PRIVACY / iOS

Privacy Notice

Effective date: 9 August 2026

1. Scope and operator

This notice applies to the WhisperInk iPhone app and its keyboard extension. WhisperInk is an independent software project operated by Theodore Wanner in Switzerland. The macOS app has a different processing design, documented under Privacy & data.

2. What leaves the iPhone

When you finish an iOS dictation, the containing WhisperInk app sends the following directly to OpenAI over HTTPS using the API key you entered:

  • The temporary audio recording.
  • Your selected language and formatting preference.
  • Up to 100 saved vocabulary spellings, when present, as transcription context.

OpenAI returns the transcript and charges the OpenAI project that owns your key. WhisperInk has no developer-operated transcription backend, and the operator does not receive your API key, audio, vocabulary, or transcript.

OpenAI states that API data is not used to train its models unless the account explicitly opts in. Its default abuse-monitoring logs may contain customer content and are retained for up to 30 days, subject to the account's data controls and legal exceptions. See OpenAI API data controls for the current terms and available retention controls.

3. Your OpenAI API key

You enter your own OpenAI API key only in the containing app. After OpenAI verifies it, WhisperInk stores it as a generic-password item in the iOS Keychain with WhenUnlockedThisDeviceOnly protection. It is not synchronized, backed up, written to the App Group or user preferences, bundled in the app, logged, or exposed to the keyboard extension.

The key must be present in memory while the app authenticates an OpenAI request. Keychain protection is strong on a normal iPhone, but no mobile app can guarantee a secret on a jailbroken or otherwise compromised device. Use a dedicated OpenAI project key with a low spend limit. Remove it in WhisperInk and revoke it on OpenAI Platform if the iPhone is lost or compromised.

4. Audio and local data

WhisperInk requests Microphone permission. While a voice session is active, iOS displays its microphone privacy indicator. Idle microphone buffers are discarded. During an active dictation, WhisperInk creates a protected 16 kHz mono WAV in the system temporary directory. It deletes the file after the OpenAI request, cancellation, or the next cleanup pass after an interrupted run. A single recording stops after ten minutes.

Completed transcripts, vocabulary, preferences, session state, and recent history are stored locally in an Apple App Group shared only by the WhisperInk app and its keyboard extension. History is limited to 500 entries and vocabulary to 250 terms.

5. Keyboard Full Access

iOS keyboard extensions cannot access the microphone. Full Access lets the microphone-only keyboard exchange bounded commands, status, and completed text with the containing app through their App Group. Although iOS describes Full Access broadly, the WhisperInk keyboard contains no API-key storage, HTTP client, or direct network endpoint. It does not transmit text you type manually or unrelated text-field context.

The keyboard inspects only the immediate text before the cursor on the device to insert spacing correctly and to ensure Undo removes only an unchanged WhisperInk insertion.

6. Analytics, advertising, and tracking

WhisperInk for iOS has no account system, advertising SDK, telemetry SDK, crash-reporting SDK, or content analytics. It does not sell data or use data for tracking. OpenAI processes transcription requests under your own OpenAI account and project policies.

7. Deletion

You can delete history and vocabulary inside the app. Remove API key deletes WhisperInk's Keychain item and returns the app to setup. Revoking the key on OpenAI Platform is the authoritative way to invalidate it and is recommended before or after removing the app.

8. Changes and contact

Material changes will be reflected by an updated effective date. Questions can be sent to theodore@getlumina.org or through our contact page.