CipherKey
This summary is here to be useful, not to replace what follows. Where the two differ, the full text governs.
CipherKey is an Android keyboard (an input method) developed and published by O’Shane McKenzie (“we”, “us”). It lets you encrypt text locally before you send it through any messaging app, and decrypt text that somebody has sent you.
For the purposes of the UK GDPR and the EU GDPR, we are the data controller only for the very limited processing described in this policy. In practice we do not receive your personal data at all: the app has no backend service.
Contact: litecodzofficial@gmail.com.
A keyboard sees everything you write. That is why CipherKey is built so that almost nothing it handles can leave the phone at all. The following are stored in the app’s private storage on your device, are never transmitted to us, and are never transmitted to anybody else unless you explicitly act to send them:
| What | Where it lives |
|---|---|
| Everything you type | Passed straight to the app you are typing in. Not recorded. |
| Your encryption keys | App-private storage, each key encrypted (“wrapped”) by the Android Keystore, which is hardware-backed on devices that support it. |
| Your personal dictionary — the words the keyboard has learned | App-private storage, encrypted at rest. |
| Clipboard history | App-private storage, encrypted at rest. Passwords and clips an app has flagged as sensitive are refused outright. |
| Saved decrypted conversations | App-private storage, encrypted at rest. |
| Settings, per-app settings, recently used emoji | App-private preferences. No message content. |
| A keyboard background image, if you choose one | Copied into app-private storage and downscaled. We never see it. |
| Your Gemini API key, if you add one | App-private storage, wrapped by the Android Keystore. Never included in an exported settings file. |
Android backup is disabled for this app, so none of the above is copied into Google Drive backups or device-to-device transfers.
Diagnostic logging is disabled in release builds, apart from a small number of fixed error messages that contain no text of yours, no key material, and no clipboard contents.
Nothing. Specifically, we operate no servers and we do not collect, receive, store, or have access to:
There is no analytics SDK and no crash-reporting SDK in the app. If CipherKey crashes, we do not find out unless you tell us.
Two third parties do receive data in the specific circumstances described next. Please read sections 4 and 5 — “we collect nothing” is true of us and is not the whole picture.
CipherKey includes optional AI tools — rewrite, translate, summarise, suggest a reply, and image generation — which are provided by Google’s Gemini API. These are a cloud service, so using them means sending text to Google.
The AI features do nothing until you supply your own Google API key and accept an in-app disclosure that states where your text goes. The key is billed to your own Google account, not ours. We have no visibility into your usage, your bill, or your requests.
Every AI request shows you a confirmation screen containing the exact text that will be sent, in full, before anything leaves the device. Nothing is sent until you tap to confirm. The confirmation screen and the network request read the same data, so what you are shown and what is sent cannot differ.
Before any request leaves the device, an on-device check refuses to send text that appears to contain a shared encryption key, an encrypted CipherKey message, an API key or similar credential, or a key fingerprint. This check is a safeguard against accidents, not a content filter, and it does not attempt to judge whether text is “sensitive” in general. What you confirm is what is sent. Do not send Google anything you would not want Google to have.
Once your text reaches Google, Google’s terms and privacy policy govern it and we cannot protect it, retrieve it, or delete it. Please read the Gemini API terms and Google’s Privacy Policy before enabling these features. Data handling differs between paid and free API tiers; free-tier usage may be used by Google to improve its products.
The app can keep a local record of your AI requests. It is off by default, it is stored only on your device, it is never transmitted anywhere, and you can view and delete it in the app’s Gemini screen at any time.
CipherKey displays banner advertisements supplied by Google AdMob. There are exactly three of them:
There is no advertisement over the keys, none on the suggestion strip, and none in any panel that handles your text — the decrypt preview, the clipboard, the key picker, and the emoji panel carry none. The AI panel cannot open in a password field, so no advertisement can appear while you are typing a password.
Google does collect data through the advertising SDK, and we never see it. This can include your
device’s advertising identifier, IP address, device and operating-system
information, coarse location inferred from IP, and interaction with the advertisements shown, used
to select advertisements, measure their performance, and detect fraud. To support this, the SDK
adds the following permissions to the app: AD_ID,
ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION,
ACCESS_ADSERVICES_TOPICS, ACCESS_NETWORK_STATE, WAKE_LOCK,
and FOREGROUND_SERVICE. None of these is used by CipherKey’s own code.
How Google uses this data is described in How Google uses information from sites or apps that use our services and in AdMob’s own documentation.
| Permission | Why |
|---|---|
INTERNET |
The Gemini features (section 4) and advertising (section 5). Nothing else in the app opens a network connection. |
CAMERA |
Scanning a key from someone else’s QR code. Requested only when you open the scanner. Decline it and you can still paste a key as text. No image from the camera is stored or transmitted. |
USE_BIOMETRIC, USE_FINGERPRINT |
Unlocking your key vault, and confirming it is you before a key is allowed to leave the device. Biometric data is handled entirely by Android; the app never receives it. |
VIBRATE |
Key-press haptics, so the strength can be adjusted. Your phone’s own touch-feedback setting still takes precedence. |
| Advertising permissions | Added by the Google advertising SDK. Listed in section 5. |
CipherKey uses no accessibility service and no notification access. Some keyboards use these to read screen contents; this one does not.
Messages are encrypted with AES-256-GCM. Keys are stored wrapped by the Android Keystore, which on supported devices is backed by dedicated hardware and cannot be extracted. Passphrase-protected key shares use Argon2id. Screens that display key material set Android’s secure-window flag, so they do not appear in screenshots, the recent-apps thumbnail, or a screen recording.
Because keys are bound to the Android Keystore on the device that created them, uninstalling CipherKey destroys your keys permanently, and any message encrypted under them becomes unreadable. The app offers an encrypted key backup protected by a passphrase you choose. Use it before you change or reset a phone.
Because your data is on your device rather than on a server, you exercise most of your rights directly in the app rather than by asking us:
If you are in the UK, the EEA, California, or another region with statutory data rights — including rights of access, correction, deletion, portability, and objection — you may exercise them by writing to litecodzofficial@gmail.com. We will respond within the period the applicable law requires. Please note that we hold no personal data about you, so in most cases our answer will be that there is nothing on our side to produce or erase, and we will say so plainly. Requests concerning data held by Google should be directed to Google.
Where the GDPR applies, our legal basis for the minimal processing involved in operating the app is the performance of our agreement with you (Article 6(1)(b)); for advertising, it is consent where consent is required and legitimate interests otherwise. You have the right to complain to your supervisory authority — in the UK, the Information Commissioner’s Office.
CipherKey is not directed at children and is not intended for use by anyone under 13, or under the age of digital consent in their country where that is higher. We do not knowingly collect personal data from children. Because the app displays advertising and can send text to a third-party AI service, it is not suitable for a child’s device.
We transfer no data anywhere, because we receive none. When you use the Gemini features or view an advertisement, data goes to Google and may be processed in the United States or in any country where Google operates infrastructure. Those transfers are governed by Google’s own safeguards and privacy policy, not by ours.
If this policy changes, the effective date at the top of the page changes with it, and the current version is always the one published at this address. If a change materially reduces the protection described here — for example, if the app were to begin collecting data itself — we will say so prominently in the app before the change takes effect.
O’Shane McKenzie
Developer, CipherKey
Email: litecodzofficial@gmail.com
Please put “Privacy” in the subject line so it is not missed.