Privacy Policy
Last Updated: August 31, 2026
This Privacy Policy applies to the KeyPaste iOS and macOS apps, the KeyPaste keyboard extension, the system share extension, and related paid features. It explains what information KeyPaste may process, how that information is stored or transferred through your device and Apple-provided services, and what controls you have over your data.
1. Information We Process
KeyPaste is designed to help you save, manage, and insert your own content. To provide these features, the app may process the following information:
- Content you choose to save: text and rich text snippets, web links, images, files, attachment names and types, tags, and content you explicitly add through the share extension or the in-keyboard save flow.
- App settings and preferences: such as theme color, appearance mode, keyboard height, haptic feedback preference, tag display preference, Pro status, and iCloud sync preference.
- Keyboard context text: when you actively use the “Save to KeyPaste” feature inside the keyboard, the keyboard extension may read the text that iOS makes available to it, including selected text, text before the cursor, and text after the cursor, in order to prepare content for saving.
- Clipboard content: when you explicitly choose a clipboard-saving action, or enable proactive clipboard capture in settings, KeyPaste may read supported text, rich text, image, or file representations from the current system clipboard. Some automatic capture surfaces accept fewer content types than explicit save flows. When you keep captured content in Inbox and enable iCloud sync, the resulting entry and eligible managed attachments may sync through Apple CloudKit to your other devices.
- On-device image recognition and search: when you use the image OCR word-selection feature, KeyPaste processes the selected image on your device to recognize text. For Pro image search, the iOS and macOS main apps may also use Apple Vision to build a local derived OCR index and ask Apple Core Spotlight to match donated image items by recognized text or concepts in your search. KeyPaste does not include its own image-recognition model or ask you to download a separate model. Recognition and matching are best effort and depend on the device, operating system, language, image, and availability of Apple’s system indexing. Images, recognized text, and search terms are not sent to TelemetryDeck, RevenueCat, or developer-operated servers.
- Link previews: when the iOS or macOS main app displays a public HTTP or HTTPS link that is an entire library snippet or Inbox item, it may contact the destination website, redirect destinations, and image, icon, or media hosts referenced by that page to retrieve a title, site icon, and representative image. Long-press on iPhone or iPad, and Space preview in the macOS main window or Quick Panel, may also load that page in a temporary in-app web view so you can peek at the live webpage. These requests can disclose your IP address and the requested URL, including its path or query, to those sites. KeyPaste validates the initially saved address before requesting metadata or loading a page peek, but Apple’s LinkPresentation framework and the in-app web view manage later DNS resolution, redirects, scripts, and page subresources; a page may therefore direct requests to other hosts or network addresses reachable from your device. KeyPaste does not keep cookies or other website data from a page peek after the preview is dismissed, does not render, play, or cache link-preview video, and does not send the link or preview to developer-operated servers, TelemetryDeck, or RevenueCat. Home Screen widgets may contact the same destination website and page-referenced image or icon hosts to retrieve a title, site icon, and representative image for link items currently visible on the widget, including items you have not opened in the main app. Widgets do not load a live webpage. The keyboard and share extension do not fetch link previews or load destination pages.
- Purchase-related information: if you purchase or restore Pro, the app uses Apple StoreKit to read product information and purchase status so paid features can be unlocked. The iOS and macOS main apps also use RevenueCat to keep anonymous purchase records for purchase analytics, restore/support operations, refund and revocation handling, and measuring Apple Search Ads. Alongside those purchase records, KeyPaste may send closed, content-free product-state categories such as platform, Pro status, Inbox limit band, value-stage band, and which product area opened the Pro screen. On iOS, KeyPaste may also send Apple’s AdServices attribution token so RevenueCat can attribute a purchase to an Apple Search Ads campaign when Apple provides that match. These records use a RevenueCat-generated anonymous identifier. KeyPaste does not send saved content, keyboard input, search terms, contact details, an advertising identifier (IDFA), or a custom account identifier to RevenueCat.
- Shortcuts input: if you actively use Shortcuts or Siri to create a snippet, KeyPaste processes the content and tags you explicitly provide for that action.
- Anonymous usage analytics: the iOS and macOS main apps use TelemetryDeck to understand how people use KeyPaste and to improve features and reliability. This may include which product surfaces you use; which features you open, complete, cancel, or are blocked from; closed category values for content type, layout, appearance, keyboard height, sync preference, export scope, filters, and results; approximate item-count bands; activation and repeat-use milestones; reliability categories; which product area opened the Pro screen; purchase or restore flow outcomes; whether the app requested an App Store review; anonymous session counts and duration; how long selected multi-step features take; closed navigation paths such as Settings or Pro; and closed diagnostic identifiers for user-visible failures. Events use fixed categories and may include basic app, device, system, accessibility, and regional context supplied by the analytics service. A verified Pro purchase may also send TelemetryDeck’s standard purchase signal, which includes purchase type, storefront country, currency, and an approximate USD amount derived by the analytics SDK. They do not include your saved or clipboard content, typed keystrokes, recognized image text, search terms, tag names, folder names, file names, URLs, the names of other apps you paste into, payment card details, order numbers, receipts, account identifiers, advertising identifiers, or free-form error messages. TelemetryDeck uses a hashed installation identifier to produce aggregate counts. When anonymous analytics is enabled, KeyPaste may give RevenueCat that same hashed TelemetryDeck installation identifier and app ID so purchase lifecycle events can appear on the same analytics dashboard; this is not a custom account identifier, is not used for advertising, and is not used to identify you as a person.
KeyPaste does not upload your saved content, clipboard content, or keyboard-captured text to developer-operated servers, and does not use that content for advertising, profiling, or cross-app tracking.
2. How Data Is Stored and Synced
- Local storage: your snippets, Inbox entries, tags, attachments, and related data are stored locally on your device by default. Link preview titles and size-limited preview images may be cached in the main app’s local system cache and in the widget extension’s local system cache. A live page peek is not written to that cache. Entries older than 30 days are deleted the next time KeyPaste maintains that cache, and the operating system may remove them sooner; they are not included in KeyPaste exports, App Group snapshots, analytics, or CloudKit sync. The main app and extensions use an App Group container to exchange the minimum data needed for read-only snapshots, queue handoff, Inbox import, and settings synchronization.
- Derived image search data (Pro): the iOS and macOS main apps keep the OCR manifest, recognized text, and dedicated image copies used for image search in local Application Support. These derived records and copies are not written to KeyPaste’s formal SwiftData store, CloudKit / iCloud, exported packages, or the App Group keyboard snapshot; they are not exposed to the keyboard or share extensions. KeyPaste donates scoped image items to an Apple Core Spotlight index, so those items may also appear in Apple system search outside KeyPaste. When a source item is deleted or Pro access is confirmed to have ended, KeyPaste schedules removal of the related local derived data and Core Spotlight items. System-index removal is best effort and may be retried when Core Spotlight becomes available.
- Extension queue flow: the keyboard and share extensions do not act as the final persistence host. They write supported pending saves into a shared App Group queue, and a main app imports those items into the formal store when it launches, returns to the foreground, or refreshes. When anonymous usage analytics is enabled, an extension may also write a bounded local activity record using fixed categories such as surface, feature, content type, result, and timing band. This record contains no saved content, keyboard text, search term, file name, target app, or account identifier. It is later read by a main app for aggregate analytics and is cleared when analytics is turned off.
- iCloud sync (optional feature): if you enable iCloud sync, KeyPaste uses Apple CloudKit / iCloud to sync eligible snippet data, Inbox entries, and managed attachments across devices signed into your Apple Account. This sync is provided by Apple. KeyPaste does not route that synced content through developer-operated servers. References to files that remain outside KeyPaste’s managed storage may be available only on the device that can access the original file.
3. Keyboard Extension and “Allow Full Access”
The KeyPaste keyboard extension can insert supported saved text into the current text field when you tap it.
If you enable Allow Full Access for the KeyPaste keyboard in iOS Settings, KeyPaste can also, when you actively use the related features or explicitly enable proactive clipboard capture:
- access the shared App Group container so the keyboard and main app can coordinate data more reliably;
- use the in-keyboard “Save to KeyPaste” flow to place accessible input context into the pending save queue;
- read supported system clipboard content when you explicitly choose the clipboard source, or when you enable automatic checking on keyboard activation; and
- provide haptic feedback based on your settings.
Even when Allow Full Access is enabled, KeyPaste does not upload your keystrokes, typed content, or clipboard content to developer-operated servers, and does not use that content for advertising, analytics, or tracking. If anonymous usage analytics is enabled, the keyboard may write only the fixed, content-free local activity categories described above; the keyboard itself does not send analytics over the network.
4. System Share Extension
When you intentionally choose KeyPaste from another app’s iOS share sheet, the share extension may read the text, image, file, or supported combination that you selected. It displays or validates the selected content and writes supported data into the shared queue for later import by a main app.
The share extension does not proactively inspect other apps. It processes only the items provided to it after you start a share action. The keyboard and share extensions do not initialize TelemetryDeck or RevenueCat, do not send analytics over the network, and do not upload the shared content to developer-operated servers. If anonymous usage analytics is enabled, the share extension may write only the fixed, content-free local activity categories described above for later processing by a main app.
5. Pro, In-App Purchases, and Apple Services
- StoreKit: KeyPaste uses Apple StoreKit for product loading, purchases, restore purchases, and purchase status validation. Payment information is handled by Apple. KeyPaste does not directly receive your payment card details or Apple Account password.
- RevenueCat: the iOS and macOS main apps use RevenueCat for anonymous purchase, restore, refund, and revocation records, closed product-state categories used to analyze those purchases, and Apple Search Ads standard attribution. StoreKit remains the only source KeyPaste uses to unlock Pro. KeyPaste does not send your saved content, keyboard input, contact details, advertising identifier (IDFA), or a custom account identifier to RevenueCat, and does not share a custom user identifier with TelemetryDeck. You can copy the anonymous purchase-record identifier from Settings and include it when you contact us.
- CloudKit / iCloud: if you enable sync, the sync service is provided by Apple and associated with your Apple Account.
- Vision / Core Spotlight: Pro image search uses Apple Vision for on-device text recognition and Apple Core Spotlight for system-provided indexing and concept matching. KeyPaste limits donated items to its own image-search domain and treats this system service as best effort.
- App Intents / Shortcuts / Siri: KeyPaste processes content from these features only when you actively configure and run those automations.
- TelemetryDeck: KeyPaste uses TelemetryDeck in the iOS and macOS main apps for the limited anonymous product analytics described above. KeyPaste does not send your name, email address, advertising identifier, custom account identifier, or user content to TelemetryDeck. Closed diagnostic identifiers and TelemetryDeck’s standard purchase fields may be included as described above. TelemetryDeck processes this data in the European Union under its own Privacy Policy.
- Websites and resource hosts for link previews: when the main app displays a preview for a public web link in your library or Inbox, a Home Screen widget shows a visible link card, or you long-press or use Space to peek at that link, your device connects directly to the destination website and may also connect to redirect destinations and page-referenced image, icon, media, script, or other subresource hosts. Their handling of normal web request data is governed by their own privacy practices. KeyPaste does not proxy these requests through a developer-operated server.
The keyboard and share extensions do not run TelemetryDeck or RevenueCat.
KeyPaste does not use advertising SDKs or cross-app tracking SDKs.
6. What We Do Not Do
KeyPaste currently does not:
- operate developer-hosted servers for storing your snippets or clipboard content;
- sell your data or share it with data brokers;
- use advertising identifiers for personalized advertising;
- include an app-owned image-search model or require a separate model download;
- perform cross-app or cross-website tracking; or
- use analytics for advertising, content profiling, or cross-app or cross-website tracking.
7. Data Retention, Deletion, and Your Controls
Unless you delete data, disable related features, or uninstall the app, KeyPaste keeps the data it processes as needed to provide the product, either locally on your device or, if enabled by you, in your iCloud container.
You can control your data in the following ways:
- Delete saved content: you can delete individual snippets and their KeyPaste-managed attachments inside the app. Deleting or replacing a saved web link also removes its local link-preview cache entry; resetting all app data clears the entire link-preview cache.
- Delete Inbox entries: you can delete individual Inbox entries, clear the Inbox, or save entries into your library and remove them from the Inbox.
- Remove derived image search data: deleting a source image removes its local derived search data and schedules deletion of its Core Spotlight item. Confirmed loss of Pro access schedules removal of the full KeyPaste image-search domain and local derived data without deleting your original saved content. System-index cleanup may complete later if Core Spotlight is temporarily unavailable.
- Turn off iCloud sync: you can disable iCloud sync in the app settings to stop future syncing through iCloud.
- Turn off keyboard full access: you can disable Allow Full Access for the KeyPaste keyboard in iOS Settings to stop in-keyboard saving, clipboard reading, and related shared-container writes from the keyboard.
- Turn off proactive clipboard capture: you can disable proactive clipboard capture in the app settings at any time to stop automatic clipboard checks.
- Turn off anonymous usage analytics: anonymous product analytics is enabled by default. You can turn it off in KeyPaste Settings on iOS or macOS. This stops new TelemetryDeck product events while the setting remains off. Data already received may be retained under TelemetryDeck’s policy. The setting does not stop StoreKit or RevenueCat purchase records needed for paid-feature functionality, restores, refunds, and revocations.
- Stop using optional entry points: if you no longer use the share extension, keyboard save flow, Shortcuts, or Siri actions, KeyPaste will no longer process new content through those entry points.
- Uninstall the app: uninstalling the app removes local app data. Files managed by another app or by Finder remain under that system location’s controls. If you previously enabled iCloud, retention and deletion of synced data also depend on your Apple Account and iCloud state.
Anonymous purchase records processed by RevenueCat, including closed product-state categories and any Apple Search Ads attribution Apple provides, may be retained for purchase analytics, restore/support operations, fraud prevention, and refund or revocation handling according to RevenueCat’s service and retention policies. To request help identifying or deleting an anonymous purchase record, copy the Purchase Record ID from KeyPaste Settings or contact us using the address below. Deleting a RevenueCat record does not cancel or revoke the underlying Apple purchase.
If you would like more information about deletion paths or need help understanding what data can be removed in the current version, please contact us at [email protected].
8. Children and Third-Party Services
KeyPaste does not target children with advertising and does not integrate third-party ad networks. If you are a minor, please use the app and related system features under the guidance of a parent or guardian.
KeyPaste relies on Apple-provided platform services such as iCloud, CloudKit, StoreKit, Vision, Core Spotlight, Shortcuts, and Siri, uses RevenueCat for the limited anonymous purchase processing described above, and uses TelemetryDeck for the limited anonymous product analytics described above. When you save a public web link and view it in a supported card layout, your device may also contact that destination website, redirect destinations, and page-referenced resource hosts as described above. Your use of those services and websites is also subject to their own terms and privacy policies.
9. Contact
If you have any questions about this Privacy Policy or how KeyPaste handles data, please contact us at [email protected].