Privacy Policy — Rewordo
Effective date: 2026-07-10 Last updated: 2026-07-28
Rewordo ("Rewordo", "we", "us") is an iOS keyboard and app that rewrites, fixes, translates and chats about your text using AI. This policy explains what we do — and mostly do not — with your data. It is written to reflect how the app actually works.
Summary (TL;DR)
- No account. The app doesn't ask for your name, email, or a login. (The one exception is our website waitlist — if you choose to join it, you give us your email; see §6.)
- We don't store the text you write. Your message is sent to an AI provider to perform the action you asked for and returned to you; we don't keep it.
- Your API key is protected. If you use your own key, it is encrypted on your device and only used in memory to make the request — never stored on our servers in readable form.
- No ads, no selling of data.
- We keep anonymous usage counts (e.g. how many rephrase/translate requests) to run and improve the service — never the content of your messages.
Who is responsible
The data controller is Martin Nohejl, a sole trader (IČO 74765086, VAT CZ8902233967), Benátecká Vrutice 155, 289 23 Milovice, Czech Republic. Contact: support.rewordo@gmail.com.
What data we process
1. The text you submit to an AI action
When you use an action (rephrase, fix, expand, concise, translate, chat, or a Share action), the relevant text is sent — over an encrypted connection — through our backend to the AI provider (currently Anthropic) to produce the result. We process this text transiently and only to fulfil your request; we do not store it and do not use it to train models. The AI provider processes it under its own privacy terms (see "Third parties").
2. Your AI provider API key (BYOK)
If you provide your own API key ("Bring Your Own Key"):
- it is stored only in the iOS Keychain on your device (shared with the keyboard), never in plain preferences;
- when a request is made, the key is encrypted on your device (envelope encryption) before it leaves the app, decrypted only in memory on our backend to call the provider, and then discarded. We do not persist your BYOK key on our servers and do not log it.
If you don't provide a key, requests use a managed key operated by us; usage is metered per installation against a monthly limit.
3. Anonymous device / installation identity
To stop abuse of our backend without creating an account, we use Apple App Attest, which gives us an opaque, anonymous installation identifier. It is not linked to your Apple ID, name, or email and cannot identify you personally.
4. Anonymous usage analytics
We record, per anonymous installation, metadata about requests — which feature was used, the AI model, token counts, success/failure, and timing. This never includes the content of your messages. We use it to operate the service, prevent abuse, understand which features are used, and plan pricing.
5. Data stored locally on your device
Your settings and chat history are stored on your device (in the app's shared container). They are not uploaded to us. Deleting the app removes them.
6. Waitlist email (marketing website only)
If you enter your email address in the "notify me at launch" form on our website, we store that address for a single purpose: to email you when Rewordo is released. This is optional, separate from the app, and based on your consent. To stop the form being abused by bots we use Cloudflare Turnstile (a privacy-friendly CAPTCHA). We do not use your email for anything else, and we do not share or sell it. You can ask us to delete it at any time at support.rewordo@gmail.com (or use the unsubscribe link once launch emails start).
What we do NOT collect
No account credentials, no contacts, no location, no advertising identifiers, and no keystroke logging — the keyboard only reads text when you explicitly trigger an action.
Third parties (processors)
- Anthropic — the AI provider that processes your submitted text. See Anthropic's privacy policy: https://www.anthropic.com/legal/privacy.
- Infrastructure — our backend runs on Google Cloud (Cloud Run); the database on Neon (PostgreSQL); caching on Upstash (Redis). These providers host data on our behalf in the European Union (Google Cloud region europe-west1) and act as processors.
- Cloudflare — provides Turnstile, the anti-bot check on our website's waitlist form. See Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/.
We do not sell your data or share it for advertising.
International data transfers
Requests to the AI provider may be processed in the United States. Where transfers occur, they rely on the provider's applicable safeguards (e.g. Standard Contractual Clauses).
Data retention
- Text you submit: not retained by us (transient).
- BYOK key: kept in your device Keychain until you delete it; not retained on our servers.
- Anonymous usage analytics: retained for 12 months, then deleted or aggregated.
- Waitlist email (website): kept until launch, or until you unsubscribe or ask us to delete it — whichever comes first.
Security
Encrypted transport (TLS); BYOK keys envelope-encrypted in transit and never stored in readable form; App Attest to verify genuine app installs; managed keys and secrets held in a secrets manager, not in code.
Your rights
Apart from a waitlist email (if you gave us one), we hold no personal identifiers, so we generally cannot link data to you. Where applicable law (e.g. GDPR/UK GDPR, CCPA) grants rights (access, deletion, objection), contact support.rewordo@gmail.com. You can delete all local data at any time by removing the app.
Children
Rewordo is not directed to children under 16 and we do not knowingly collect their data.
Changes
We may update this policy; the "Last updated" date will change and material changes will be noted in the app or on this page.
Contact
Martin Nohejl (IČO 74765086) — support.rewordo@gmail.com — Benátecká Vrutice 155, 289 23 Milovice, Czech Republic