Is Keyda Safe to Use as Your Keyboard? Privacy, Encryption and Data Controls Explained
A clear look at how Keyda handles your typing data: BYOK key encryption, voice recording policy, data deletion on sign-out and what stays on-device.
Giving a third-party keyboard access to everything you type is a reasonable thing to be cautious about. Keyboards see messages, passwords fields aside, notes, searches and drafts across every app on your phone. Before installing one, it is fair to ask exactly what happens to that data.
This post walks through what Keyda actually does with your typing data, voice recordings and provider keys, based on how the app is documented to work.
The short version
Keyda encrypts stored BYOK provider keys with AES-256-GCM, does not store raw voice audio, lets you keep AI processing on-device when you choose that route, and deletes your data when you sign out. Cloud AI requests are sent to whichever route you pick: Keyda's managed pool, your own BYOK provider, or an on-device model that never leaves the phone.
How your BYOK provider key is protected
If you connect your own AI provider key (OpenAI, Claude, Gemini, Groq or xAI), that key is encrypted at rest with AES-256-GCM on Keyda's servers and scoped to your user account. It is only used to contact your configured provider on your behalf. You can rotate or delete a stored key at any time from Settings, and if a key is rejected by the provider, Keyda does not retain or silently retry the failed call.
What happens to your voice
Because Apple does not allow third-party keyboards to access the microphone directly, voice typing briefly opens the Keyda app to record and transcribe speech before handing the finished text back to wherever you were typing. That transcription happens through Apple's Speech Recognition during the active recording.
Keyda does not store the raw audio. The resulting transcript stays in your private on-device history, and syncing that history to your Keyda account is disabled by default, meaning you have to opt in before any transcript leaves your device.
On-device processing as a privacy option
Keyda's on-device models, Gemma 3n and Gemma 3 1B, run entirely on your phone. Requests handled this way do not require an internet connection and do not get sent to a cloud provider at all. This is the most private route available in Keyda, and it is worth choosing deliberately for sensitive notes, private drafts or anything you would not want processed by an external server.
Typing, themes, snippets, notes and voice typing all continue to work offline through on-device processing, even without a connection, though voice recognition accuracy is somewhat better when Apple's stronger online model is available.
What happens when Keyda reads a web link
If you paste a link and ask Keyda about it, the app's server fetches that public page, extracts its text and passes it to the AI model handling the request. This feature is on by default but can be turned off in Settings if you would rather Keyda never fetch external pages on your behalf.
Data deletion on sign-out
Signing out of your Keyda account triggers deletion of your account-linked data. Combined with voice transcripts staying local by default, this gives you a reasonably clear boundary: data you have not explicitly synced tends to stay on your device, and signing out clears what was tied to your account.
Who sees your cloud AI requests
Where a request goes depends entirely on which AI route handled it:
- Keyda AI (managed): the request goes through Keyda's backend to one of its supported cloud providers.
- BYOK: the request goes directly to the provider tied to your own key, using your account and billing relationship with that provider.
- On-device: the request never leaves your phone.
Knowing which route you are using for a given request is the most direct way to reason about where that text is actually going. Our on-device AI, BYOK and Keyda AI guide covers how to choose between the three.
A practical privacy checklist
| Question | What to do |
|---|---|
| Is this text sensitive? | Use an on-device model instead of a cloud route |
| Do I want link-reading off by default? | Disable it in Settings |
| Do I want voice history to stay local? | Leave account sync off (the default) |
| Am I switching devices or accounts? | Sign out to clear account-linked data |
| Did I paste a provider key that no longer works? | Rotate or delete it from Settings |
Why this matters more for a keyboard than a typical app
A keyboard is not one app among many; it is the surface every other app types through. That makes clear, controllable privacy behavior more important here than it would be for a single-purpose app, since the same keyboard is present for banking app searches, private messages and public social posts alike. Keyda's design, splitting data handling by route (on-device, BYOK, managed) rather than treating every keystroke identically, is meant to give you a way to match the privacy level to the moment.
Final thought
No app can promise perfect privacy, and the honest answer is that any cloud AI route involves sending text to a third-party model provider. What you can reasonably expect from Keyda is transparency about which route handles a given request, encryption for stored provider keys, no raw audio storage, and a genuine offline, on-device path for anything you would rather keep off the cloud entirely.
Privacy on a keyboard is not one setting. It is a series of small choices about which route handles which request.