Effective date: 25 August 2026 Last updated: 28 September 2026
Privacy Policy
This Privacy Policy applies to the mobile application ByoKey for iPhone and iPad ("the App") and to the website https://byokey.app ("the Website"), together "the Services".
1. Summary
This section is an overview for orientation. Sections 2 to 18 are the binding text.
- We operate no server for the App. There is no user account, no registration and no login. ByoKey is a client that talks to third-party providers directly from your device.
- We do not receive your content. Your chats, prompts, project instructions, attachments, generated images, voice recordings and API keys never reach us. We have no technical means of accessing them and hold no copy.
- Everything you create is stored on your device, inside the App's protected container. API keys are stored separately in the iOS Keychain.
- The App transmits data over the network only after you have given consent, and only to the AI provider you selected — or to a server of your own whose address you entered — authenticated with your API key (with a server of your own, only if you entered one). The only other recipient is Apple, if you switch on its server speech recognition (Section 7). Most of these providers process data in the United States. Some process it in the European Union (Mistral AI, Scaleway, IONOS), one is based in the United Kingdom (Requesty), and one (DeepSeek) processes data in the People's Republic of China.
- The App contains no analytics, no advertising, no tracking, no crash reporting and no third-party SDKs. There is no advertising identifier and no App Tracking Transparency prompt, because there is nothing to track.
- We process personal data only when you write to us (e-mail or content report) and, in a limited technical form, when you visit the Website.
2. Controller
Responsible for data processing within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR):
Maximilian Skibinski Wladimir-Komarow-Straße 41 15517 Fürstenwalde/Spree Germany E-mail: support@byokey.app Website: https://byokey.app
Data protection officer. We have not appointed a data protection officer because the conditions of Art. 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) are not met.
Scope of our controllership. To the extent the Services involve processing of personal data for which we are the controller, this is limited to (a) the operation of the Website (Section 12), and (b) messages you send us directly (Section 11). Processing that takes place exclusively on your device (Section 5) and the transmission you initiate to a provider of your choosing (Section 6) do not put your content in our hands at any point.
3. Terms used in this policy
| Term | Meaning |
|---|---|
| Provider | A third-party operator of an AI programming interface that you select in the App and address with your own API key — for example OpenRouter, OpenAI or Mistral. See Section 6.3 for the full list. |
| API key | The secret credential you obtain from a provider and enter into the App. It identifies your account with that provider and is billed to it. |
| Chat | A conversation stored on your device, consisting of your messages and the provider's responses. |
| Project | A folder for chats with its own default settings, in particular its own system prompt. |
| System prompt | Standing instructions that are transmitted with every message in a project. |
| Attachment | A PDF, text file, source-code file or image that you attach to a message. |
4. How ByoKey works, and why that determines this policy
ByoKey is a "bring your own key" client. When you send a message, your device opens a direct connection to the programming interface of the provider you selected and transmits the request there. The connection is encrypted with TLS; the only exception is a server of your own that you address with http://, which the App allows only for local-network addresses (see Section 17). There is no proxy, no relay and no server of ours anywhere in that path.
Three consequences follow, and we state them plainly because they cut both ways:
- We cannot read, analyse, sell or hand over your content, because we never have it.
- We cannot restore it. If you delete a chat or lose your device, the content is gone. There is no backup on our side.
- We cannot act on your behalf towards a provider. Once data has been transmitted to a provider, only that provider — and you, as the holder of the account there — can delete it.
5. Data processed on your device
The following data is created and stored exclusively on your device, inside the App's sandboxed container. All files the App writes are encrypted at rest by iOS (NSFileProtectionCompleteUntilFirstUserAuthentication): they are unreadable until the device has been unlocked once after a restart. Your API keys are held to a stricter level in the iOS Keychain (kSecAttrAccessibleWhenUnlockedThisDeviceOnly) — readable only while the device is unlocked, and never synced to iCloud.
| Category | Examples | Storage location | Retention |
|---|---|---|---|
| Chats and messages | Your prompts, provider responses, timestamps, model used | App container (JSON file) | Until you delete them |
| Projects | Project name, system prompt, default model, accent colour, creation date | App container | Until you delete them |
| API keys | The secret credential of each provider – entered by you, or created in your OpenRouter account when you use "Connect with OpenRouter" | iOS Keychain, in a separate entry per key | Until you delete the key |
| Key metadata | Name you gave the key, provider, creation date, date of last successful verification | App container | Until you delete the key |
| Attachments | Text extracted on the device from PDF, text and source-code files; images reduced to a maximum of 1536 px and re-encoded as JPEG | App container, separate folder | Until you delete the chat or the attachment |
| Generated images | Images returned by an image model | App container | Until you delete them |
| Cost and token counters | Estimated tokens and costs per chat, project and session | App container | Until you delete the data |
| Content reports | Reports you file about a response (Section 10) | App container, local log | Until you delete the data |
| Settings | Interface language, consent status, active key per provider, voice settings | App container | Until you delete the data |
The monthly spending budget is a single App-wide setting, not a per-project one.
In addition, the App stores your own settings and working state on the device: blocked models, prices you entered yourself, the address and name of a server of your own, the last chat and project you had open, the active provider and default model, temperature, maximum response length, monthly budget, currency, filter strictness, and the version of the Terms you accepted. Temporary voice recordings, exported files and the HTML preview folder are written to the App's temporary directory and removed again when they are no longer needed.
The masked form of a key (“sk-or-v1-…4f2a”) shown in the interface is derived from the Keychain in memory while the App is running. It is never written to the state file.
The state file never contains an API key. Where a provider returns an error message that itself contains a fragment of a key, that fragment is redacted before the message is stored in the chat. The redaction covers the known API-key formats and is a best-effort measure, not a guarantee.
iCloud and device backups. If you have iCloud Backup or encrypted local backups enabled, iOS may include the App's container — and, depending on your settings, Keychain entries — in those backups. Backups are operated by Apple and governed by Apple's privacy policy. You can exclude ByoKey in *Settings → [your name] → iCloud → Backup → Manage Account Storage*.
Legal note. This processing takes place under your sole control on hardware you own. We have no access to it, receive no copy and derive no information from it.
6. Data transmitted to the AI provider you choose
6.1 Nothing is transmitted before you consent
Before the first network request to a provider, the App shows a consent screen that names:
- the recipient by name, and where it processes data,
- every category of data that will be transmitted, individually and including your API key and your IP address,
- a link to that provider's own privacy policy,
- for recipients outside the European Union: that your data will be processed outside the EU or forwarded there, and the risks this entails for the level of protection.
Consent must be given actively. It is per provider, and it can be withdrawn at any time in the settings with effect for the future. Withdrawing consent immediately stops a response that is still streaming and a recording that is still running, and blocks all further requests to that provider.
For a server of your own, the consent screen names the host name or IP address from the address you entered, and the name you gave the server, if any, because the App cannot know who operates it; there is no privacy policy it could link to. If you change the address, the App withdraws the consent: it applied to the previous server only. If the new address points to a different computer, the App also stops using the key you entered for the previous one until you select it again.
Voice mode requires a separate consent. If you use speech recognition or speech output via a provider rather than on the device, that requires its own, separate consent. Consent for text does not cover audio.
The App enforces this in its network layer: every request it sends to an AI provider checks the consent status before it is sent. The single exception is Apple's server speech recognition described in Section 7, which you enable separately in the settings.
Legal basis: your consent, Art. 6(1)(a) GDPR, and — insofar as the transmission goes to a third country — Art. 49(1)(a) GDPR (see Section 6.5). Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).
Connect with OpenRouter. Instead of entering a key, you can sign in to OpenRouter from the App. The App opens Apple's system sign-in window with OpenRouter's website only once you have given your consent for OpenRouter; if you have not, it shows the consent screen first. In the sign-in window you sign in directly with OpenRouter – or create an account there – and the App never sees your password or other sign-in details. OpenRouter then creates an API key in your account and sends a one-time code back through the return address on our website (Section 12.5), which forwards it straight to the App; the App exchanges it for the key directly with OpenRouter. The exchange also requires a random check value that the App created on your device for this sign-in and sends to no one but OpenRouter (PKCE). The key is then stored in the iOS Keychain like a key you entered. The sign-in window shares its sign-in state with Safari. Each connection creates a new key in your OpenRouter account. Removing the key in the App, or "Delete all data", deletes it only from your device; to invalidate it, delete it in your OpenRouter account.
6.2 What is transmitted
When you send a message, the following leaves your device:
- the text of your message,
- the earlier messages of the same chat, to the extent they fit into the selected model's context window. When the window is full, the oldest messages are dropped automatically and are not transmitted. The App shows you the size of the selected model's context window, and warns you before sending when your attachments alone would no longer fit,
- the system prompt of the project the chat belongs to,
- the text extracted from attached documents. The document file itself is not uploaded — extraction happens on the device, and only the extracted text is transmitted,
- attached images, reduced in size and re-encoded as JPEG,
- the identifier of the selected model and the generation parameters,
- your API key, in a header of the request (with a server of your own only if you entered a key),
- the technical data that any HTTPS request produces and that cannot be avoided: your IP address, the time of the request, TLS metadata and the request size,
- in provider voice mode only: the audio recording of what you say, and/or the text to be read aloud,
- when the provider is OpenRouter, two identifying headers (HTTP-Referer: https://byokey.app and X-Title: ByoKey) that tell OpenRouter which app the request came from. They contain nothing about you.
- the file names of the documents you attach, in the header that introduces the extracted text,
- the App's own safety instruction, which is prepended to every request,
- in provider voice mode: the language code, the speech model identifiers and the selected voice name.
The App additionally contacts the provider in these cases:
- to load the list of available models and their prices,
- to show the usage and remaining credit of your key,
- to generate an image, if you have selected an image model,
- when you use "Connect with OpenRouter": to exchange the one-time code for your API key (this request contains the code and the check value, but no message content), and then, with the new key, to check whether your account has ever had credit and to load the model list.
These requests carry your API key but no message content, except for the image request, which carries your prompt and any reference image.
6.3 Recipients
Which provider receives the data is determined solely by your choice in the App. Only the provider you have selected and consented to receives anything.
| Provider | Place of processing | Privacy information |
|---|---|---|
| OpenRouter | United States | https://openrouter.ai/privacy |
| OpenAI | United States | https://openai.com/policies/privacy-policy |
| Google (Gemini API) | United States / Ireland | https://policies.google.com/privacy |
| Mistral AI | France (European Union) | https://legal.mistral.ai/terms/privacy-policy |
| DeepSeek | People's Republic of China | https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html |
| Groq | United States (contracting entity Groq LLC, or Groq UK Limited for Europe) | https://groq.com/privacy-policy |
| SpaceXAI (formerly xAI) | United States | https://x.ai/legal/privacy-policy |
| Together AI | United States | https://www.together.ai/privacy |
| Cerebras | United States | https://www.cerebras.ai/privacy-policy |
| Anthropic | United States and other countries (contracting entity Anthropic Ireland, Limited for users in the EEA, the UK and Switzerland; otherwise Anthropic, PBC) | https://www.anthropic.com/legal/privacy |
| Scaleway | France (European Union), data centre in Paris | https://www.scaleway.com/en/privacy-policy/ |
| IONOS AI Model Hub | Germany (European Union) | https://docs.ionos.com/cloud/ai/ai-model-hub/governance-and-compliance/data-handling |
| Vercel AI Gateway | United States; forwarded to the operator of the selected model | https://vercel.com/legal/privacy-policy |
| Requesty | United Kingdom; forwarded to the operator of the selected model | https://www.requesty.ai/privacy |
| DeepInfra | United States | https://deepinfra.com/privacy |
| Your own server (only if you enter one) | Wherever that server runs — on your own network, if it is your own computer | The operator's own information; none, if you operate the server yourself |
| Apple (speech recognition — only if you enable it in the settings) | United States | https://www.apple.com/legal/privacy/ |
*Provider details and links last verified on 24 September 2026.*
Apple is not an AI provider and appears here only because of the optional server speech recognition described in Section 7.
Special note on aggregators. OpenRouter, Vercel AI Gateway and Requesty are aggregators. They do not operate most of the models offered through them; they forward your request to the operator of the model you selected. The actual chain of recipients therefore depends on the model and may include companies not listed in the table above. Which operators are involved for a given model, and which of them retain data, is documented by the aggregator on its model pages. Please consult that information before you send confidential content.
Requesty stores requests encrypted in the European Union for up to 30 days by default; you can switch this off for your key in your Requesty account with "Zero Data Retention". Models that Requesty marks as released for training are hidden by the App. DeepInfra also offers models from Google and Anthropic; for these, those companies' terms apply in addition.
A server of your own. In the settings you can choose "Custom server" and enter the address of any server with an OpenAI-compatible interface — typically Ollama or LM Studio on your own computer. The recipient is then whoever operates that server; the App cannot check who that is. If the server runs on your own network, your data does not leave that network — unless the server itself passes it on, for example to a cloud model.
6.4 The provider is an independent controller
For everything that happens after transmission — storage duration, use for model training, onward disclosure, security, deletion — the provider is the controller in its own right, on the basis of the contract you concluded with it when you created your account there. This policy does not and cannot govern that processing.
Two points deserve your attention:
- Training. Whether your inputs are used to train or improve models is decided by the provider and, with several of them, by a setting in your account. Some offer a "zero data retention" or "no training" option. Check this in your provider account; the App cannot set it for you. Free models at OpenRouter are generally only available if you allow, in your OpenRouter account, providers that may train on your inputs or publish them.
- Your provider account. Requests for information, deletion or objection concerning transmitted content must be addressed to the provider, not to us.
- A server of your own. If you connect a server of your own, its operator is the controller for everything that happens there — if you operate it yourself, that is you. We have no access to it.
6.5 Transfers to third countries
Most of the providers listed process data in the United States. There is no general adequacy decision for the United States; some US companies are certified under the EU-U.S. Data Privacy Framework, others are not. Where a provider is not certified, US authorities may have access rights that fall short of the standard of protection under EU law, and effective legal remedies may not be available to you.
DeepSeek processes data in the People's Republic of China. There is no adequacy decision for China. Chinese law grants state authorities far-reaching access to data held by domestic companies, and there is no equivalent legal remedy available to persons in the EU. We strongly advise against sending personal data of third parties, business secrets or other confidential information to this provider.
Requesty is based in the United Kingdom. For the United Kingdom, the European Commission has adopted an adequacy decision (Art. 45 GDPR). Requesty forwards your request to the operator of the model you selected, however, and that operator may be located in a third country without such a decision.
Scaleway and IONOS state that they process data exclusively in data centres in the European Union — in France and in Germany respectively; with these two providers there is no transfer to a third country. Anthropic's contracting entity for users in the EEA is Anthropic Ireland, Limited, but processing also takes place outside the European Union; Anthropic does not offer EU-only processing.
With a server of your own, you decide where it is located. If it runs on your own network, no transfer to a third country takes place.
Transfers to providers in third countries without an adequacy decision are made on the basis of your explicit consent under Art. 49(1)(a) GDPR, given in the consent screen described in Section 6.1. Before the first transmission, that screen names the recipient and tells you that your data will be processed outside the EU or forwarded there, and what that means for the level of protection. We cannot guarantee an adequate level of protection for these transfers.
7. Device permissions the App requests
The App requests the smallest set of permissions that its functions require, and it requests them at the moment they are first needed, not on first launch.
| Permission | When it is requested | What we do with it |
|---|---|---|
| Microphone | When you open voice mode for the first time | Records what you say for the duration of a dictation. On-device mode: the recording does not leave the device. Provider mode: the recording is transmitted to the provider, subject to the separate audio consent. |
| Speech recognition | When you open voice mode for the first time | The App asks iOS for on-device recognition and uses it whenever the selected language supports it; the recording then never leaves your device. If the language has no on-device recognition, the App does not transcribe at all — unless you explicitly switch on "Allow Apple's server recognition" in Settings › Voice mode. That setting is off by default. With it on, the recording is transmitted to Apple Inc. for transcription and is governed by Apple's privacy policy. This is the only transmission in the App that is not covered by the per-provider consent described in Section 6; the setting itself is your consent to it, and switching it off ends it. |
| Personal Voice | Only if you choose a personal voice for reading aloud | Used locally for speech synthesis. |
| Photos — add only | When you save a generated image to your photo library for the first time | Writes the image. The App holds add-only access and never reads your photo library. |
| Local network | Only when the App connects for the first time to a local-network address that you entered under "Custom server" | Connects to exactly that address — for example Ollama or LM Studio on your Mac. The App does not search your network for devices and contacts no other device. |
Attaching a photo does not require a permission. The system photo picker runs in a separate process outside the App. The App receives only the images you actually tap and at no point gains access to your library. For this reason the App declares only the "add" purpose string in its configuration.
The App requests no access to location, contacts, calendar, health data, Bluetooth (beyond audio routing for voice mode) or notifications, and it uses no advertising identifier. It asks for access to the local network only in the case described above.
8. Cost display
The App estimates the tokens and costs of your requests locally and shows totals per chat, per project and per session. Where a provider reports the cost of a request itself — OpenRouter and Requesty do — the App uses that figure. Otherwise it calculates the cost on your device from the prices the provider publishes in its model list; OpenRouter, Requesty, Vercel AI Gateway, DeepInfra, Together AI and xAI deliver them there. Where the model list shows no price for a model, you can enter your own: touch and hold the model in the model list and choose "Set price". Prices you enter are marked "(custom price)" in the list, apply only to that model with that provider, are used only where the provider neither reports the cost nor lists a price, and stay on your device.
Where a provider does not report usage, the App estimates the token counts locally. Where a provider does not publish prices, the App uses the prices you entered yourself, if any, and marks the result as an estimate; where neither is available it shows no amount at all rather than a wrong one. In every case the figure is an estimate, not an invoice. The figure that counts is the one in your provider account. See Section 6 of the Terms of Use.
9. Local file export and HTML preview
Export. If a response contains source code, you can save the detected files individually or as a ZIP archive. The export runs entirely on your device. Where the files end up afterwards — the Files app, iCloud Drive, another app you share them with — is your choice and is then governed by the destination's terms.
HTML preview. Generated HTML files can be rendered locally in the App. This preview is sealed off: it loads only local files from the preview folder, and every attempt to reach an external address is blocked. Navigations, new windows and script dialogs are refused by the App and the blocked address is shown to you; images, stylesheets, fonts and script-initiated network calls are blocked by the content security policy without a separate notice. A content security policy is inserted into every HTML page before it is written to the preview folder. No browsing data is retained, and no second window can be opened. Server-side languages such as PHP are not executed and cannot be executed — the preview displays such files, it does not run them.
10. Content moderation, reporting and safety notices
Local filtering. Before anything is sent, the App checks your new message on its own; every earlier message of the chat that would be transmitted, each on its own; the project's system prompt; and your new message together with the system prompt and your two previous messages in the chat, so that a request cannot be split across several messages. Earlier messages that fail the check are marked and not transmitted. Text extracted from a file you attach is checked once, when you attach it. The provider's text response is checked as well — already while it is streaming. All of this happens on your device, against a locally stored set of rules. Its results are not transmitted anywhere, and no profile is built from them.
Language limitation, stated openly. The detection keywords are German and English only; input in other languages is not caught by them. The rule set additionally recognises Polish refusal phrases, so that a model's legitimate refusal in Polish is not mistaken for a violation. The binding safety instruction the App prepends to every request, and the check on the response, apply regardless of language.
Images are not checked. The filter reads text. It cannot assess the content of an image. This applies both to images you attach and to images a model generates. For image content, the provider's own moderation and the reporting and blocking functions described below are the applicable safeguards.
Reporting. You can report any response. The report is stored in a local log on your device. If you additionally choose to send it to us, your mail app opens with a prepared message; nothing is sent until you send it yourself. If you do send it, we receive your e-mail address and the content you included — see Section 11.
Blocking. You can block a model, which prevents the App from using it further. This setting is local.
Safety notices. If the App detects an expression of an acute personal crisis, it displays local emergency contact information for your interface language. This detection runs on the device. No assessment of your condition is stored, transmitted or forwarded, and the notice itself triggers no network request.
11. When you contact us
| Channel | Data we receive | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Support e-mail | Your e-mail address, the content of your message, any attachments and metadata your mail server adds | Answering your enquiry | Art. 6(1)(b) GDPR, or Art. 6(1)(f) — our legitimate interest in responding to enquiries | Until the enquiry is settled; then deleted, unless statutory retention obligations apply |
| Content report by e-mail | The above, plus the report reason and the excerpt you attach | Investigating the report and meeting our obligations as a provider of an app with user-generated content | Art. 6(1)(f) GDPR; where a statutory duty exists, also Art. 6(1)(c) | Up to 24 months, so that repeat cases can be recognised |
We do not use this data for any other purpose, and we do not use it to build a profile. Where we are legally obliged to report a matter to a public authority — for example in the case of depictions of the sexual abuse of children — we will do so.
12. The Website
12.1 Hosting
The Website is served through Lovable Cloud, the hosting service of:
Lovable Labs AB Regeringsgatan 25 111 53 Stockholm Sweden Data protection officer: dpo@lovable.dev
We have concluded a data processing agreement with this provider pursuant to Art. 28 GDPR (https://lovable.dev/data-processing-agreement). The provider engages sub-processors of its own; the applicable list is published at https://lovable.dev/subprocessors. The Website's content is held on the Supabase infrastructure that the provider uses for Lovable Cloud.
Place of processing: European Union. The provider offers a choice between the European Union, the United States and Asia Pacific, and data does not move out of the selected region by itself.
12.2 Log data
Each retrieval of a page produces log data at the hosting provider. According to the provider's own description this includes the IP address and approximate location, browser type and version, the pages and features accessed, timestamps, session or device identifiers and error codes.
Purpose: delivering the page, ensuring stability and security, and detecting misuse. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the site. Retention: we do not operate the server ourselves and have no direct access to the raw logs; retention follows the hosting provider's specification.
12.3 The contact form
The Website offers a contact form with the fields Name, Email, Subject and Message. The form does not transmit anything to us or to our hosting provider. Your entries are assembled in your browser into a prepared e-mail and handed to your own mail application; nothing is sent until you send that e-mail yourself.
Once you do, we receive an ordinary e-mail. Purpose, legal basis and retention are then the same as for the support e-mail described in Section 11: we use it to answer your enquiry, on the basis of Art. 6(1)(b) GDPR where it concerns a contract or its initiation and otherwise Art. 6(1)(f) GDPR, and we delete it once the matter is settled, unless statutory retention obligations apply.
You may write to support@byokey.app directly instead of using the form at any time. No cookie is set and no third-party service is involved.
12.4 Cookies and third parties
The Website uses no analytics, no advertising and no tracking pixels. Technically necessary components — in particular the hosting provider's delivery network — may set cookies or comparable identifiers. Storage that is strictly necessary to provide a service you expressly requested does not require consent (§ 25(2) no. 2 TDDDG).
| Name | Purpose | Set by | Lifetime |
|---|---|---|---|
| __cf_bm | Distinguishes human visitors from bots; protects the site against automated abuse | Cloudflare (security layer of the hosting provider) | 30 minutes |
| __dpl | Pins the browser to one deployment so that lazily loaded page fragments come from the same build | Hosting provider's edge network | Session |
Both are strictly necessary to deliver the website and are therefore set without consent under Section 25(2) no. 2 TDDDG. Neither is used for analytics, advertising or profiling.
Beyond that, no content is loaded from third-party servers.
A display language you select is stored in a strictly necessary cookie or in your browser's local storage. This storage serves solely the language switch you requested and is not evaluated for any other purpose.
12.5 Return address of the OpenRouter sign-in
After you confirm the connection, OpenRouter sends the App's sign-in window to https://byokey.app/auth/openrouter together with a one-time code. This page only forwards the code directly to the App on your device; it does not display, store or pass it on, and it contains no analytics or third-party content. As with every page request, the hosting provider records the address in its log data (Section 12.2), including the one-time code. The code expires after a short time and is worthless without the check value that only the App holds for this sign-in (PKCE).
13. Apple and the App Store
The App is distributed through Apple's App Store. Downloading, installing and updating are handled by Apple under Apple's own terms and privacy policy. We have no influence over this and receive no personal data from it.
Apple provides us with aggregated, anonymised statistics (App Analytics) — for example the number of downloads or the distribution of crashes by device type. These figures do not allow us to identify individual users, and we do not attempt to combine them with any other data.
Apple's privacy policy: https://www.apple.com/legal/privacy/
14. Deleting your data
In the App. *Settings → Delete all data* removes chats, projects, attachments, generated images, cost data, local reports, quarantined recovery files and the Keychain entries holding your API keys. The operation is irreversible.
Individually. Chats, projects, attachments, images and individual API keys can each be deleted on their own.
Deleting the App. Removing ByoKey from your device deletes its container. Because iOS does not in all cases remove Keychain entries when an app is deleted, we recommend running *Delete all data* before you delete the App.
Data already transmitted. Content that has reached a provider is outside our reach. Delete it in your account with that provider, or exercise your rights against it directly.
15. Your rights
Under the GDPR you have the right, in respect of personal data for which we are the controller, to:
- access (Art. 15) — confirmation of whether we process data about you, and a copy;
- rectification (Art. 16);
- erasure (Art. 17);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object (Art. 21) to processing based on Art. 6(1)(f);
- withdraw consent (Art. 7(3)) at any time, with effect for the future.
To exercise any of these rights, write to support@byokey.app. We will respond within one month.
One honest limitation. For the data described in Section 5 we hold nothing: it is on your device. A request for access would return an empty result from us, and a request for erasure can only be answered by pointing you to the deletion function in the App. The same applies to data you transmitted to a provider — those rights must be exercised against the provider.
Right to lodge a complaint (Art. 77 GDPR). You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. The authority competent for us is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg Stahnsdorfer Damm 77 14532 Kleinmachnow, Germany Phone: +49 33203 356-0 E-mail: poststelle@lda.brandenburg.de https://www.lda.brandenburg.de
16. Children
The App is not directed at children. In line with its App Store age rating, you may use it only if you have reached the age indicated there, and in any event only if you are old enough to consent validly to the transmission of data to a provider — in Germany and in several other EU Member States, that is 16 years. Younger users may use the App only with the consent of a parent or legal guardian, who is then responsible for the API key and for the costs it incurs.
We do not knowingly process personal data of children. Because we operate no account system, we have no means of verifying age.
17. Security
- All connections to AI providers use TLS (HTTPS). The only exception is a server of your own that you enter with an http:// address. The App accepts http:// only for addresses of the kind used within a local network — private IP addresses (such as 192.168.x.x, 10.x.x.x or 172.16–31.x.x, and the corresponding IPv6 ranges), names ending in .local, and names without a dot; every other address must begin with https://. An http:// connection is unencrypted, as is customary within a home network. The App cannot tell which network such an address leads to: in a network you do not control — in a hotel or café, for example — another device could answer at the same address, so use http:// only on your own network.
- API keys are stored in the iOS Keychain, not in the App's state file and not in plain text anywhere else.
- The App uses no third-party libraries, which removes an entire class of supply-chain risk.
- The App's data is protected by the iOS sandbox and encrypted at rest by iOS file protection (NSFileProtectionCompleteUntilFirstUserAuthentication), so that it is unreadable until the device has been unlocked once after a restart.
What we cannot promise. No system is completely secure. The security of your data at a provider, the security of your provider account and the physical security of your device are outside our control. Protect your device with a passcode or biometrics, keep iOS up to date, set a spending limit on every API key, and revoke a key at the provider immediately if you suspect it has been exposed.
18. Changes to this Privacy Policy
We will update this policy when the App changes or the legal situation requires it. The current version is always available at https://byokey.app/privacy and is linked from within the App. The date at the top shows when it was last changed. Where a change concerns processing based on your consent, we will ask for that consent again rather than relying on the old one.
19. Contact
Maximilian Skibinski Wladimir-Komarow-Straße 41 15517 Fürstenwalde/Spree Germany E-mail: support@byokey.app
*This document is available in German, English and Polish. The German version at https://byokey.app/de/privacy prevails in the event of any discrepancy; the other language versions are translations provided for convenience. Mandatory consumer protection provisions of your country of residence remain unaffected.*