Privacy Policy

This policy explains how personal data is handled when you use the InBrackets iOS app, keyboard extension, website, and backend service. It covers both built-in AI processing and “Custom API Configuration”, the app’s Bring Your Own Key (BYOK) feature.

1. Who is responsible for your data

Artem Avanesian, an independent developer in Poland, is the controller of personal data processed to operate InBrackets (“I” or “me”). InBrackets is a product name, not a separate company.

Artem Avanesian
Aleja 3 Maja 51a / 651
30-062 Krakow, Poland
Email: a.p.avanesian@gmail.com

You can use these contact details for privacy questions and requests concerning your data.

2. The main points

3. Keyboard text and AI processing

The keyboard reads text made available by iOS in the active input field to provide its editing features. In button mode, pressing the AI button submits the available text before and after the cursor. In bracket-trigger mode, completing the configured bracket trigger submits the text extracted from those brackets. The selected context instruction is included in the AI request. Text entered into the app’s AI demonstration feature is also submitted when you run it.

Do not assume that only a highlighted word will be sent. The amount of surrounding text available depends on iOS and the app you are typing in. InBrackets does not request access to your complete message history in other apps.

iOS “Allow Full Access” enables the keyboard’s network functionality. It does not itself send text, and it is not a substitute for any separate consent required for AI processing. The confirmation option displays a result after processing; canceling that result does not undo the request already sent to the AI provider.

Built-in AI mode

When custom API usage is disabled, the app sends the prompt and selected instruction to the InBrackets backend over HTTPS with an account authentication token. The backend checks your account and usage allowance, forwards the prompt to the OpenAI API, and returns the generated text. Your request is therefore associated with your account during processing.

The backend sends the prompt to OpenAI using the Developer’s API credentials. It does not add your InBrackets email address or account ID to that AI request. However, text you submit may itself identify you or another person.

The InBrackets application database stores account and usage information, rather than the content of prompts or AI responses. The backend code does not intentionally log prompt or response content. Infrastructure metadata and provider-side retention are separate, as explained below.

Custom API Configuration (BYOK)

When enabled, this mode sends your prompt, selected instruction, selected model, and API token directly from your device to OpenAI, OpenRouter, xAI (Grok), or Mistral over HTTPS. The InBrackets backend receives neither this AI request nor your BYOK token. A failed BYOK request is not automatically resent through the InBrackets backend.

The app also contacts the selected provider directly to retrieve its model list, using your token when supplied. Direct connections expose ordinary connection information, such as your IP address, to that provider. OpenRouter may forward the prompt to the underlying model provider according to its routing settings.

Your provider processes data under the terms and privacy arrangements applicable to your account and selected model. BYOK changes where the request is sent; it does not make AI processing local or anonymous.

4. Other information processed

Data comes from you, your device and requests, and service providers such as Firebase and Apple. InBrackets does not request your contacts, photos, microphone, or precise GPS location for its text keyboard features. Information of that kind may nevertheless appear in text you choose to submit.

5. Purposes and legal bases

Where the GDPR applies, I rely on the following legal bases:

Account information is necessary for account-based features; an AI prompt is necessary to produce an AI result; and a provider token is necessary for authenticated BYOK requests. You can choose not to provide this information, but the corresponding feature will not work.

The Service is not intended to process sensitive personal data such as medical records, biometric identifiers, or information about religious beliefs or sexual life. Do not submit such data or confidential information about others unless you have a valid basis to disclose it. An ordinary request to rewrite text does not by itself establish a legal basis for processing special-category data.

6. Who receives information

Providers act as processors or independent controllers according to the particular service and applicable agreement. For example, a BYOK provider manages your direct provider account, and Apple manages its payment relationship with you. I may also disclose necessary information to authorities where legally required, or to professional advisers where necessary to address a legal or accounting matter.

7. Retention and AI training

I do not use your prompts or results to train an InBrackets AI model. OpenAI states that API data is not used to train its models by default unless the API customer opts in. This describes OpenAI’s published default, not a guarantee covering every BYOK account. OpenAI may retain prompts and responses in abuse-monitoring logs for up to 30 days by default, with longer retention for legal or safety reasons; other storage can depend on the model, feature, and account settings. See its API data controls. No zero-retention guarantee is made here.

Other BYOK providers have their own retention and training practices. Check the chosen provider, model, and routing settings before submitting content.

Infrastructure logs and backups have separate service-specific lifecycles, so deletion from an active database does not mean immediate deletion from every backup or provider system. You may ask for information about the retention applicable to your data.

8. International processing

I am based in Poland, but service providers may process data outside Poland and the European Economic Area, including in the United States. Firebase states that its Authentication service operates from US data centers. BYOK processing locations depend on the provider and routing you select.

Transfers for which I am responsible must use an applicable GDPR transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses with any necessary additional safeguards. You can contact me to request information about the safeguards applicable to a particular transfer and a copy, subject to necessary redactions. Your BYOK provider separately explains transfers for processing under your direct relationship with it.

9. Website storage, advertising, and security

The InBrackets website does not use advertising cookies, tracking pixels, or analytics scripts. It does not build advertising profiles from your visits. Hosting providers still process the technical requests needed to serve pages. The iOS app does not integrate advertising or third-party behavioral analytics SDKs.

Network requests to the InBrackets backend and supported AI endpoints use HTTPS. Account-based backend operations require authentication. Local app data relies on iOS app isolation and device protections. BYOK tokens use iOS Keychain as described above; other settings and InBrackets sign-in tokens remain in shared app settings. No system can guarantee absolute security. Protect your device and revoke a provider token if you suspect it has been exposed.

10. Your choices and deleting your account

You can disable AI, change the trigger mode, edit or remove saved contexts, and change or clear your provider token in “Custom API Configuration”. Disabling BYOK switches future AI requests to built-in mode; to stop AI transmission, disable AI or stop triggering requests. You can also remove the keyboard or turn off its Full Access in iOS settings.

To delete your InBrackets account, use Delete Account in the app’s account section and follow the reauthentication steps. The process deletes your InBrackets user database record and its nested data, then your Firebase Authentication account. The BYOK token and configuration are cleared on that device before server-side deletion starts. Successful completion signs you out and clears saved contexts. If deletion fails, follow the displayed instructions or contact me for help.

Deletion does not cancel your Apple subscription, close a separate AI provider account, revoke your provider’s API key, or remove text already placed in another app. Manage those separately. Apple purchase notifications and separately stored diagnostic or legally required records may remain as explained in Section 7.

11. Your data protection rights

Subject to the conditions of applicable law, you may request access to your personal data, correction, erasure, restriction, and portability. You may object to processing based on legitimate interests and withdraw consent for processing based on consent. Contact me using Section 1; I may need proportionate information to verify your identity. Do not send passwords or API keys.

GDPR requests are normally answered within one month. If an extension of up to two further months is justified, I will explain it within the first month. Requests are ordinarily free. If a request cannot be fulfilled, I will explain why and what remedies are available.

You may complain to your local supervisory authority or Poland’s President of the Personal Data Protection Office (UODO). See UODO’s complaint guidance. You do not have to contact me first.

InBrackets does not use AI to make decisions about you with legal or similarly significant effects. Automated account rules check subscription validity and available usage; contact support to contest an access or billing error.

12. Children and policy updates

InBrackets is not directed to children under 13. The age and guardian-permission requirements in the Terms of Use, applicable law, and your chosen provider’s rules also apply. Where processing relies on a child’s consent, any required parental authorization must be obtained; the age threshold for valid data protection consent may be higher than 13. Contact me if you believe a child has provided data without the required authorization.

I may update this policy when the Service or its data practices change. The date above identifies the version. Material changes will be communicated through the app or another appropriate channel before they apply, and separate consent will be requested where required.