An AI keyboard can see everything you type — and so can every other keyboard on your phone, including the one you are using now. On Android a keyboard is an Input Method Editor, and the system delivers it the contents of whatever field you type in. That is how keyboards work. The question worth asking is not whether it can see your typing, but what leaves your device, when, and what is kept afterwards.
Written by a keyboard vendor. We build FlickReply, so treat the sections about it as a claim rather than a verification. The checks and red flags below are written to apply to FlickReply exactly as they apply to everything else — run them on us too.
What an Android keyboard can actually access
When you enable a new keyboard, Android shows a warning saying it may be able to collect all the text you type, including passwords and card numbers. That warning is accurate and it is not specific to AI keyboards — it appears for every third-party input method, because the operating system cannot inspect what an app does with the text it is handed.
Android does treat some fields differently: a field marked as a password is flagged, and a well-behaved keyboard disables learning and suggestions for it. That is a convention keyboards follow rather than a wall the system enforces, which is why using a password manager with autofill is better practice than typing credentials on any keyboard.
The three questions to ask of any keyboard
Including this one. Each answer below covers keyboards generally first, then FlickReply specifically.
1What can it see?
Every Android keyboard receives the contents of the text field you are typing in. That is not a loophole, it is the definition of an input method — Android hands an enabled IME your keystrokes so it can put characters on screen. Gboard, SwiftKey and FlickReply all have this same access, and so does any keyboard you have ever installed.
FlickReply
FlickReply sees what you type while you are typing it, like any keyboard. It does not read your chat history, your other apps, your contacts or your location, and it requests no permission to do so.
2What leaves the device, and when?
This is the question that actually separates keyboards, and the one most privacy policies answer vaguely. A keyboard can process everything locally, transmit continuously, or transmit only on an explicit action. Those are very different products and the difference is rarely on the marketing page.
FlickReply
Ordinary typing stays on the device. Text is transmitted only when you tap for an AI action, and what goes depends on which: polish sends the message you wrote; a reply suggestion sends the conversation shown on screen, because that is what it is built from. It is not continuous and it is not in the background. The honest trade-off: the AI features need a connection, and the text in a request does leave your phone.
3What is kept afterwards?
Transmission and retention are separate questions. A service can process text without storing it, or store it indefinitely for training. Look for a policy that says which, in those words.
FlickReply
AI processing is temporary and request-based. Message content is not retained for training and typing content is not sold. Account, billing, quota, diagnostic and abuse-prevention records are kept where needed to run the service or comply with law. Clipboard history lives on your device and can be cleared in keyboard settings.
Privacy mode, for when you would rather switch keyboards
Privacy mode turns off AI features and history capture for a session. Nothing typed while it is on is sent for processing or added to clipboard history. It exists for the situations where the honest alternative is switching back to another keyboard — a confidential work thread, a form you would rather not have processed, handing your phone to someone else.
It is available on the free tier and on Premium. The two tiers differ only in AI allowance — 10 requests a day against 500 — never in how text is handled. Full detail is in the privacy policy, and if you want everything removed, the account deletion page explains what goes and what must be retained.
Red flags in any keyboard app
Worth checking before you install anything, this app included.
It requests permissions a keyboard has no use for — contacts, location, camera, call logs.
The privacy policy says your privacy matters but never says where text is processed or what is retained.
There is no identifiable publisher and no support address.
It is free, heavily ad-supported, and does not explain how it makes money.
It cannot be used at all without creating an account and granting access to something unrelated.
Reviews mention ads appearing over other apps, or the keyboard behaving when you are not typing.
If you want AI that never leaves the phone
Then FlickReply is not the right answer, and it would be dishonest to pretend otherwise. FlickReply processes AI requests on a server, which is what lets it work identically on a budget phone and a flagship — but it does mean the text in an AI request leaves your device.
Some keyboards do process on-device — Google’s Gboard runs its AI writing tools locally using Gemini Nano, so text stays on the phone, though that requires a recent flagship chipset. If on-device processing is a hard requirement for you, use one of those instead. Server-side processing is the trade FlickReply makes to run the same way on any Android phone, and it is a real trade rather than a detail.
FAQ
AI keyboard privacy: common questions
Technically yes, and so can every other keyboard on your phone, including the one you use now. On Android a keyboard is an Input Method Editor, and the system delivers it the contents of whatever text field you are typing in — that is the mechanism by which any keyboard works at all. The meaningful question is not whether a keyboard can see your typing but what it does with it: whether it transmits it, when, how much, and what it keeps.
It depends entirely on the keyboard, and Android tells you as much — it shows a warning when you enable any new input method, because the system cannot vouch for what one does with the text it receives. A keyboard from a developer who publishes a clear privacy policy, states where processing happens and does not request unrelated permissions is a reasonable risk. One that is free, ad-heavy, requests contacts or location access, and has no identifiable publisher is not.
No. Ordinary typing is handled on the device and does not leave it. Text is transmitted only when you actively trigger an AI action, and what goes depends on the action: tapping polish sends the message you wrote, while asking for a reply suggestion sends the conversation shown on screen, because that is what the suggestion is built from. Your keystrokes in general are not sent, and nothing is sent in the background. This does mean the AI features need an internet connection and that the text involved does leave your phone. If your requirement is AI writing that never leaves the device at all, FlickReply is not the right tool — some keyboards process locally on recent flagship hardware, and that is worth looking into instead.
AI processing is temporary and request-based, and message content is not retained for training or sold. Account, billing, quota, diagnostic and abuse-prevention records are kept where they are needed to run the service or required by law. Clipboard history is stored on your device for the keyboard tools panel and can be cleared from keyboard settings.
Privacy mode disables the AI features and history capture for a session, so nothing you type while it is on is sent for processing or added to clipboard history. It is intended for the cases where you would otherwise switch keyboards — entering a password into a plain text field, a confidential work thread, someone else borrowing your phone.
Android does not route password fields through third-party keyboards the way it does ordinary text: fields marked as passwords are flagged, and a well-behaved keyboard disables learning and suggestions for them. It is still sensible to use a password manager with autofill rather than typing credentials manually, on any keyboard. FlickReply does not trigger AI actions on their own — an AI request only ever happens when you tap for one.
Three practical checks. Look at the permissions the app requests in Google Play — a keyboard has no legitimate need for contacts, location or your camera. Read whether the privacy policy states where text is processed and what is retained, rather than only that your privacy is important. And check whether the developer is identifiable and reachable; an app with no named publisher and no support address has no accountability.
No. The tiers differ only in AI allowance — 10 requests a day free versus 500 on Premium — not in how text is handled. FlickReply does not show ads on any tier and does not sell typing content on any tier. Privacy mode is available on both.