VibeKey Privacy Policy
Last updated: September 2026
VibeKey is a keyboard. It sees everything you type, so the most important thing this policy can tell you is what we deliberately do *not* do with it.
Controller: Unblok ("VibeKey", "we", "us"). Contact: info@unblokapp.com
1. Our commitment
Your typing is not our business model. VibeKey is built so that core typing never leaves your device, and so that anything that does leave your device happens only because you asked for it.
2. What we do NOT collect
- Keystrokes are never collected. We do not record, store, transmit, or sell what you type. Nothing you type is uploaded for typing, autocorrect, suggestions, advertising, or model training.
- No passive keystroke logging, in any mode, at any time.
- Learned words and personal dictionary stay on your device. Corrections and learned vocabulary are stored locally and included only in backups you create yourself.
- Clipboard history stays on your device.
- No analytics or crash SDKs. The app ships without Firebase Analytics and without Crashlytics. We do not track how you use VibeKey. Diagnostic logs are written to the Android system log on your device only and are never uploaded.
- No accounts. There is no VibeKey sign-in, so we hold no email address, phone number, name, or social profile for you.
- No contacts, no photos, no precise location. We do not request or read them.
3. What leaves your device, and when
Data leaves your device only for these actions, and only when you trigger them:
| Action you take | What is sent | Where it goes |
|---|---|---|
| Generate an AI keyboard theme | The prompt text you typed and theme parameters | VibeKey API → Google Gemini |
| Claim or unlock a Drop, card, or theme | Item identifier, your install ID, reward verification data | VibeKey API (Firebase) |
| Browse Drops | A catalog request | vibekey.app / Google Cloud Storage |
| Download a theme, card, font, sound, dictionary, or Assist model | The asset identifier | Google Cloud Storage / GitHub / Hugging Face |
| Viewing an advertisement | See Section 5 | Google AdMob |
| Using the in-app browser | Whatever you enter there, as with any browser | The site you visit |
On-device Assist transforms (fix, rephrase, shorten, and translation when the on-device model is enabled) run entirely on your phone and send nothing.
4. Identifiers we use
- Install ID. A random UUID generated on your device the first time the app needs it, stored locally. It is used for rate limits, entitlements, claim records, and abuse prevention. It is not derived from your device, hardware ID, phone number, SIM, or Google account, is not shared with advertisers, and is regenerated if you clear the app's data or reinstall.
- Google Advertising ID (GAID). Used by the Google Mobile Ads SDK to serve and measure ads. It is resettable and controllable by you in Android Settings → Google → Ads.
- App Check token (Play Integrity). A short-lived token proving a request came from a genuine, unmodified VibeKey install. It protects our API from abuse and contains no personal information about you.
- IP address. Used transiently by our API to deliver responses, rate-limit, prevent abuse, and derive a two-letter country code so we can select the right regional model tier. We retain the country code, not your IP address, in service records.
- Rewarded-ad verification data. A random per-request nonce, the feature being unlocked, your install ID, and Google's transaction ID. Kept briefly to stop replay and fraud. It contains nothing you typed.
5. Advertising
VibeKey is free and ad-supported. There is no subscription and nothing to buy.
5.1 How ads relate to content. The weekly Drop is free while it is live and requires no ad. Other themes, individual Vibe Cards, archived Drops, and extra Assist capacity unlock when you choose to watch a rewarded video. Watching is always optional; typing itself never requires an ad.
5.2 Who serves the ads. Google AdMob, using the Google Mobile Ads SDK. Google acts as an independent controller for the advertising data it processes, under Google's Privacy Policy and how Google uses information from sites or apps that use its services.
5.3 What the ad SDK processes. Your Google Advertising ID; device and app information such as device model, operating system version, app version, language, network type, and screen or ad size; coarse location inferred from your IP address; and ad interaction events such as request, impression, click, video completion, and reward. With your consent, this may be used for personalized advertising, frequency capping, and measurement.
5.4 Your consent choice. In the European Economic Area, the United Kingdom, Switzerland, and other regions where it is required, we present a Google-certified consent form (Google User Messaging Platform) before any ad request, so you can accept or reject personalized advertising and review vendor purposes. Your choice is stored on your device and can be changed at any time in VibeKey → Settings → Ads & privacy. Ads are not requested before consent is resolved where consent is required.
5.5 Declining personalized ads. You still get the same content. Rewarded videos continue to work; they are simply non-personalized, which typically means less relevant ads.
5.6 We do not sell your data. We do not sell or share personal information for cross-context behavioral advertising beyond the advertising consent described above, and we do not receive keystroke or message content back from advertisers.
5.7 Children. VibeKey is not directed at children under 13 and we do not knowingly serve advertising to them.
6. Third-party services
| Service | Purpose | Data involved |
|---|---|---|
| Google AdMob | Rewarded, interstitial, and native advertising | Advertising ID, device and app info, IP-derived coarse location, ad events |
| Google Gemini (via VibeKey API) | AI keyboard theme generation | Your theme prompt text |
| Together AI (via VibeKey API) | Admin/content pipeline only | Not used when you claim Drops in the app |
| Google Firebase (Cloud Functions, Firestore) | Entitlements, claim records, rate limits, reward verification | Install ID, item identifiers, country code, verification data |
| Google Firebase App Check / Play Integrity | Abuse prevention | Integrity token |
| Google Cloud Storage | Delivery of themes, cards, fonts, sounds, dictionaries, models | Asset requests, IP address |
| Google Play | App distribution and updates | Handled by Google |
| Vercel | Hosting for vibekey.app | Standard web request logs |
All AI generation runs through the VibeKey API. VibeKey does not offer a bring-your-own-key mode, so your prompts reach AI providers only via our API, under our provider agreements, and are not used by us to train models.
7. Retention
- Prompts: transmitted for generation and not retained by us as a browsable history; provider retention is governed by our agreements with them.
- Entitlement and claim records: retained while needed to honor your collection and to prevent fraud.
- Reward verification records: retained briefly, for anti-replay only.
- Country codes and rate-limit counters: retained on a rolling short-term basis.
- Everything else — themes, cards, learned words, clipboard, settings — lives on your device and is removed when you clear the app's data or uninstall.
8. Security
Traffic to our API and to AI providers is encrypted in transit with TLS. Theme and card asset files are encrypted at rest in the delivery pipeline. Requests to our API are gated by App Check. No system is perfectly secure, but because we never receive your keystrokes, the most sensitive data a keyboard touches is never exposed to us in the first place.
9. Your rights
Depending on where you live, you may have the right to know what data is processed, to request a copy, to request deletion or correction, to object to or restrict processing, to withdraw consent, and to opt out of personalized advertising. Specifically:
- Personalized advertising: change your choice in VibeKey → Settings → Ads & privacy, or reset or delete your Advertising ID in Android settings.
- Deletion: clearing the app's data or uninstalling removes the local data and rotates your install ID. To have server-side records tied to an install ID deleted, email info@unblokapp.com with that install ID.
- Access and portability: email us; because we hold no account and no keystroke data, the server-side record for an install is small.
- EU/EEA, UK, Switzerland: you may also lodge a complaint with your local supervisory authority.
- California: you have rights to know, delete, correct, and opt out. We do not sell personal information for money, and we honor Global Privacy Control signals on vibekey.app.
Legal bases where the GDPR applies: performing the service you requested (generation, claims, downloads), legitimate interests (security, fraud prevention, rate limiting), and consent (personalized advertising).
10. International transfers
Our infrastructure and providers operate in the United States and other countries. Where required, we rely on Standard Contractual Clauses or equivalent safeguards for transfers out of the EEA, UK, and Switzerland.
11. Children's privacy
VibeKey is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy. The updated version will be posted here with a new "Last updated" date, and material changes will be announced in the app.
13. Contact
info@unblokapp.com