EQkey Privacy Policy
EQkey is an AI writing keyboard for iOS and Android, provided by Surgelit LLC ("Surgelit," "we," "us," or "our"). This Privacy Policy explains what information EQkey processes, why we process it, when text leaves your device, and the choices available to you.
1. The short version
EQkey does not upload a stream of your ordinary keystrokes. After the adult-eligibility check succeeds, the keyboard may learn accepted English words and next-word counts on your device to improve local suggestions. It excludes secure fields, keeps that model separate for each credential identity, and does not send the learned words or counts to EQkey's API. Other text leaves your device only when you deliberately use an AI feature or submit information such as account details or support feedback.
- Reply sends the message you chose to copy or paste so the service can suggest a response.
- Charm sends the draft you entered in EQkey so the service can suggest a rewrite.
- Opener sends the scene, persona, relationship and tone choices needed to create an opening line. It does not send text from a conversation unless you deliberately enter text into the request.
AI suggestions are returned as editable drafts. EQkey does not send a message on your behalf.
2. Information we process
AI request content
When you use Reply, Charm or Opener, we process the text and choices needed to complete that request. These may include a copied message, your draft, previous suggestions you asked us to avoid repeating, the selected persona, relationship, opener scene and intimacy level.
Account and profile information
EQkey can be used with a device-based guest session. We create a random device identifier, guest identifier and authentication token to maintain that session, apply usage limits and prevent abuse.
The onboarding asks for gender and date of birth before the personalized keyboard is built. Those answers are held only in memory until the date-of-birth check confirms that the user is 18 or older; no profile choice is uploaded or persisted before that check. Other profile and sign-in fields are optional. Depending on the feature you choose, we may process:
- your name or nickname and email address, plus an optional email address or phone number you enter in a support or safety report;
- gender, birthday, occupation, interests and other profile choices you provide;
- Google, Apple or Firebase account identifiers and authentication tokens. A complete signed Firebase ID token may contain an identity-provider
pictureor profile-photo URL claim; - personas, relationship choices, intimacy level and keyboard preferences associated with your account.
Google and Apple sign-in are optional. Phone and Facebook sign-in are not offered in the current U.S. production build. Information supplied by an available identity provider depends on your provider settings and the permission screen you approve. EQkey does not request access to your photo library and does not separately call a profile-photo API or add a standalone avatar field to the login request. It does, however, send the complete Firebase ID token to Surgelit's API for authentication, and that signed token may contain a provider profile-photo URL claim. We therefore treat that claim conservatively as linked account information collected for App Functionality, not for tracking.
Purchases
The current version is free and does not offer in-app purchases. A future paid version would require a new policy review before it may process transaction and subscription information.
Support and safety reports
If you report AI content or contact support, we process the report or message, any contact information you choose to provide, and the information needed to investigate it. The current iOS feedback client does not add device diagnostics. On Android, a feedback submission may also include the operating-system version and device model to help troubleshoot the issue.
Service and network information
Our systems may process technical information that normally accompanies a network request, such as IP address, request time, app version, platform, response status and security logs. We use this information to deliver the service, protect accounts, prevent abuse and diagnose failures. We do not use an advertising identifier to provide EQkey.
Usage analytics
EQkey counts required AI usage and, if you independently opt in, may send allowlisted events such as app launch, sign-in method, successful AI replies, persona use, and suggestion counts, positions or lengths. Firebase may also generate its own lifecycle, session, engagement, device and technical analytics events while that choice is enabled. Automatic screen-view reporting is disabled. These events do not include your keystrokes, message text or drafts.
- Backend counters (required): AI usage counts are always sent to our API to apply free usage limits and membership benefits.
- Firebase Analytics (optional, off by default): accepting the service agreement does not opt you in. You can independently enable or disable Share usage analytics in Settings at any time and continue using EQkey either way. Turning it off stops future collection. Firebase Analytics is not present in the keyboard extension at all.
On-device keyboard personalization
After the app has confirmed that you are 18 or older, EQkey may update an on-device model from ordinary English words you accept and from adjacent-word counts. This is used only to rank local keyboard suggestions. EQkey does not learn from password or other secure fields, does not include these words in usage analytics, and does not upload the model to our API. The model is isolated by credential identity and is cleared or made inaccessible when the identity changes, the account is deleted, or the eligibility gate is no longer satisfied. Uninstalling the app also removes the model because EQkey excludes it from backup and device transfer.
3. Information EQkey does not access for its service
EQkey does not request direct access to your contacts, photo library, precise location, calendar, microphone, camera or health data. It does not separately select, read or upload a photo or avatar. As explained above, a complete Firebase ID token used for optional sign-in may nevertheless contain the identity provider's profile-photo URL claim, which is sent to Surgelit's API as part of that authentication token.
Operating systems protect secure password fields from third-party keyboards. EQkey does not attempt to bypass those protections.
The current version displays no advertising and does not use cross-app tracking. On Android, EQkey removes the Advertising ID and AdServices permissions and disables Firebase Analytics advertising-ID collection. We do not sell personal information and do not use EQkey information for cross-context behavioral advertising.
4. Why iOS asks for Full Access
Apple prevents a third-party keyboard from using the network unless the user enables Allow Full Access. EQkey needs network access for the AI features and for session and account functions used by the keyboard.
Without Full Access, EQkey continues to provide ordinary keyboard input and local keyboard functions. Network-based AI features are unavailable. Clipboard content is accessed only as part of a Reply action you start — when you open the Reply panel or tap paste — and it leaves your device only if you go on to submit that request.
You can turn Full Access off at any time in iOS Settings > General > Keyboard > Keyboards > EQkey.
5. How we use information
We use information to:
- generate the reply, rewrite or opener you requested;
- personalize suggestions using the persona, relationship and intimacy settings you selected;
- authenticate users and maintain guest or signed-in sessions;
- enforce free usage limits;
- operate, secure and troubleshoot the service;
- review reports, respond to support requests and improve safety;
- comply with law and enforce our Terms of Use.
Where applicable, our legal bases include performance of a contract, your consent, compliance with legal obligations, and our legitimate interests in operating and securing EQkey. You may withdraw consent where consent is the basis, without affecting earlier processing.
6. Service providers and disclosures
We use service providers to operate EQkey. Depending on the feature you use, these may include:
- AI processing providers, which process the content and settings submitted for an AI request on our behalf and only to generate the requested output. We do not authorize these providers to use your content to train their own models or for advertising;
- cloud hosting and infrastructure providers, which host our API and databases in the United States;
- Google, Firebase and Apple, which provide optional authentication and platform services; Firebase Analytics receives usage events only while the independent Settings choice is enabled;
- Apple App Store and Google Play, which distribute the current free app; a future paid version would require updated purchase disclosures.
These providers process information to perform services for us or as otherwise disclosed to you by their own permission and privacy notices. We do not authorize providers to use EQkey data for targeted advertising.
We may also disclose information when required by law, to protect users or the public, to investigate fraud or abuse, or as part of a merger, financing, acquisition or sale of assets subject to appropriate safeguards and notice where required.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
7. Data retention
We keep personal information only as long as needed for the purposes described in this policy, and we apply the following retention periods:
- AI request content is processed to generate your response. Request and response text may appear in service logs used for security, abuse prevention and troubleshooting; those logs are retained for no more than 30 days and then deleted. We do not use AI request content to build advertising profiles.
- API and security logs, which may include IP address, request metadata and response status, are retained for no more than 90 days, unless a specific security investigation or legal obligation requires a longer period.
- Account and profile information is kept while your account or guest session is active, and is then deleted or anonymized in accordance with applicable law, except for limited records we must keep to comply with law, resolve disputes or enforce our agreements.
- Support and safety reports are retained as needed to resolve the issue and as permitted or required by applicable law.
- Purchase records: not applicable to the current version, which offers no in-app purchases.
We do not keep full payment card details.
8. Security and international processing
EQkey uses HTTPS/TLS to protect information in transit. We also use access controls and operational safeguards designed to protect information against unauthorized access, alteration or disclosure. No system can guarantee absolute security.
Surgelit is based in the United States. Our service providers and infrastructure process information in the United States, which may have different data protection laws from your country. Where required, we use appropriate transfer safeguards.
9. Your choices, account deletion and privacy rights
Stop AI text processing
Do not tap an AI action. You can continue using the keyboard for ordinary typing. On iOS, you can also disable Full Access. On either platform, you can remove EQkey as an enabled keyboard or uninstall the app.
Delete a signed-in account
Open EQkey and go to Settings > Account > Delete account. The entry stays available even if profile loading fails. After confirmation, we delete or anonymize your account and associated data in accordance with applicable law, except for limited records we must keep to comply with law. Deletion cannot be undone.
The current version has no in-app purchase. If a future version offers a store subscription, deleting an EQkey account will not automatically cancel it; it must also be canceled in the applicable store account settings.
Delete guest data or request deletion without the app
You can request deletion without reinstalling the app by emailing [email protected]. If the request concerns a signed-in account, include the account email. For guest-data requests, we may ask for information reasonably necessary to locate and verify the session. We will process verified deletion requests in accordance with applicable law.
Other rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, or appeal a decision about your request. You may also have the right to complain to a data protection authority.
Send requests to [email protected]. We may need to verify your identity before completing a request. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
California residents may request information about categories of personal information collected, sources, purposes and disclosures. EQkey does not sell personal information or share it for cross-context behavioral advertising.
10. Children
EQkey is intended only for people aged 18 or older. We do not knowingly collect personal information from children. If you believe a person under 18 has provided information to EQkey, contact [email protected] so we can investigate and delete it where appropriate.
11. AI-generated content
AI suggestions may be inaccurate, inappropriate, biased or unsuitable for a conversation. Review and edit every suggestion before sending it. You are responsible for the message you choose to send.
You can report inappropriate AI content inside EQkey at Settings > Support > Report keyboard content. Reports help us investigate safety issues and improve safety controls.
12. Changes to this policy
We may update this policy when EQkey, our providers or legal requirements change. We will change the Last updated date and provide additional notice in the app when required.
13. Contact us
Surgelit LLC
30 N Gould St, Ste R
Sheridan, WY 82801
United States
Email: [email protected]
Support: https://eqkey.surgelit.com/contact/