it is usually load-bearing.

  • #privacy
  • #security
  • #AI keyboard