Privacy Policy

This policy states what actually holds: which data leaves your device and when, who processes it, how long it is kept, and how you delete it.

Effective 2026-09-16Last updated 2026-09-16Applies to Faspond for iOS 1.0.4

1. What this policy covers

This policy applies to the Faspond iOS app (com.astrazenith.faspond), its keyboard extension (com.astrazenith.faspond.keyboard), the Faspond server services behind them, and this website.

Faspond is a cloud product: when you tap AI, text leaves your device and is handled by our services and by a model provider. The point of this document is to say exactly which text, at which moment, and to whom — including the things we deliberately do not do.

2. Who we are

Faspond is built and operated by astraZenith, which is the data controller for the processing described here.

Contact: astrazenith.ent@gmail.com. Privacy questions reach us fastest with “Privacy” in the subject line.

3. At a glance: what leaves your device

This table is the whole list. If something is not on it, it does not leave.

DataWhenGoes toStored?
The message you pasted into the keyboardThe tap on AIFaspond AI service → OpenRouter → the model providerNot stored, not logged
The draft you asked it to tidyThe tap on AISameNot stored, not logged
The knowledge card being citedThe tap on AISameAlready yours, in your account
Your tone settingThe tap on AISameAlready yours, in your account
A screenshot you pickedYou chose it in the appFaspond AI service → the model providerThe picture is discarded; a hash and the extracted text are kept
The text of a reply you sentOnly with writing-style learning onFaspond (Django)Becomes numbers in the account; no text column exists
Latency, error codes, request idsEvery AI requestFaspondYes, without any content
The keyboard appearing, typing, deleting, pressing return and switching to the next keyboard send nothing. Every row above is triggered by a named button you pressed.

4. What we collect, and why

4.1 Account data

AI features need an account. Identity is handled by Firebase Authentication (Google LLC); you can sign in with Apple, Google or email. From the identity provider we receive and store:

  • your email address
  • a display name, if the provider supplies one
  • an avatar URL, if the provider supplies one
  • an account identifier that everything else hangs off

We do not have your password. Faspond has no password system of its own; if you sign in with email, the password is held by Firebase.

4.2 What you put into Faspond

  • Knowledge cards — the passages and question-and-answer pairs you write, stored in your account.
  • Tone settings — the tone you picked, or the wording you wrote yourself.
  • Screenshot extractions — a screenshot you pick is downscaled and stripped of EXIF on the device before it is sent. Once the model has read it, the picture itself is not kept: what is kept is a SHA-256 hash (so the same screenshot is not imported twice) and the extracted text.

4.3 The clipboard library — not on this list

The contents of your clipboard library (addresses, account numbers, tax ids) are encrypted in this device’s Keychain and are never uploaded to a Faspond server. They do not sync between devices, and they do not follow you to a new phone. That is a deliberate trade.

4.4 Usage and diagnostics

One row per account per day holds counts: requests, words, tokens, errors. It runs quotas and finds faults, and contains no message content.

Server logs are keyed by request id and record the mode, the model used, timings and error codes. Message text, pasted text and generated text are not log fields.

5. What we do not collect

These are worth naming, because they are exactly what anyone should be suspicious of in a third-party keyboard:

DataWhy it is checkable
Microphone audioNo microphone purpose string, no audio framework and no speech-recognition provider code in either bundle
Text around your caretNo shipping client populates those fields; the keyboard sends the message you pasted and the draft you are writing, nothing else
Which app you are typing inThe source-app identifier is never filled in
Your system clipboardRead once, when you tap Paste. No polling, no caching
Location, contacts, health, financial dataNo such permission string, framework or data column exists
Advertising identifier (IDFA), trackingNo ad SDK, no App Tracking Transparency prompt, and tracking is declared false in both privacy manifests
Crash and performance reportingNo crash reporter and no analytics SDK is in the bundle

We do not track you for any purpose, and we do not combine your data with third-party data for advertising or measurement.

6. The keyboard extension

iOS puts an “Allow Full Access” switch in front of every third-party keyboard. Only with it can an extension open a network connection or read data shared with its containing app. Faspond needs it to call the AI service and to read your knowledge base and clipboard library.

Without Full Access, Faspond is still a working keyboard: the zhuyin, English and number layouts, the candidate row and the space-bar trackpad all work, and none of it makes a network request.

With Full Access granted, what you type is still not sent. Sending happens on the tap of AI, and its scope is the table in section 3.

7. AI processing and model providers

Faspond does not train models. When you tap AI, the content takes this path:

your device → the Faspond AI service → OpenRouter (model gateway) → the provider of the model chosen for that request (Anthropic, Google or OpenAI).

The AI processing disclosure inside the app lists the providers a request may currently be routed to. It is rendered from a versioned file; when that file changes, you are asked to agree again.

We make no promise about a provider’s own retention or training policy. What we can state is our own system: message content is not stored in a Faspond database and is not written to a Faspond log. How a provider handles what passes through it is governed by that provider’s published terms. A guarantee we cannot verify would be worse than none.

8. Two separate consents

ConsentDefaultWhat it covers
AI processingNot grantedSending the message you pasted, your draft and the cited card to a model, in exchange for a reply
Writing-style learningOffLearning how you write from replies you sent, so later replies sound like you

They are deliberately separate: agreeing to have one message answered is not agreeing to be studied. Both can be changed at any time under Settings › AI & Data, and withdrawing does not undo processing that already completed.

The AI consent is enforced on the server. Without it the request is refused — not merely hidden in the interface.

9. Who we share with

We do not sell personal data and we do not share it for advertising. These services process some of it so the product can work:

ServiceWhat it handles
Google LLC — Firebase AuthenticationIdentity: email, display name, account identifier
Google LLC — Google Sign-In (only if you use it)Per Google’s own privacy manifest, that SDK also collects data including a device identifier
Apple Inc. — Sign in with Apple (only if you use it)Identity; you may choose to hide your email address
OpenRouterGateway for AI requests, forwarding them to one of the providers below
Anthropic, Google, OpenAIThe model providers that generate the reply
ZeaburCloud infrastructure hosting the Faspond services, database and cache

We may have to disclose data when the law requires it, for example under valid legal process. Where we are permitted to tell you, we will.

10. International transfers

The services above may process data outside your country. By using Faspond you understand that content you send by tapping AI may be transferred to another country for processing.

11. How long we keep things

  • Message content and drafts: not kept. They do not exist in Faspond’s systems once the request completes.
  • Knowledge cards, tone settings, account data: until you delete them, or delete the account.
  • Screenshots: the image is not kept; the hash and extracted text are deleted with the card they belong to.
  • Writing-style data: held as numbers, deleted when you turn learning off or delete the account.
  • Usage counts and server logs: kept no longer than operations and security require. They hold no message content; write to us for the current retention setting.
  • Database backups: after deletion, data may persist briefly in routine backups until that backup rotates out.

12. Your rights

Depending on where you live you may have the rights below. We honour them regardless of whether the law requires it:

  • Access — find out what we hold about you.
  • Correction — cards, tones and your account name are editable in the app.
  • Deletion — see section 13; you can do it yourself in the app.
  • Withdrawing consent — AI processing and writing-style learning can be switched off at any time.
  • A copy of your data — write to us and we will send a copy of your account contents.

To exercise any of these, write to astrazenith.ent@gmail.com. So that we do not hand your data to somebody else, we will first confirm the request comes from the account holder.

13. Deleting your account

In the app: Settings › Data & Account › Delete Account. It deletes your account, knowledge cards, tone settings, writing-style data and usage records. For accounts created with Apple, the Sign in with Apple grant is revoked at the same time.

Clipboard library contents were never on a server; removing the app removes them. Full steps and alternatives are on the account deletion page.

14. Children

Faspond is a tool for people running a business. It is not designed for children and we do not knowingly collect data from them. If you believe a child has given us personal data without consent, write to us and we will delete it.

15. Security

  • Every connection between device and server uses HTTPS; the app’s transport security settings do not permit arbitrary cleartext loads.
  • Clipboard library contents live in the device Keychain and never leave the phone.
  • Every API request is authenticated and can only reach the data belonging to that account.
  • No permanent model-provider or identity-provider secret is shipped inside the app or its bundled resources.

No system is perfectly secure, and we will not claim otherwise.

16. Changes to this policy

When this policy changes we update the dates at the top of this page. If the change affects what leaves your device, the in-app AI processing disclosure is versioned up too and you are asked to agree again.

17. Contact us

astraZenith
Privacy and data: astrazenith.ent@gmail.com
Product support: Support centre