Privacy Policy
AppKeys - Per-App Keyboards
In short: AppKeys has no account or login, and your per-app keyboard settings and rules are stored on your device. AppKeys is not a keyboard (input method), and it does not read, store, or send anything you type in other apps or any key presses. The app shows ads through Google AdMob (no ads are shown while Remove Ads is active; see section 4 for when it becomes active) and sends usage events and crash reports to Google through Firebase Analytics and Firebase Crashlytics. The names and package names of the apps you set a keyboard for, and which keyboards you chose, are not included in usage events. Instead, usage events include the app type assigned by Android (for example, game, video, or social), and every time the Accessibility Service detects that an app has come to the foreground and switches the keyboard, this information is sent to Firebase Analytics.
1. Information We Collect and Process
The information AppKeys handles is as follows.
- Keyboard settings and rules — stored on your device: The app stores the following in a database on your device. The "chosen keyboard" below is stored as the identifier Android gives each keyboard (a string made of the keyboard app's package name and component name).
- Per-app keyboard settings: for each app you set a keyboard for, its package name and app name, whether the setting is on, the chosen keyboard, the time a per-app pause ends, and the times the setting was created and last changed
- Time rules: for rules you create for an app or a category, their time range (start and end time), chosen keyboard, whether the rule is on, the rule order, and the times it was created and last changed
- Category rules: for each app type (games, video, social, and so on), whether the rule is on, the chosen keyboard, and the time it was last changed
- My categories: the name you entered, whether it is on, the chosen keyboard, the package names of its apps, and the times it was created and last changed
- Apps excluded from categories: the package name of each app you took out of category handling, the time you did so, and the time the exclusion ends (including no end time)
- App settings and operating records — stored on your device: The time a global pause ends; your theme and language; whether on-screen notices are shown and their position; whether you finished the first-run guide (onboarding); whether Remove Ads is active (true/false); whether Remove Ads has ever been active on this device (true/false); records for the welcome offer (the time you first opened the app on this device, and whether you dismissed the welcome offer card on the home screen); records used to decide when to ask for a review (the number of times the keyboard was switched, counted only up to 10; the time you first opened the home screen; the time a review was last requested); records used to decide when to send a service-off notification (whether the service has ever connected, the time it last connected, the time a notification was last sent, and whether notification permission has been requested); and whether each one-time usage event has already been sent. These are stored in the app's storage on your device.
- Return-keyboard record — stored on your device: Switching the keyboard really changes the device's default keyboard setting, so just before switching, the app saves a single record in the app's storage on your device to use when switching back: the identifier of the default keyboard before you entered the app, the identifier of the keyboard it switches to, that app's package name, and the time it was saved (and, when it overwrites an earlier record, the identifier of the keyboard in place at that moment). There is only one such record, and it is deleted once the keyboard has been switched back and handling of that app ends. If the Accessibility Service stopped without switching back, the record is read and handled the next time the service connects, and a record older than 24 hours is deleted without being used. This record is not sent, is not included in the backup files you create, and is excluded from Android Auto Backup.
- Installed app information — read on your device: So you can choose which apps to set a keyboard for, the app loads the package name, name, and icon of the apps shown on your home screen (launcher) from your device and displays them. For category rules and for the app type value in usage events, the app also reads the app type Android assigns to each app (
ApplicationInfo.category) on your device. The loaded list is not stored or sent, and the app type is sent only as the app_category value of the usage events below; only apps you turn on or whose settings you change, apps you put in one of My categories, apps you exclude from a category, and apps imported from a backup file are saved to the keyboard settings and rules above.
- Keyboard information — read on your device: To show the keyboards you can choose from and to decide whether a keyboard can be switched to, the app reads from Android the list of keyboards turned on on your device (identifier, name, the keyboard app's package name, and whether it is a keyboard for typing text), the current default keyboard, and the names of the keyboards you saved, and it shows the keyboard apps' icons on screen. This information is used only on your device, for display (selection lists, settings screens, and on-screen notices) and for deciding whether to switch, and it is not sent. Only the identifiers of the keyboards you choose (when you create a new setting, the default keyboard at that moment is filled in as the starting value) are saved, to the keyboard settings and rules above and to the return-keyboard record below. The identifiers of the keyboards you choose are kept only in the app's storage on your device and in backup files you create yourself (see below), and the app does not send them anywhere (if Google backup is turned on for your device, data in the app's storage may be included in Android Auto Backup; see section 6).
- Usage events — sent to Firebase Analytics: The app sends the following events to Firebase Analytics. App names and package names, and keyboard identifiers, names, and package names, are not included in any event. The "app type" below (
app_category) is the value assigned by Android (one of game, audio, video, image, social, news, maps, productivity, accessibility, undefined, other, or unknown).
screen_view: when you open a screen — the screen name (home, app list, keyboard editor, rule editor, settings, theme/language selection, category rules, category settings, category app list, My categories editor, Remove Ads, onboarding)
onboarding_page_view, onboarding_skipped, onboarding_completed: when you view a page of the first-run guide, when you end it with "Later", and when you finish it (including with "Later") — the page number and whether the Accessibility Service is on
a11y_disclosure_shown, a11y_disclosure_result: when the accessibility disclosure dialog is shown and when you agree or decline — where it was opened (home, settings, onboarding) and your response
enable_service_clicked: when you agree to the accessibility disclosure on the home screen or in onboarding and go to the accessibility settings (no additional values)
a11y_settings_abandoned: when you agreed to the disclosure and went to the settings but came back within 5 minutes without turning the service on (no additional values)
a11y_enabled: once, when the Accessibility Service connects for the first time (no additional values)
service_connected: when the Accessibility Service connects — the number of apps whose keyboard setting is on
a11y_lost: when the Accessibility Service is unbound or destroyed, or when a service-off notification is sent — the reason (unbound, destroyed, detected off)
managed_app_added (and first_app_added the first time): when you turn on an app in the app list or first save a new app's setting on the keyboard editor screen — that app's app type and where it happened
managed_app_removed: when you turn off an app in the app list or delete an app on the home screen — that app's app type and where it happened
keyboard_changed: when a keyboard you changed on the keyboard editor screen is saved — that app's app type. Which keyboard it is is not sent
schedule_set: when you save a new time rule on the rule editor screen — what the rule belongs to (an app, an app-type category, or one of My categories). The times and the keyboard are not sent
category_rule_changed: when you turn a category rule on or off or save a new value — the app type and whether it is on. Which keyboard it is is not sent
custom_category_saved: when you create or edit and save one of My categories (a group of apps you pick yourself), or turn it on or off or save a new keyboard for it — the number of apps in it and whether it is on. The category name, the names and package names of its apps, and which keyboard it is are not sent
custom_category_deleted: when you delete one of My categories (no additional values)
category_app_excluded, category_app_included: when you uncheck or re-check an app on the category app list screen and it is saved — the category kind (app-type category or My categories). Which app and which category are not sent
keyboard_applied (and first_keyboard_applied the first time): when the Accessibility Service actually switches the default keyboard to that app's keyboard (for example, when it detects a foreground app switch, when a pause ends, when the service connects, or when the screen turns on or you unlock the device) — that app's app type, where the value came from (per-app setting, category rule, or My categories), and how the foreground app was detected (detect: an accessibility event, a11y, or Usage access, usage). Which keyboard it is is not sent, and the event is not sent if that keyboard was already the default keyboard when you entered the app
keyboard_released: when you leave an app you set a keyboard for and its handling ends — what triggered it (leaving to the home screen or another screen where the keyboard is not switched, switching to another app, a pause, a global pause, the screen turning off, the service stopping, or a record left by an earlier run being handled when the service connects) and the result (switched back to your previous keyboard, kept the keyboard you changed to, nothing to switch back, or could not switch back). Which app and which keyboard are not sent
keyboard_switch_failed: when the keyboard could not be switched to that app's keyboard — the reason (the chosen keyboard is turned off or removed, the system did not accept the switch, the current default keyboard could not be read, or the return-keyboard record could not be saved). Which app and which keyboard are not sent
pause_set, pause_resumed: when you pause or resume per-app keyboard switching — the scope (global or app), where it happened (home, on-screen notice, Quick Settings tile), and the pause length in minutes (-1 for indefinite)
overlay_action: when, on an on-screen notice, you tap the pause button, choose or cancel an item in the pause length list, open the menu, or in the menu change the keyboard or choose to open settings, stop managing this app, or exclude it from its category — the action type. Which app it is and the values you changed are not sent
ad_shown: when an app open ad is shown — the ad format and what triggered it
paywall_shown: when you open the Remove Ads screen — a value for where it was opened (recorded as settings wherever you open it from)
purchase_initiated, purchase_completed, purchase_failed, purchase_restored: when you start, complete, or fail a Remove Ads purchase, or try to restore purchases — the product ID (remove_ads_lifetime, or remove_ads_lifetime_welcome for the welcome offer product) and a failure reason code or whether the restore succeeded. Order numbers, amounts, payment methods, and purchase tokens are not sent.
backup_exported, backup_imported: when you export settings to a file or import and merge them from a file — the number of per-app settings exported or imported. The number of rules and file names, locations, and contents are not sent.
review_prompted: when the app requests the Google Play review dialog (no additional values)
- User properties: the number of apps whose keyboard setting is on (
managed_app_count), whether the Accessibility Service has been turned on (a11y_enabled), whether a Remove Ads purchase was completed on this device (premium, recorded only when a purchase completes), and whether the optional Usage access permission is on (usage_access, true/false)
For the information Firebase Analytics collects automatically alongside these events, see section 4.
- Crash reports — sent to Firebase Crashlytics: When the app crashes, error details, device diagnostic information, and a commit hash identifying the app build (
git_hash) are sent. See section 4.
- Advertising data — collected by Google AdMob: To serve ads, the AdMob SDK may collect and use device identifiers such as the advertising ID, your IP address, and ad interaction data. In regions that require consent, such as the European Economic Area (EEA) and the UK, Google's User Messaging Platform (UMP) asks for your consent and stores your choice on your device. See section 4.
- Purchase information — handled by Google Play: Remove Ads purchases are handled by the Google Play billing system. The app does not receive or store payment methods such as card numbers, or billing addresses. The product prices it receives from Google Play are used only to show them on screen and to calculate the welcome offer discount and decide whether to show the offer; they are not stored or sent. The only values about purchases stored on your device are whether Remove Ads is active (true/false) and whether it has ever been active on this device (true/false). See section 4.
- Backup files — saved where you choose: When you export from the settings screen, the app creates a backup file (JSON) in a location you pick yourself with the system file picker. The file contains an app identifier (
appkeys), the file format version, the export time, per-app settings (package name, app name, whether the setting is on, and the chosen keyboard's identifier), per-app time rules (package name, time range start and end time, keyboard identifier, whether the rule is on, and rule order), category rules (app type, whether the rule is on, and keyboard identifier), My categories (the name you entered, whether it is on, keyboard identifier, and the package names of its apps), the package names of apps you excluded from categories with no end time, and category time rules (the app type or My category name they belong to, time range start and end time, keyboard identifier, whether the rule is on, and rule order). It does not contain pause states (global and per-app pauses, and apps taken out of category handling for a set time), the times settings were created or changed, app settings and operating records such as theme and language, the return-keyboard record, or account or device identifiers. The app does not send this file anywhere, and when you import, it reads only the file you pick, once. Whether the keyboards in the imported items are turned on on this device is checked only on your device.
- Information the app does not ask for: The app does not ask you to enter a name, email address, or phone number, and does not request permissions to access your contacts, photos, storage, precise location, camera, microphone, or Bluetooth devices.
2. Accessibility Service
AppKeys uses the Android Accessibility Service for its core feature: switching to the keyboard you set for an app when that app comes to the foreground, and switching back to your previous keyboard when you leave it. AppKeys is not a keyboard (input method) and contains no input method service. It only changes which of the keyboards already turned on on your device is the default keyboard.
- Events it receives: The service subscribes to one event type only: window state change events (
TYPE_WINDOW_STATE_CHANGED). It does not subscribe to text change events or key events. Separately from accessibility events, while the service is connected it also receives Android's screen-off, screen-on, device-unlocked, and device-shutdown broadcasts.
- What it reads: It reads the package name and window class name from each event, whether that window is full screen, and the package name of the currently active window, to determine which app is in the foreground. The service configuration declares window content retrieval (
canRetrieveWindowContent), but the only value the app's code reads from the active window is the package name. It does not read text shown on the screen or anything you type with a keyboard, and it does not store or send them. It does not receive or intercept key presses (it does not declare key event filtering, and there is no code that handles key events).
- Protected screens and the optional Usage access permission: For some app screens (for example, the compose screen of some mail apps), Android delivers neither events nor the active window to the Accessibility Service, so the service alone cannot tell that the app has come to the foreground. Only if you turn on the optional Usage access permission yourself, the service reads the package name of the one app that most recently came to the foreground from Android's usage records, at the moment it could not read the active window, and uses it to determine the foreground app (see section 3). If you do not turn this permission on, usage records are not read, and the keyboard is not switched when you go straight to such a screen.
- What it does: When an app you set a keyboard for and turned on (or an app with no per-app setting that falls under a category rule you turned on) comes to the foreground, the service uses the keyboard switching function Android provides to accessibility services (
SoftKeyboardController.switchToInputMethod) to change the device's default keyboard to the keyboard you set for that app. This really changes the default keyboard value in Android's system settings, and it stays that way while you use the app. When you leave that app, the service switches back to the keyboard you were using before you entered. So that it can switch back, it saves a return-keyboard record on your device before switching (see section 1). If you change to another keyboard yourself while using the app, your choice is kept and is not switched back. It can only switch to keyboards that are turned on on your device, so if the keyboard you set is turned off or removed, nothing is switched. If that keyboard is already the default keyboard when you enter the app, nothing is changed. If time rules exist, it uses the value of the rule that matches the device time when you enter the app. When the screen turns off or the device shuts down, it switches back to your previous keyboard; while the screen is off or the lock screen is showing, it does not switch the keyboard; and when you unlock the device it checks the foreground app again and applies its keyboard. If the Accessibility Service is turned off or stopped and cannot switch back, the switched keyboard may remain the default keyboard; in that case the saved record is handled the next time the service connects (a record older than 24 hours is not used, and nothing is switched back if the default keyboard has changed in the meantime).
- On-screen notices: When it switches the keyboard, it briefly shows a notice on the screen. This notice is not an Android notification but a window the Accessibility Service draws over the screen (an accessibility overlay), and the window does not receive key input. The notice shows the app name and the name of the keyboard it switched to, and it has a pause button and a menu button, whether the keyboard was applied by a per-app setting, a category rule, or one of My categories. Tapping the pause button shows a list of pause lengths, and for the length you choose (including no end time) the keyboard is not switched for that app only (for an app handled by a category, only that app is taken out of category handling for that time). The menu has change keyboard (chosen from the list of keyboards turned on on your device), pause, open settings, stop managing this app (apps handled by a per-app setting) or exclude from the category (apps handled by a category), and close. When the keyboard could not be switched, a one-line notice with no buttons is shown; no notice is shown when the keyboard is switched back. In the settings screen under "On-screen notices", you can choose to show them or not.
- What is sent: Each time the keyboard is switched, that app's app type, where the value came from, and how the foreground app was detected (an accessibility event or Usage access) are sent to Firebase Analytics as a
keyboard_applied event. In addition, the Accessibility Service sends keyboard_released (what triggered it and the result), keyboard_switch_failed (why the switch failed), service_connected (the number of apps turned on), a11y_lost, and, when you use the buttons or menu on an on-screen notice, overlay_action and pause_set events (see section 1). App names and package names, and keyboard identifiers and names, are not sent. No keyboard_applied event is sent when you switch to an app that has neither its own setting to apply nor a category rule turned on, an app whose own setting you have turned off, or an app you have paused.
- On-device storage: The app's code does not keep a history of foreground app switches. The values the Accessibility Service writes to your device on its own are the single return-keyboard record (see section 1; it contains the package name of the app the keyboard is currently switched for, and it is deleted after switching back), the clearing of a global pause when its period ends, the keyboard-switch count used for review requests, the service connection record (whether it has ever connected and the time it last connected), and whether each one-time usage event has already been sent. In addition, when you use the buttons or menu on an on-screen notice, it writes what you did: the time a pause ends (to the app's own setting for an app handled by a per-app setting, or, together with the package name, to the apps excluded from categories for an app handled by a category), a keyboard changed in the menu (saved to the per-app setting or the per-app time rule applied at the time; for an app handled by a category, a new per-app setting is created with that app's package name and app name), turning the per-app setting off, and excluding the app from its category (for an app-type category the package name is added to the apps excluded from categories; for one of My categories the app is removed from its apps). However, events sent to Firebase are temporarily kept on your device by the Firebase SDK until they are sent.
- Actions on your behalf: The only thing the service does on your behalf is the default keyboard switching described above. It does not tap, scroll, or type for you. It does not declare the gesture capability (
canPerformGestures).
- Your control: The Accessibility Service works only after you turn it on yourself in Android Settings. Before taking you to the accessibility settings screen, the app shows a disclosure dialog and asks for your consent. If you turn the service on within 5 minutes after agreeing, you are brought back to the app automatically. You can turn the service off at any time in Android Settings, and you can pause per-app keyboard switching from the home screen or the Quick Settings tile.
3. Permissions
- Accessibility Service (BIND_ACCESSIBILITY_SERVICE): Detects the foreground app and automatically switches the device's default keyboard and switches it back (see section 2).
- Usage access (PACKAGE_USAGE_STATS) — optional permission: It is off by default and works only after you read the notice under "More accurate app detection" in the app's settings and turn it on yourself on the Android settings screen. What is read: only when the Accessibility Service could not read the active window, the package name of the one app that most recently came to the foreground, from the last 10 minutes of usage records (it is not read periodically, and not while the screen is off or locked or while everything is paused). Purpose: to switch to the keyboard you chose for an app on protected screens the Accessibility Service cannot see, and to switch the previous app's keyboard back when you move to such a screen. Storage and transmission: the package name is used on the spot to determine the foreground app and is not stored separately (if the keyboard is switched for that app, its package name is part of the single "keyboard to return to" record described in section 1). Your app usage time and usage history are not stored and are not sent anywhere. What is sent is only whether this permission is on (true/false) and, when a keyboard is switched, a marker that the foreground app was detected through this permission (see section 1). How to turn it off: turn AppKeys off under Android Settings > Apps > Special app access > Usage access (the name may differ by device), or tap "More accurate app detection" in the app's settings to go to the same screen. Everything else keeps working without it.
- Installed app and keyboard queries: To show the list of apps you can set a keyboard for, the app declares that it queries apps shown on your home screen (launcher), and to show keyboard names and icons, it declares that it queries the keyboards (input methods,
android.view.InputMethod) on your device. Libraries bundled with the app also declare some query entries automatically (the ad SDK: apps that handle web links, phone calls, text messages, and adding calendar events; the Google Play Billing Library: the Google Play Store app). The app does not request the permission to query all apps (QUERY_ALL_PACKAGES).
- Notifications (POST_NOTIFICATIONS, Android 13 and later): If the Accessibility Service is turned off, or is on but not connected, the app sends an "AppKeys is off" notification. Using WorkManager, the app checks the service state about every 6 hours (whether the service is connected and whether this app is turned on in Android's accessibility settings). The check itself happens on your device, and an
a11y_lost event is sent when the notification is sent. It notifies you once each time the service goes off, does not notify again while it stays off, and notifies once more if the service reconnects and then goes off again. Tapping the notification opens the app's home screen. The permission is requested on the home screen while the Accessibility Service is running, or when you come back after turning the service on from the settings screen; it is asked only once across the app and not asked again if you deny it. The app does not send persistent notifications. It sends one kind of promotional notification: a reminder that the welcome offer is ending. When you open the app's screens, it uses WorkManager to schedule one reminder for about 24 hours before the welcome offer period ends (7 days from the time you first opened the app on this device; see section 4). The reminder is not sent if, at that time, Remove Ads is active, a lookup found that this Google account already owns a Remove Ads product, the ownership lookup has not finished, the offer period has ended, the price of the welcome offer product could not be received from Google Play, that price is not lower than the regular product's price, or notification permission is not granted. It is sent on a notification channel separate from the service-off notification ("Offers"), and tapping it opens the app's Remove Ads screen (the app does not go there while the first-run guide is in progress). The app does not ask for notification permission separately for this reminder.
- Internet (INTERNET) and network state (ACCESS_NETWORK_STATE): Used to check ad consent and load ads, to send Firebase Analytics and Crashlytics data, and to open this privacy policy page from the settings screen.
- Advertising ID (AD_ID) and ad services permissions (ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_TOPICS): Declared by the Google AdMob SDK and Firebase Analytics for ad serving and measurement.
- Google Play billing (com.android.vending.BILLING): Declared by the Google Play Billing Library and used to buy Remove Ads and to confirm and restore the purchase.
- WAKE_LOCK and install referrer access (BIND_GET_INSTALL_REFERRER_SERVICE): Declared by Firebase Analytics and WorkManager. The install referrer is Google Play information about how the app was installed.
- FOREGROUND_SERVICE and DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION: Declared automatically by Android libraries bundled with the app (WorkManager, AndroidX). The app does not run a foreground service, and the latter is a permission private to this app that prevents other apps from calling receivers used only inside the app.
- Quick Settings tile: You can add a "Per-app keyboard" tile to Quick Settings in the notification shade. Tapping the tile pauses or resumes per-app keyboard switching, and opens the app instead when the Accessibility Service is not running (long-pressing the tile also opens the app). The tile does not request any permission (it is protected by BIND_QUICK_SETTINGS_TILE so that only the system can connect to it).
- Permissions the app does not use: The app does not use the display-over-other-apps permission (SYSTEM_ALERT_WINDOW) or the modify-system-settings permissions (WRITE_SETTINGS, WRITE_SECURE_SETTINGS). It changes the device's default keyboard only through the keyboard switching function Android provides to accessibility services (see section 2). The app contains no input method service and does not declare the input method permission (BIND_INPUT_METHOD).
4. Third-Party Services
AppKeys uses the following third-party services.
- Google AdMob and User Messaging Platform: Shows a banner ad at the bottom of the home screen and an app open ad when you open or return to the app (no app open ad is shown when you come into the app from the accessibility settings, battery optimization settings, the system keyboard settings, the file picker, a service-off notification, the Quick Settings tile, "open settings" in the on-screen notice menu, or a welcome offer reminder). No app open ad is shown before you finish the first-run guide (onboarding); app open ads start from the next time you leave and come back to the app after finishing it (the request that loads an ad in advance may still be made during the guide). Ads are set to play muted. When you open the app's screens, the app first uses the UMP SDK to check whether consent is required in your region and shows a consent form if needed. It initializes the AdMob SDK and requests ads in advance only when ads can be requested, so AdMob SDK initialization and ad requests do not occur when the app process runs only because of the Accessibility Service, the Quick Settings tile, the service state check, or the welcome offer reminder task. Your consent choice is stored on your device by the UMP SDK, and in regions that require consent, such as the EEA and the UK, you can change it under "Privacy options" on the app's settings screen (it is reset if you clear the app's data or reinstall the app, and is checked again the next time you open the app). To serve and measure ads and prevent fraud, AdMob may collect and use device identifiers such as the advertising ID and app set ID, your IP address and the approximate location derived from it, and ad interaction and diagnostic data; this information is processed by Google. The app does not set any option in its ad requests to limit personalized ads, so whether ads are personalized depends on your consent choice (in applicable regions) and your Google ad settings. While Remove Ads is active, banner and app open ads are not requested or shown (for when a purchase becomes active, see "Welcome offer and when Remove Ads is active" below). However, the consent check and AdMob SDK initialization when you open the app's screens still take place while Remove Ads is active. See the Google Privacy Policy and AdMob's data disclosure.
- Google Play billing: The purchase this policy calls "Remove Ads" is the product shown in the app under the name "AppKeys Pro" (a one-time purchase, product ID
remove_ads_lifetime). Besides not showing ads, it lifts the free usage limits. While Remove Ads is not active, you can create new time rules only up to 2 in total (per-app and per-category rules combined) and new My categories only up to 1, and you cannot turn on a category rule (per app type) that is off or export or import a settings backup. Time rules and My categories you already created, and category rules that are already on, keep working regardless of the limits and can be edited or deleted. Buying and paying is handled by Google Play, and payment information is processed by Google under Google's policies. Using the Google Play Store app on your device, the app looks up the product price and whether this Google account owns the purchase when the app process starts (including when it starts because the Accessibility Service connects), and looks up the product price when you open the Remove Ads screen, and when the payment sheet could not be opened from that screen, only if it has not been received yet (it also looks up ownership at that point if no ownership lookup has finished yet). It looks up whether this Google account owns the purchase again when you tap Restore purchase, when you return to the app's screens, and when you tap the buy button and Google Play reports that the product is already owned. If the app has already found that the account owns the product, tapping the buy button looks up ownership right away without opening the payment sheet. It also looks up ownership when the welcome offer reminder task (section 3) runs; that task also looks up the product price if it has not been received yet. When a purchase completes, the app sends the purchase information back to Google Play to acknowledge it but does not store the purchase token; it stores only whether Remove Ads is active (true/false) and whether it has ever been active on this device (true/false) on your device.
- Welcome offer and when Remove Ads is active:
- Welcome offer: for 7 days from the time you first opened the app on this device, the app shows a separate product that sells the same thing (Remove Ads and the lifting of the free usage limits) at a discounted price (a one-time purchase, product ID
remove_ads_lifetime_welcome) on the home screen, the settings screen, and the Remove Ads screen. It is not shown if Remove Ads is active, if a lookup found that this Google account already owns a Remove Ads product, if the ownership lookup has not finished yet, if the price of the welcome offer product could not be received from Google Play, or if that price is not lower than the regular product's price. The price and discount percentage are shown and calculated from the two product prices received from Google Play, and the remaining time is calculated on your device from the first-open time stored on your device and the device clock. The welcome offer card on the home screen is shown only while the Accessibility Service is running, and is not shown again once you dismiss it. One reminder is sent about 24 hours before the period ends (see section 3).
- When Remove Ads becomes active: when you complete a purchase, when you tap Restore purchase on the Remove Ads screen, or when you tap the buy button with an account that already owns the product. It makes no difference which of the two products is owned. The ownership lookups the app runs on its own (when the app process starts, when you return to the app's screens, when you open the Remove Ads screen or the payment sheet could not be opened from it, and in the welcome offer reminder task) activate Remove Ads only if there is a new purchase that has not been acknowledged yet or Remove Ads has been active on this device before. So on a device where you reinstalled the app or cleared the app's data, a purchase that has already been acknowledged is not activated again automatically; tapping Restore purchase activates it again. If the account has been found to own the product, tapping the buy button also activates it again without a payment (for the case where app settings are restored from a Google backup, see section 6). If any lookup succeeds and finds no owned purchase, Remove Ads is deactivated; if a lookup fails, the current state is kept.
- Google Play In-App Review: Once the keyboard has been switched to an app's keyboard 10 or more times, at least 3 days have passed since you first opened the home screen, and at least 60 days have passed since the last request, the app requests the Google Play review dialog on the home screen. Google Play decides whether to actually show the dialog and handles any review you write; the app cannot tell whether you wrote a review or see its rating or content.
- Firebase Analytics (Google Analytics for Firebase): Collects the usage events and user properties listed in section 1. Events sent by the Accessibility Service and the service state check may be sent even if you have not opened the app's screens. Separately, the Firebase Analytics SDK automatically collects information such as an app instance ID, device model, OS version, app version, language, and approximate region estimated from your IP address (such as country or city), along with events such as first open, session start, engagement time, and in-app purchases. The app does not apply the setting that turns off advertising ID collection, so the advertising ID may also be collected. Events are processed in connection with the app instance ID (and the advertising ID, if collected), so they are not anonymous. See the Google Privacy Policy.
- Firebase Crashlytics: In release builds, when the app crashes, it sends the error stack trace, diagnostic information such as device model, OS version, and app version, and an installation identifier, together with a commit hash identifying the build (
git_hash). Because the app also uses Firebase Analytics, crash reports may include recent Analytics events logged before the crash (including the usage events in section 1). Firebase Sessions, included with Crashlytics, may also send app session information. See the Google Privacy Policy.
- GitHub Pages: When you tap "Privacy Policy" in the settings screen, an in-app web view loads this page from feelpass.github.io. Standard web request information, such as your IP address, is sent to GitHub's servers.
- You can reset or delete your advertising ID (or opt out of personalized ads) in Android Settings > Google > Ads. Menu names may differ by device and Android version.
5. How Information Is Used
- Settings and records stored on your device: Used for automatic keyboard switching based on per-app settings, time rules, and category rules, and for switching back to your previous keyboard; pausing; on-screen notices; applying your theme and language; applying Remove Ads; limiting how often ads and review requests appear; service-off notifications; and calculating and showing the welcome offer period and sending its ending reminder.
- Firebase Analytics events: Used to understand how features are used, what types of apps per-app keyboards are used for, whether keyboard switching and switching back work properly, and where people stop during the first-run guide, accessibility setup, and purchase, in order to improve the app.
- Crashlytics reports: Used to find the causes of errors and improve app stability.
- AdMob: Used to show ads so the app can be offered for free.
- Google Play billing and In-App Review: Used to process and confirm Remove Ads purchases and to let you leave a review for the app if you want to.
6. Data Retention and Deletion
- Deleting settings: Turning an app off in the app list keeps its setting on your device in the off state; deleting an app on the home screen removes that app's keyboard setting and its time rules from your device. Time rules can also be deleted individually on the keyboard editor screen, and turning a category rule off keeps it on your device in the off state with its value.
- Uninstalling: Uninstalling the app deletes the keyboard settings, rules, app settings, and return-keyboard record stored on your device. If you only clear the app's data, your ad consent choice is reset. Remove Ads is not activated again automatically; it is activated again when you tap Restore purchase on the Remove Ads screen, or tap the buy button with an account found to own the product (no payment is made) (the same applies if you uninstall and reinstall the app, although this can differ as described under "Android Auto Backup" below if app data is restored from a Google backup when you reinstall; see section 4 for the detailed conditions). The welcome offer period is also calculated anew from the next time you open the app.
- Backup files: Exported backup files stay where you saved them and are not deleted when you uninstall the app. Delete them yourself if you no longer need them. If you choose a location provided by another service, such as a cloud drive, the file is kept under that service's policies.
- Android Auto Backup: The app allows Android Auto Backup and excludes only the return-keyboard record (section 1) from backup and device-to-device transfer. So if Google backup is turned on for your device, your keyboard settings and rules (including the identifiers of the keyboards you chose) and app settings may be included in your Google Account backup and restored to a new device or to a device where you uninstalled and reinstalled the app. App settings include the Remove Ads records and the welcome offer records (section 1), so on a device where app settings were restored from a backup, Remove Ads may be activated again by the Google Play ownership lookup without tapping Restore purchase, and the welcome offer period may continue from the earlier first-open time. You can manage backups from the Google backup menu in Android Settings.
- Refunds: If a Remove Ads purchase is refunded or canceled, Remove Ads is deactivated at the next Google Play lookup: ads are shown again and the free usage limits in section 4 apply again (you cannot create new time rules or My categories beyond the limits, turn on a category rule that is off, or export or import a settings backup). Your keyboard settings, rules, and other data on your device are not deleted, and rules and categories you already created and category rules that are already on keep working.
- Information sent to Google: Information sent to AdMob, Firebase Analytics, Firebase Crashlytics, and Google Play is retained by Google under each service's policies. Uninstalling the app does not delete information that has already been sent.
- Stopping transmission: The app has no in-app setting to turn off Firebase Analytics or Crashlytics. Turning off the Accessibility Service stops automatic keyboard switching, and the events the Accessibility Service sends (section 2) are no longer generated. Even with the Accessibility Service turned off, events from using the app's screens and ad requests still occur when you use the app. AdMob SDK initialization and ad requests occur only when you open the app's screens, but when the app process starts, the Google Play purchase lookup and the service state check run, and an
a11y_lost event is sent when that check sends a service-off notification.
- For questions about information that has been sent, or to request its deletion, please contact us using the address below.
7. Children's Privacy
AppKeys is not directed at children under 13 and does not knowingly collect personal information from children.
8. Changes to This Policy
We may update this policy as needed. Any changes will be posted on this page.
9. Contact
If you have any questions about this privacy policy, contact us at philleeran@gmail.com.
Effective date: October 5, 2026