Privacy Policy
Last updated: September 11, 2026
This policy explains how personal data is handled when you use the InBrackets iOS app, keyboard extension, website, and backend service. It covers both built-in AI processing and “Custom API Configuration”, the app’s Bring Your Own Key (BYOK) feature.
1. Who is responsible for your data
Artem Avanesian, an independent developer in Poland, is the controller of personal data processed to operate InBrackets (“I” or “me”). InBrackets is a product name, not a separate company.
Artem AvanesianAleja 3 Maja 51a / 651
30-062 Krakow, Poland
Email: a.p.avanesian@gmail.com
You can use these contact details for privacy questions and requests concerning your data.
2. The main points
- AI processing sends text off your device when you activate the configured AI trigger. Ordinary typing does not continuously send a stream of keystrokes to the InBrackets server.
- In built-in mode, AI requests pass through the InBrackets backend to OpenAI.
- With custom API usage enabled in “Custom API Configuration”, AI requests and your API token go directly to your chosen provider. They do not pass through the InBrackets backend.
- Account and subscription requests still use the InBrackets backend in either mode.
- The Service does not sell personal data or use your keyboard text for advertising. There is no InBrackets server-side conversation history.
3. Keyboard text and AI processing
The keyboard reads text made available by iOS in the active input field to provide its editing features. In button mode, pressing the AI button submits the available text before and after the cursor. In bracket-trigger mode, completing the configured bracket trigger submits the text extracted from those brackets. The selected context instruction is included in the AI request. Text entered into the app’s AI demonstration feature is also submitted when you run it.
Do not assume that only a highlighted word will be sent. The amount of surrounding text available depends on iOS and the app you are typing in. InBrackets does not request access to your complete message history in other apps.
iOS “Allow Full Access” enables the keyboard’s network functionality. It does not itself send text, and it is not a substitute for any separate consent required for AI processing. The confirmation option displays a result after processing; canceling that result does not undo the request already sent to the AI provider.
Built-in AI mode
When custom API usage is disabled, the app sends the prompt and selected instruction to the InBrackets backend over HTTPS with an account authentication token. The backend checks your account and usage allowance, forwards the prompt to the OpenAI API, and returns the generated text. Your request is therefore associated with your account during processing.
The backend sends the prompt to OpenAI using the Developer’s API credentials. It does not add your InBrackets email address or account ID to that AI request. However, text you submit may itself identify you or another person.
The InBrackets application database stores account and usage information, rather than the content of prompts or AI responses. The backend code does not intentionally log prompt or response content. Infrastructure metadata and provider-side retention are separate, as explained below.
Custom API Configuration (BYOK)
When enabled, this mode sends your prompt, selected instruction, selected model, and API token directly from your device to OpenAI, OpenRouter, xAI (Grok), or Mistral over HTTPS. The InBrackets backend receives neither this AI request nor your BYOK token. A failed BYOK request is not automatically resent through the InBrackets backend.
The app also contacts the selected provider directly to retrieve its model list, using your token when supplied. Direct connections expose ordinary connection information, such as your IP address, to that provider. OpenRouter may forward the prompt to the underlying model provider according to its routing settings.
Your provider processes data under the terms and privacy arrangements applicable to your account and selected model. BYOK changes where the request is sent; it does not make AI processing local or anonymous.
4. Other information processed
- Account data: your email address, Firebase user ID, email verification status, authentication and refresh tokens, account timestamps, and subscription status. Your email and password pass through the account backend to Firebase Authentication for sign-up, sign-in, and reauthentication. The InBrackets user database does not store a copy of your password.
- Purchases and usage: an account-to-purchase identifier, Apple transaction and product identifiers, purchase and expiry dates, renewal or revocation information, and the remaining usage allowance. Apple supplies signed transaction data and subscription notifications. Subscription processing errors may be retained with related account and transaction identifiers to resolve purchase problems. I do not receive your full payment card details from Apple.
- Local settings: saved context instructions, keyboard preferences, selected provider and model, sign-in tokens, and cached subscription type are stored in shared app settings (iOS UserDefaults). Your BYOK API token is stored separately in iOS Keychain, in an access group shared by InBrackets and its keyboard extensions. The Keychain item is accessible only while the device is unlocked, is not synchronized through iCloud Keychain, and does not migrate to another device through a backup restore. A saved context is sent off-device when it is included in an AI request.
- Technical information: hosting, authentication, and backend infrastructure can process IP addresses, request paths, timestamps, response status, user-agent information, and error diagnostics to deliver and secure the Service.
- Support correspondence: your email address, message, and any attachments or diagnostic information you choose to provide. Email providers process this correspondence. Please do not include passwords, API keys, or unnecessary sensitive information.
Data comes from you, your device and requests, and service providers such as Firebase and Apple. InBrackets does not request your contacts, photos, microphone, or precise GPS location for its text keyboard features. Information of that kind may nevertheless appear in text you choose to submit.
5. Purposes and legal bases
Where the GDPR applies, I rely on the following legal bases:
- Providing the service you request — performance of a contract (Article 6(1)(b)): managing your account, authenticating access, processing requested AI edits, storing your chosen settings, administering subscriptions and allowances, and addressing service-related support requests.
- Security and resolving problems — legitimate interests (Article 6(1)(f)): preventing unauthorized access and payment abuse, diagnosing failures, resolving disputed transactions, handling general correspondence, and establishing or defending legal claims. These interests are balanced against your rights.
- Legal obligations (Article 6(1)(c)): responding to legally valid requests and retaining records where tax, accounting, consumer, or data protection law requires it.
- Consent (Article 6(1)(a)), where required: optional processing that requires your permission will be explained separately. You may withdraw consent without affecting the lawfulness of processing before withdrawal. Reading this policy does not constitute consent.
Account information is necessary for account-based features; an AI prompt is necessary to produce an AI result; and a provider token is necessary for authenticated BYOK requests. You can choose not to provide this information, but the corresponding feature will not work.
The Service is not intended to process sensitive personal data such as medical records, biometric identifiers, or information about religious beliefs or sexual life. Do not submit such data or confidential information about others unless you have a valid basis to disclose it. An ordinary request to rewrite text does not by itself establish a legal basis for processing special-category data.
6. Who receives information
- Google / Firebase / Google Cloud: account authentication, database storage, backend execution, and website hosting. See Firebase’s privacy and security information.
- OpenAI: AI processing in built-in mode, and in BYOK mode when selected. See OpenAI’s API data controls.
- Your chosen BYOK provider and, where applicable, its model providers: see OpenRouter’s Privacy Policy, xAI’s Privacy Policy, and Mistral’s Privacy Policy. Provider-specific API terms and account controls also apply.
- Apple: App Store payments, purchase verification, and subscription administration. Apple processes its own account and payment records under Apple’s Privacy Policy.
- Email service providers: delivering and storing support correspondence; where Google mail services are used, see Google’s Privacy Policy.
Providers act as processors or independent controllers according to the particular service and applicable agreement. For example, a BYOK provider manages your direct provider account, and Apple manages its payment relationship with you. I may also disclose necessary information to authorities where legally required, or to professional advisers where necessary to address a legal or accounting matter.
7. Retention and AI training
I do not use your prompts or results to train an InBrackets AI model. OpenAI states that API data is not used to train its models by default unless the API customer opts in. This describes OpenAI’s published default, not a guarantee covering every BYOK account. OpenAI may retain prompts and responses in abuse-monitoring logs for up to 30 days by default, with longer retention for legal or safety reasons; other storage can depend on the model, feature, and account settings. See its API data controls. No zero-retention guarantee is made here.
Other BYOK providers have their own retention and training practices. Check the chosen provider, model, and routing settings before submitting content.
- AI text: the InBrackets backend processes text to return the requested result and does not maintain a prompt or response history in its database. Text inserted into another app remains subject to that app’s storage and privacy practices.
- Account records: retained while your account exists and removed from active account storage through the deletion process below. According to Firebase, deleted authentication data can take up to 180 days to be removed from its live and backup systems.
- Local settings and credentials: retained until replaced or cleared. Signing out clears InBrackets session tokens, but does not clear saved contexts or the BYOK token. Clearing the token or changing providers in Custom API Configuration removes the saved Keychain item. The account deletion process clears the BYOK token before deleting server-side account records; successful completion also clears saved contexts on that device. Uninstalling the app should not be relied on to delete a Keychain item: clear the token first or revoke it with the provider. Device backups and copies on other devices may retain older data under their own settings.
- Purchase errors, support, and technical records: retained for the time needed to investigate an incident, resolve the request or transaction, and meet any applicable recordkeeping or legal-claim requirements. Relevant criteria include whether a case is still open, statutory recordkeeping duties, and applicable limitation periods. Such records are not all removed automatically by the account deletion action; contact me for a review of remaining personal data.
Infrastructure logs and backups have separate service-specific lifecycles, so deletion from an active database does not mean immediate deletion from every backup or provider system. You may ask for information about the retention applicable to your data.
8. International processing
I am based in Poland, but service providers may process data outside Poland and the European Economic Area, including in the United States. Firebase states that its Authentication service operates from US data centers. BYOK processing locations depend on the provider and routing you select.
Transfers for which I am responsible must use an applicable GDPR transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses with any necessary additional safeguards. You can contact me to request information about the safeguards applicable to a particular transfer and a copy, subject to necessary redactions. Your BYOK provider separately explains transfers for processing under your direct relationship with it.
9. Website storage, advertising, and security
The InBrackets website does not use advertising cookies, tracking pixels, or analytics scripts. It does not build advertising profiles from your visits. Hosting providers still process the technical requests needed to serve pages. The iOS app does not integrate advertising or third-party behavioral analytics SDKs.
Network requests to the InBrackets backend and supported AI endpoints use HTTPS. Account-based backend operations require authentication. Local app data relies on iOS app isolation and device protections. BYOK tokens use iOS Keychain as described above; other settings and InBrackets sign-in tokens remain in shared app settings. No system can guarantee absolute security. Protect your device and revoke a provider token if you suspect it has been exposed.
10. Your choices and deleting your account
You can disable AI, change the trigger mode, edit or remove saved contexts, and change or clear your provider token in “Custom API Configuration”. Disabling BYOK switches future AI requests to built-in mode; to stop AI transmission, disable AI or stop triggering requests. You can also remove the keyboard or turn off its Full Access in iOS settings.
To delete your InBrackets account, use Delete Account in the app’s account section and follow the reauthentication steps. The process deletes your InBrackets user database record and its nested data, then your Firebase Authentication account. The BYOK token and configuration are cleared on that device before server-side deletion starts. Successful completion signs you out and clears saved contexts. If deletion fails, follow the displayed instructions or contact me for help.
Deletion does not cancel your Apple subscription, close a separate AI provider account, revoke your provider’s API key, or remove text already placed in another app. Manage those separately. Apple purchase notifications and separately stored diagnostic or legally required records may remain as explained in Section 7.
11. Your data protection rights
Subject to the conditions of applicable law, you may request access to your personal data, correction, erasure, restriction, and portability. You may object to processing based on legitimate interests and withdraw consent for processing based on consent. Contact me using Section 1; I may need proportionate information to verify your identity. Do not send passwords or API keys.
GDPR requests are normally answered within one month. If an extension of up to two further months is justified, I will explain it within the first month. Requests are ordinarily free. If a request cannot be fulfilled, I will explain why and what remedies are available.
You may complain to your local supervisory authority or Poland’s President of the Personal Data Protection Office (UODO). See UODO’s complaint guidance. You do not have to contact me first.
InBrackets does not use AI to make decisions about you with legal or similarly significant effects. Automated account rules check subscription validity and available usage; contact support to contest an access or billing error.
12. Children and policy updates
InBrackets is not directed to children under 13. The age and guardian-permission requirements in the Terms of Use, applicable law, and your chosen provider’s rules also apply. Where processing relies on a child’s consent, any required parental authorization must be obtained; the age threshold for valid data protection consent may be higher than 13. Contact me if you believe a child has provided data without the required authorization.
I may update this policy when the Service or its data practices change. The date above identifies the version. Material changes will be communicated through the app or another appropriate channel before they apply, and separate consent will be requested where required.