English
How we handle your information
Privacy Policy
Published and effective: September 21, 2026 · Version 1.1
Wonhyuk Choi (the “Operator”) explains below how personal information is processed in the typik app and keyboard service. This policy covers the iOS, iPadOS and Android apps and their connected AI, place search, and usage and reward features.
The short version
- We don’t continuously send your everyday keystrokes to a server.
- AI features run only after a user aged 18 or older agrees to the data transfer. The text to process and your options are sent to the typik server and Google Gemini. Place search terms are also sent to Kakao.
- We don’t store the original AI inputs or responses in typik’s database or application logs. Outside providers have their own retention terms.
- We do process usage and reward records and ad SDK data. Deleting the app or using “Reset storage” does not by itself delete your balance or reward records on the server.
1. Operator and privacy contact
- Operator and privacy officer
- Wonhyuk Choi
- Service
- typik · com.roome.typik
- Contact email
- whchoi000@gmail.com
Requests to access, correct, delete or suspend the processing of your personal information, and other questions about the service, can be sent to the email address above.
2. Information we process and why
typik doesn’t require you to sign up. We process the information below when you run a feature yourself, or when the app, server or ad SDK provides the service. Even without an account, we use identifiers to keep usage and reward wallets separate for each device.
| Category | Information processed | Purpose and location |
|---|---|---|
| AI writing | The selected text; depending on the feature, the text before the cursor, the current line, or clipboard content chosen for summarizing; options; persona definitions and examples; generated results | Polishing, tone rewrites, summaries and interpreting place requests. Processed by the AI provider via the typik server |
| Place and route search | Search terms extracted from your input; place names, addresses and coordinates of origins and destinations; mode of travel | Kakao place search and route lookup. The device’s GPS location is not collected |
| Usage and rewards | Hash of the app-scoped device identifier (Android), server device ID, auth token, daily token and run counts, cumulative usage, bonus balance, invite codes and relationships, reward grant times, transaction IDs and duplicate-grant prevention records | Usage limits, balance recovery, invite and ad reward grants, abuse prevention. On the device and the typik server |
| Operations and security | Request IP, connection and request information, feature and model type, input and output length and token counts, processing time, success, failure and error type, administrator grant history | Providing the service, diagnosing failures, rate limiting, verifying rewards. Server and infrastructure providers |
| Advertising | IP address and approximate location derived from it, device and advertising identifiers, app and ad interactions, diagnostic and ad performance information, wallet identifier for reward verification | Serving, measuring and analyzing AdMob ads, fraud prevention, reward verification. Google’s ad SDK and servers |
| On-device features | Key assignments, settings and skins, snippets, personas, clipboard history, the last content sent to AI | Providing the keyboard and local tools. The full history is not automatically uploaded to the app server |
| Email inquiries | Reply email address, the content of your inquiry and any files you attach | Responding to inquiries, verifying your identity and the scope of your request, handling requests to exercise your rights |
We don’t automatically send your full clipboard history or snippet list. If you choose part of it as the target of an AI feature, however, that content is sent. Don’t put sensitive information such as resident registration numbers, passwords, or financial or health information, or other people’s personal information without their consent, into AI input.
3. Outside services and processing outside Korea
To the extent needed to provide features, we use the infrastructure, APIs and SDKs of the companies below. Information is sent over the network when you run a feature or connect to the service. Processing by overseas companies may involve transfer and storage outside the Republic of Korea.
- Cloudflare, Inc. — server and storage infrastructure
Relays AI requests, stores per-device usage and rewards, and handles connection security and operational logs. We use the global infrastructure of this U.S. company, and API execution is configured to run in the Tokyo, Japan region. This setting does not guarantee that all logs and stored data are kept only in Japan. Cloudflare Privacy Policy
- Google — Gemini API
Processes the text, options and personas sent for AI processing, and the results. Processing may take place in the United States or other countries where Google or its subprocessors have facilities. Google states that it retains inputs, context and outputs for 55 days to detect abuse and for security, and that flagged content may be reviewed by authorized personnel. Google’s terms for paid services state that inputs and responses are not used to improve its products, while its terms for unpaid services allow product improvement and human review. Which terms apply depends on the billing and data settings of the connected project and the relevant terms. The typik Operator does not collect original AI text to train its own models. Gemini API Terms · Abuse monitoring and retention
- Google — AdMob
The ad SDK in the host app processes advertising and device identifiers, IP address, interactions and diagnostic information. The iOS keyboard extension does not include the ad SDK. Google’s global processing facilities, including in the United States, and its service policies apply. Text you send to AI is not provided as content for ad requests. Google Privacy Policy · How Google uses information from apps that use its services
- Kakao Corp. and Kakao Mobility Corp. — places and routes
Search terms, origins and destinations, and the coordinates needed for lookups are sent to the APIs of these Korean companies. The coordinates are those of the places searched for, not your device’s current location. When you open a Kakao Map link, that service’s policies apply. Kakao Privacy Policy · Kakao Mobility Privacy Policy
- Apple and Google — OS backup and restore
Depending on your device settings, the auth token may be stored and synced in iCloud Keychain on iOS or Google Block Store on Android. On Android, cloud backup is requested when end-to-end encrypted backup is available. The location, retention and deletion of backed-up information are governed by the relevant account and OS settings. Apple Privacy Policy · Google Privacy Policy
Questions about outside processing can be sent to the Operator’s email, and each company’s privacy contact can be found in the policies above. If you don’t run AI or place search, you avoid sending text or search terms for those features. Basic typing and local tools such as the calculator and snippets work without connecting to those APIs. The ad SDK may also process information while the app starts up and when ads are requested, so not watching an ad does not by itself mean that nothing is collected.
4. Retention and deletion
- Original AI inputs and outputs: The typik server uses them to process your request and does not permanently store them in a database or application logs. Retention by outside AI providers follows Section 3 and that provider’s terms.
- On-device data: Kept until you delete those records or reset local storage. The last content sent can be deleted separately with “Clear record.” Data remaining in OS backups and the keychain may persist depending on your device and account backup settings.
- Usage and reward information: Kept on the server for as long as needed to recover balances, manage usage and prevent duplicate rewards. Current balances, invite relationships and duplicate-grant prevention records have no automatic expiry. Daily usage is refreshed the next time you use the service, and the 50 most recent administrator grants are kept.
- Operational logs: Performance, error and reward-result metadata are kept in Cloudflare Workers Logs for up to 7 days (3 days on the free plan, 7 days on the paid plan). Automatic request logging is turned off, and original AI inputs and responses, auth tokens and deletion verification codes are not written to application logs.
- Advertising and OS backups: Follow the relevant provider’s retention policies and your ad and backup settings. Deletion on the typik server and deletion by outside providers are not the same process.
- Inquiries: Used to respond to and follow up on your inquiry, and deleted within 90 days after it is closed. If we need to keep them because of a legal retention obligation or a dispute, we will tell you the basis and the period separately. Deletion verification codes are removed from support records once the request is handled.
“Reset storage” in the app and deleting the app are not requests to delete your server wallet or reward history. In the app, under Data & privacy → Prepare a server data deletion request, you can get a verification code that is valid for 7 days. Creating a verification code does not by itself submit a deletion request. To have your server data deleted, email whchoi000@gmail.com with the verification code. After confirming what the request covers and that you are entitled to make it, we will complete it or tell you the reason for any delay within 7 days. We delete the requesting wallet’s balance, usage and reward history and its invite code links. To prevent fraudulent re-grants, we keep only the deletion time and the wallet’s restricted status for 90 days, after which they are deleted automatically. The deleted wallet cannot be reused, but if you keep using the app, a new anonymous wallet with no balance or history is created so you can use the AI and reward features. Invite relationships and duplicate-reward prevention records in other users’ wallets may remain separately to keep those users’ rewards consistent, and records held by outside providers and OS backups follow those providers’ procedures. Don’t send auth tokens, administrator keys or passwords by email.
Information that is no longer needed for its purpose, or that must be destroyed following a lawful deletion request, is deleted in a way that makes it hard to recover. If we need to keep it to comply with the law or resolve a dispute, we will confirm and tell you the reason and scope.
5. Your choices and rights
- You run AI features yourself. You can check what will be sent and “Last sent content.”
- On iOS, turning off Allow Full Access for the typik keyboard in Settings limits the keyboard’s online AI features. The app and the keyboard can be configured separately.
- To stop using the keyboard, you can remove typik in your OS keyboard settings or delete the app.
- You can withdraw your consent to AI data transfer under Data & privacy in the app. After withdrawing, you’ll need to agree again before running AI, and you can keep using the basic keyboard.
- In regions where ad privacy choices must be offered, the app provides that menu under Data & privacy. On iOS, the app asks whether to allow tracking before requesting ads, and if you don’t allow it, it doesn’t request personalized ads using the advertising identifier. Basic typing, AI and rewarded ads don’t require you to allow tracking.
- You can delete or reset your advertising identifier and manage choices about personalized ads and app tracking in the ad and privacy settings of your device and your Google or Apple account. Menus and effects vary by operating system.
- Requests to access, correct, delete or suspend the processing of your personal information are received at the Operator’s email. We may ask for the minimum information needed to confirm that you are the user or their legitimate representative.
If you learn that someone else’s or a child’s personal information was sent against their wishes, please let us know at the contact above. We will review the request and tell you what steps are needed under the applicable laws. You can also use the same contact to report AI results that expose personal information or contain inappropriate content.
For advice on or reports of privacy violations, you can contact the Personal Information Infringement Report Center, and for dispute mediation, the Personal Information Dispute Mediation Committee (both in Korea).
6. Security measures
Communication between the app and the API uses HTTPS. Auth tokens are protected with the iOS Keychain or Android Keystore, and no server secret keys are included in the app. We apply server request authentication, usage limits, signature verification for ad rewards and duplicate-grant prevention, and operational logs are set up so that they don’t record original AI inputs or responses.
7. Changes and contact
If the information processed, the outside providers, retention, or the way you exercise your rights changes, we will update the policy and its effective date on this page. We will announce significant changes in a way you can see, such as a notice in the app, and follow any required procedure where the law calls for separate consent.
First effective: September 21, 2026
Privacy contact: whchoi000@gmail.com