Effective date: January 1, 2026
Protecting your personal data is very important to us. This privacy policy explains how and for what purposes personal data is processed when you use the “Blind Accessibility Keyboard” app (the “app”). The English version of this policy is authoritative; in case of any discrepancy with a translated version, the English version prevails.
The entity responsible for data processing in connection with this app is:
Philip Heyse, Irmgard-Keun-Str. 21, 50997 Cologne, Germany (individual developer). Email: bak@bright-side.de
For any privacy question or to exercise your rights, contact us at bak@bright-side.de.
The app is a keyboard. We have designed it to keep what you type private:
Spoken announcements (text-to-speech). To speak keys, words, and other announcements, the app passes the text to be spoken to the text-to-speech engine installed on your device (for example, the engine provided by Google or your device manufacturer). That engine is a separate service that we do not control, and its provider’s privacy policy applies. Most engines process speech on the device, but depending on the engine and your device settings, some voices may process text in the cloud. You can choose and configure the engine in your device’s settings.
Apart from processing by the text-to-speech engine you have chosen (see above) and by the voice-input provider you choose if you use voice input (see “Voice input” below), the only information that leaves your device is what is necessary to process purchases and subscriptions you choose to make (see “In-app purchases” and “Third parties” below).
The keyboard has an optional microphone key for dictating text instead of typing it. Voice input runs only when you tap the microphone key, and the microphone is used only while you are dictating. In the app’s settings you choose how your speech is turned into text:
You can switch providers, or remove your API keys, at any time in the settings. Where you use cloud voice input (OpenAI or Gemini), the legal basis is your consent (Art. 6(1)(a) GDPR), which you give by selecting the provider and entering a key; you can withdraw it by switching back to on-device or device recognition, or by deleting the key.
Your API keys are stored encrypted on your device (protected by the Android keystore) and are excluded from device backups. They are never transmitted to us.
Voice-input diagnostics. If a dictation fails, the app saves a local technical error report (the time, which provider and model you used, your device and keyboard-layout language, and the technical error message) to help diagnose the problem. This report does not contain your audio or the transcribed text. It stays on your device; you can view, export, or delete it in the settings, and it only leaves your device if you choose to export and share it.
We do not maintain our own servers that store your personal data.
Where the GDPR applies, processing is based on:
Payment processing. During in-app purchases, transaction data (for example, purchase ID, product, and timestamp) is transmitted to the app store’s payment service (Google Payments / Google Play Billing, Google LLC). The app does not transmit complete payment data such as card or bank details; those are collected and processed only by the payment service. Google’s privacy policy applies in addition: https://payments.google.com/payments/terms/privacy
Subscriptions and purchase management — RevenueCat. For in-app purchases and subscriptions we use RevenueCat, Inc., 300 Euclid Ave, San Francisco, CA 94118, USA. RevenueCat processes purchase-related usage data on our behalf to enable in-app payments, subscription management, and receipt validation. This may include an app user identifier, purchase and receipt data, subscription status, a device identifier, and country/locale. Data is processed only for these purposes. See RevenueCat’s Privacy Policy (https://www.revenuecat.com/privacy/) and GDPR notice (https://www.revenuecat.com/gdpr/).
Voice input providers. If you enable cloud voice input, the audio you dictate is sent to OpenAI or Google under your own API key, as described under “Voice input” above. These providers act under your own account with them, not as our processors, and we do not receive your audio or the resulting text.
We do not sell your personal data, and we do not use advertising or analytics SDKs in the app.
The app lets you buy paid content or subscriptions through in-app purchases. Payment is processed exclusively by the app store’s payment service and RevenueCat. We receive only the transaction status (for example, purchase confirmation, time, and product identifier). Processing of this data is for the performance of the contract (unlocking purchased features).
If you contact us (for example, by email), we process the personal data you provide — your email address and the content of your message — solely to handle your request. The legal basis is the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) and our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR). We delete this correspondence when it is no longer needed to handle your request, unless a legal retention obligation requires longer storage.
Some recipients are located outside the European Economic Area (EEA), including the United States:
We do not operate servers of our own. Local app data remains on your device until you delete it or uninstall the app. Support correspondence is deleted when it is no longer needed (see “Contact and support”).
If you make a purchase, RevenueCat stores an app user identifier together with your purchase and subscription data on our behalf. We keep that record until you ask us to delete it (see “Your rights”); otherwise RevenueCat’s own retention periods apply. Purchase and tax records held by the app store’s payment service are retained by that provider under its own policies and statutory retention obligations.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
The app does not use cookies, advertising identifiers, or third-party analytics or tracking SDKs.
The app contains no advertising. We do not collect or use your data for personalized advertising or marketing.
The app requests only the permissions required for its function as a keyboard and for the features you use. The microphone permission is used only for voice input (the microphone key) and only while you are dictating (see “Voice input”). You can review and change permissions in your device settings at any time.
The app is not directed at children. If you are below the age of digital consent in your country (16 in parts of the EEA, 13 in some countries and in the United States under COPPA), please use the app only with the consent of a parent or legal guardian. We do not knowingly collect personal data from children.
Subject to applicable law, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. Where processing is based on consent, you may withdraw it at any time with future effect. We answer requests within 30 days; in complex cases this period may be extended in accordance with the law, with interim notice.
To exercise your rights, contact us at bak@bright-side.de.
Deleting your purchase data. The purchase record that RevenueCat holds on our behalf is the only personal data we control, and we delete it at your request — you do not need to contact RevenueCat yourself. So that we can find the record, please include your app user identifier: in the app, open Options, go to the Data Privacy section and use Copy user ID. Send it to us before you uninstall the app or clear its data: the identifier is stored only on your device and cannot be recovered afterwards. Please note that deleting the record also ends any free access we granted you, and that the purchase and tax records held by the app store’s payment service are not ours to delete — please direct those requests to Google, whose contact details are in its privacy policy.
You have the rights listed above under the GDPR (and UK GDPR). You also have the right to lodge a complaint with a data protection supervisory authority if you believe your data is processed unlawfully.
Do Not Sell or Share My Personal Information. We do not sell or share your personal information for cross-context behavioral advertising. To make a request, email bak@bright-side.de.
You may withdraw consent (subject to legal or contractual restrictions), access your personal information, and challenge our compliance by contacting bak@bright-side.de. In addition to PIPEDA, provincial privacy laws (for example, Quebec’s Law 25) may give you further rights.
We may update this policy to reflect technical or legal changes. The current version is available in the app and in the app store listing. We will communicate significant changes (for example, within the app).
If you have any questions about this privacy policy or about how your data is handled, contact us at bak@bright-side.de.