Privacy Policy
Last updated: 30 July 2026
Short version: your bindings and your clips are on your phone. Only on your phone. We don't have them. Not “we promise not to look” — there is no Shortiz server holding them, and no cloud account they sync to, so there is nothing anywhere to look at.
The long version follows, because a keyboard asking for Full Access owes you the long version.
Who this covers
This policy covers the Shortiz iOS app and the Shortiz keyboard extension. Data collected by the shortiz.app website is covered separately in the Website section at the end — different system, different rules.
What Shortiz stores, and where
| Data | Where it lives | Who can read it |
|---|---|---|
| Bindings | Your device, in a shared container the app and keyboard both use. Nowhere else. | You |
| Clips (text + images) | Same. | You |
| Keystrokes | Nowhere. Processed to type the character, then gone. | Nobody |
That table is the whole dataset. There is no fourth row.
No Shortiz servers. We do not operate a server that stores bindings, clips, or anything else the keyboard sees. This isn't a policy choice we could quietly reverse — it's the architecture. If that ever changes, it changes in a released version with this policy updated first.
No sync, no cloud, in this version. Shortiz 1.0 does not sync anything anywhere. There is no iCloud storage, no account, and no cross-device transfer — your bindings and clips exist on the one phone you made them on. If a future version adds sync, it will be opt-in and this policy will be updated before that version ships.
The honest trade: nothing leaves your phone, so nothing follows you to a new one. Delete the app and your bindings go with it.
What we do not do
- No analytics in the keyboard. The Shortiz keyboard extension — the part that sees your typing — contains no analytics, advertising, attribution, or crash-reporting SDK. Zero events leave it.
- No keystroke logging. Keystrokes are typed, not stored, not transmitted, not counted.
- No tracking. No advertising identifier, no cross-app or cross-site tracking, no ad networks, no data brokers. Shortiz shows no App Tracking Transparency prompt because there is nothing to ask for.
- No account. Shortiz has no sign-up, no login, and no user identifier. We could not link data to you if we had any, because we don't know who you are.
- No selling, no sharing. There is nothing on our side to sell or share.
- No AI. Nothing you type or copy is sent to any model, ours or anyone else's. Shortiz remembers what you bound and what you copied and types it back. That is the entire mechanism.
Full Access — what it's for
iOS asks you to grant Allow Full Access before any keyboard can read the system clipboard. The warning iOS shows is generic: it describes what the permission could let any keyboard do, not what Shortiz does.
Shortiz uses it for exactly one thing: reading your clipboard into the tray. Nothing else.
- Full Access off: typing works, bindings work, long-press expansion works. The clipboard tray is unavailable.
- Full Access on: the tray works. Nothing else changes.
You can turn it off at any time in Settings → General → Keyboard → Keyboards → Shortiz, and keep using bindings.
One honest limitation while we're here: iOS does not permit any keyboard to monitor the clipboard in the background. Shortiz reads the clipboard only when the keyboard opens or when the Shortiz app comes to the foreground. Things you copy in between were never visible to it.
Deleting your data
- A binding or a clip: delete it in the app. It's gone.
- Everything: delete the Shortiz app. All of it goes with the app — there is no second copy in a cloud account to hunt down afterwards, because there was never a first one.
Because we hold no copy, there is no request to send us and no waiting period. There is also nothing for us to delete on your behalf — which is the point.
Your rights (GDPR, UK GDPR, CCPA/CPRA)
Rights of access, portability, correction, erasure, restriction, objection, and non-discrimination apply to personal data a company holds about you. For the Shortiz app, we hold none — so these rights are satisfied in the strongest available way: there is no processing to object to, no profile to access, and nothing to erase. Your data is already in your hands, on your device.
We do not sell or share personal information, and never have. There is no “Do Not Sell or Share My Personal Information” flow because there is nothing that could trigger one.
If you believe we hold data about you and this is wrong, write to us at the address below and we will look. You also have the right to complain to your local data protection authority.
Children
Shortiz is rated 4+ and collects no data from anyone, of any age. We do not knowingly collect personal information from children because we do not collect personal information at all.
Website (shortiz.app)
The Shortiz website is separate from the app and is the only place any data is collected:
- Analytics. The site can run product analytics (PostHog and Microsoft Clarity). They stay off until you accept the consent banner, and you can withdraw consent at any time by clearing your choice in the banner. Declining changes nothing about how the site works.
- The app and keyboard run neither of these. Website analytics never touch app data — the two don't connect, and there's no identifier that could connect them.
Changes to this policy
If this policy changes materially — in particular, if Shortiz ever starts transmitting data off your device — we will update this page and the “Last updated” date, and describe the change in the app's release notes for the version that introduces it. Policy first, then the code.
Contact
Questions, requests, or a security issue: [email protected]