Privacy Policy, Clex Keyboard for Android (archived 2026-08-07 version)
The privacy policy for Clex Keyboard on Android: what stays on your device, what leaves it, and what happens to it afterwards.
Archived version. This is the privacy policy for Clex Keyboard for Android that applied from 7 August 2026 until 18 August 2026. It is kept for reference and is no longer in force. The current policy is at clex.ai/en/legal/privacy-policy-android/.
Effective date: 7 August 2026
This policy covers Clex Keyboard for Android. The other Clex products, and the Clex website, are covered by the general Clex privacy policy. Where the two describe Android behaviour differently, this one is the accurate document.
At a Glance
| Question | Answer |
|---|---|
| Does Clex see what I type? | No. Free text never leaves the device, and no Clex server can receive it. |
| Does Clex see what is read aloud from my screen? | No. Read Aloud makes no network request at all. |
| Does Clex hear what I dictate? | No. Speech is transcribed on the device and the audio is never stored or sent. |
| What does leave the device? | A licence check, requests for model files, and a daily count of feature use. Section 4 lists every field. |
| Can a usage report be traced to me? | No. Reports carry no identifier for you or your device, and a report stops existing when it arrives: its numbers are added into a total for your whole organisation. |
| Can I switch the counting off? | Yes, in the app’s settings, at any time, without asking us. |
| Where is the data processed? | On servers in Germany, inside the EU. |
1. Who We Are
This Privacy Policy is issued by Clex A/S, a Danish corporation (CVR 37750840) with registered address at Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark. For the Swedish market, Clex Sweden AB (org.nr 559544-8001) is the contracting party.
Clex develops language-technology writing support for the care sector. This policy describes how we handle information when you use Clex Keyboard for Android.
| Field | Details |
|---|---|
| Legal name | Clex A/S |
| Country | Denmark (EU) |
| CVR | 37750840 |
| Website | clex.ai |
| Data-protection contact | Uffe Gorm Pal Hansen - Email us |
| General contact | Email us |
Clex A/S is the data controller for the data described in section 4. The organisation that deployed Clex to you (municipality, care provider, or employer) remains the controller for the records its staff write in its own systems. We never receive those records.
2. Scope
This policy covers Clex Keyboard for Android, distributed through Google Play and through managed device deployment. The other Clex products, and the Clex website, are covered by the general Clex privacy policy on clex.ai. Where the two documents describe Android behaviour differently, this one is the accurate document.
The app is designed for professional care workers who document care activities within their organization’s electronic health record (EHR/EOJ) systems.
3. Our Approach to Privacy
Clex Keyboard is built on a local-first, privacy-by-design architecture:
- The free text you write stays on your device. It is not sent to us, and we cannot read it.
- Word prediction, auto-correction, sentence correction, live translation, speech to text and read aloud all run on the device, using models stored in the app.
- What does leave the device is a licence check, a set of usage measurements, and requests for model files. Section 4 lists every field.
- No keystrokes are logged, monitored, or transmitted at any point.
The usage measurements are daily counts of feature use. They carry no identifier for you or your device, and you can switch them off in the app’s settings. Sections 4.2 and 4.3 describe the whole report and what becomes of it.
About the keyboard access warning. When you enable Clex Keyboard, Android displays a standard warning that the keyboard may be able to collect everything you type, including passwords and credit card numbers. This warning is shown for all third-party keyboards and is not specific to Clex. Clex Keyboard does not collect, store or transmit the text you type. Section 4 lists everything the app does send, and section 5 lists what it never sends.
3.1 Who Clex Keyboard Is For
Clex Keyboard is a reading and writing aid for care workers, and in particular for those who are dyslexic, who find reading and writing difficult, or who have low vision. Read Aloud is registered with Google as an accessibility tool, and Android’s Accessibility settings say the same thing.
Each feature answers a particular difficulty:
| Feature | What it is for |
|---|---|
| Read Aloud, section 7 | Reading on screen. Text in any app is spoken instead of read. |
| Word prediction and auto-correction | Spelling. The next word is offered, so it does not have to be spelled out. |
| Sentence correction | Writing. Checks spelling and grammar in text you have already written and rewrites it, and shows you each change before you accept it. |
| Speech to text, section 6 | Writing. You speak, and the words are written for you. |
| Read-back of your own text | Hearing what you wrote before you save it. |
| Live translation | Writing in a language that is not your own. |
Live translation answers a language need rather than a disability. It is listed so that the list is complete.
3.2 What That Means for Your Privacy
Clex is made for people who find reading and writing difficult, so the fact that someone uses it can say something personal about them. Under the GDPR that kind of information is protected by Article 9, and we treat it that way.
Read Aloud sends nothing it reads. It makes no network request of any kind. The text it reads never leaves the device, and no server ever sees it. Section 7.2 describes what happens to it.
We count how often each feature is used, including Read Aloud, speech to text and sentence correction. For each one we count the number of times it was used that day and the number of times it failed. Nothing about what was read, said or written is recorded. Section 4.2 lists the whole report.
Those counts are never held against a person or a device. A report carries no name, no e-mail address, no account and no identifier of any kind, so two days’ reports from the same device cannot be matched to each other. The protection does not rest on that alone: when a report reaches our servers it is not filed, it is added. Its numbers are summed into a running daily total for your whole organisation, and the report itself stops existing at that moment. Section 4.3 describes this in full. What remains is a number such as “this organisation used speech to text 214 times on 3 August”, which is the same number whether it came from four people or forty.
We keep these counts because they are how we find out when a feature stops working on a customer’s devices, and these are the features people most depend on. If you would rather send nothing at all, the switch in section 4.2 turns off every count, including these.
We do not ask whether you have a reading difficulty, we do not record a diagnosis, and we do not infer one. Nothing in the app switches on or off on the basis of one.
4. What Data Is Processed
4.1 What Leaves Your Device
| What is sent | When | Purpose and legal basis |
|---|---|---|
| Your licence key, exchanged for a short-lived access token | App start and token refresh | Confirms the app is licensed. Performance of a contract, Art. 6(1)(b) |
| Your activation code (Bring Your Own Device only) | When you activate the app | Same |
| Usage measurements, listed in 4.2 | One report per day of use, uploaded by a background check that runs about once every 24 hours when the device is online | Service reliability, and knowing which features are used. Legitimate interest, Art. 6(1)(f) |
| Requests for language and model files | First use of a language or feature, when you ask for an update yourself, and unattended about once every 24 hours, see 4.5 | Installs and updates the on-device models. Art. 6(1)(b) |
Nothing else is transmitted. There is no request that carries the text you write.
4.2 The Usage Measurements: What Is in a Report
One report describes one calendar day. This is the whole report, and nothing else:
- the date it describes, as a day only, with no clock times
- the app version, shortened to its first two numbers, such as 1.12
- the keyboard language, if it is Danish, Swedish, English or German. Every other language is reported as “none”
- three fixed labels, identical in every report from every device: the name of the report format, the product (“keyboard Android”) and the platform (“Android”)
- a random report number, created for that one report, used only so a repeated upload of the same report is not counted twice
- the counters: for each measured thing, the number of times it happened that day
If the keyboard language or the app version changes during a day, the day’s counts are split into one report per combination, each still describing only that calendar day.
The counters measure use of the keyboard’s own features. Each is a number of times something happened that day, never the words involved: how many times a suggested word or symbol was taken, an auto-correction was applied or undone, your own text was read back, the voice failed, the translation panel was opened, a translation was produced, the language was changed, a setting was changed, and the keyboard was opened. Two of them record only whether the keyboard and the app were used at all that day.
They also count three more features, each as a number of uses and a number of failures:
- Speech to text: recordings started, finished, cancelled, clips that held no speech, and failures, split into a refused microphone permission, a model that would not load, and everything else
- Sentence correction: corrections started, accepted, closed without accepting, and refused because the text was too long or held too many words the model does not know
- Read Aloud: the accessibility service starting, the button being pressed, reading beginning, and the button failing to appear on screen. When the voice itself fails, that is counted together with the keyboard’s own read-back, named above
None of these records what was read, said or written, which app was in front, or when in the day it happened.
The remaining counters are operational rather than about you. They record how quickly the app responded, whether model downloads and updates succeeded or failed and for what technical reason, and whether licence checks and report uploads went through. They describe the software’s health, not your use of it.
A report never contains what you typed, which app you were typing in, any time of day, any character count, or any identifier for you or your device. It is sent with your organisation’s access token, section 4.4, so we can tell which organisation it belongs to, and no more.
You can switch the measurements off, in the app’s settings under Privacy, with the switch named “Share anonymous usage statistics”. It is on until you turn it off. Turning it off stops the counting at source and deletes every report not yet sent. To object to this processing in other ways, see section 11.
4.3 What Happens to a Report After It Arrives
This section describes our own servers, because what happens after upload is what decides whether a count can ever be connected to a person.
A report is checked, then added, then gone. Our service accepts only the field names listed in 4.2 and only counter names from a fixed list. Anything else is refused. The accepted numbers are added into a running daily total for your organisation, and the report is not written to a file or a table anywhere. There is no record from which a single day’s upload could be pulled back out.
What is stored is a total, not an event. One stored row is: the date, the organisation, the product, the platform, the app-version bucket, the language, the counter name, and the number. There is no row for a device, an installation, a session, or a person, because no such value ever reaches the service.
The report number is used once and expires. The random number in 4.2 is kept on its own for a short period so that the same report cannot be counted twice, then it is deleted automatically. It identifies a report, never an app or a user.
We do not record where the report came from. The service does not read or store the IP address a report arrives from, and it does not store browser or device signatures.
Only totals can be read back, and only internally. The interface that reads this data requires an internal credential. The credential the app uses to upload cannot read anything. When totals are read back, the language and app-version breakdowns are deliberately dropped, so that a small group cannot be isolated within an organisation.
It deletes itself. Totals are deleted automatically 24 months after the day they describe. If a customer relationship ends, we can erase every total belonging to that organisation on request.
4.4 The Access Token
The token identifies the licensed organisation, its expiry, and a label your organisation configured. The label is used only on your device, to adapt predictions. The token carries no name or contact detail for you, it is never stored on our side, and it is not written to our logs.
4.5 Model and Language Downloads
Requests for model files carry no identifier at all: no account, no licence, no device ID. As with any download, the server that delivers the file can see your IP address.
These downloads also run unattended, about once every 24 hours, with the app closed. One can transfer several hundred megabytes when a model has changed, so Android holds the transfer until four things are true at once: the device is charging, it is on wi-fi and not on mobile data, and neither the battery nor the storage is low. The unattended run only updates models that are already on your device. It never installs a new one on its own. It keeps the models current without making you wait for a download while you work.
You can also start the same check yourself, under Status, then Assets updater, then Update now. That one runs when you ask it to. If you are on mobile data, the app asks first.
4.6 Local Features (No User Text Transmitted)
These features run on your device. No user text is sent to Clex or to any third party for them:
- Word prediction and auto-correction.
- Sentence correction, which checks spelling and grammar in your text and rewrites it, using models stored in the app.
- Live translation. Language files are downloaded once on first use and then kept on the device.
- Symbol search and sentence suggestions, looked up in a read-only database inside the app.
- Speech to text, described in section 6.
- Read Aloud and text-to-speech, using the offline voices installed on your device. Read Aloud is described in section 7.
- Crash reports, which are stored locally and never uploaded. You can copy one to the clipboard yourself if you choose to send it to us.
No user text is included in any download or network request related to these features.
4.7 The Update Log on Your Device
The app can keep a short technical log of the model updates in section 4.5, so that support can answer why an update did or did not happen on a particular device. When a line is written, it holds:
- the date and time on your device, with the time-zone offset
- whether the update check ran, and the reason if it was skipped
- which of the app’s entry points started the check, and if Android stopped it, why
- the language the app was set to use
- which model and language files were checked, and the version each is at
- whether a download was started
- the type of any error, which is a short technical name and never a message
Only a limited number of recent lines is kept, and the oldest are removed as new ones arrive.
The log stays in the app’s private storage on your device. It is not sent to us, it is not included in any backup or device transfer, and it is removed when you clear the app’s data or uninstall the app. You can read it yourself under Status, then Assets updater, then Logs. On that screen you can copy it, if you decide to send it to support, and you can delete it.
The log contains none of the text you write, nothing from the screen, no audio, no licence key, no access token and no identifier.
5. What We Do Not Collect
We do not collect or store:
- The text you type into EHR/EOJ systems or any other application
- The text you type, in any file the app keeps on your device, including the update log in section 4.7
- The name of the app you are typing in
- The length of what you write. No character counts leave the device
- The time of day you type. A usage report names only the calendar day it describes
- Keystrokes, keystroke timing, or input patterns
- The audio you speak to the app
- Your screen content, beyond the on-device, in-memory handling described in section 7
- Personal data such as names, addresses, phone numbers, or health records of any individual
- Photographs or other user-generated media
- Information from the EHR/EOJ systems where text is entered
- Device contacts, location, call logs, SMS, or browsing history
The app contains no third-party analytics, crash-reporting, advertising or attribution components. Usage measurements go only to Clex’s own servers.
6. Speech to Text and the Microphone
Speech to text writes down what you say. It is optional. Android asks for microphone permission the first time you use it, and the keyboard works fully if you decline.
- The microphone is active only while speech to text is running. It stops when you stop it, and it stops on its own after a pause in speech.
- Audio is transcribed by a model stored in the app, on your device.
- The audio is held in memory while it is transcribed. It is not written to a file, not kept after the transcription, and not uploaded. It is not sent to Android’s speech service either.
- The transcription is inserted into the text field you are writing in, the same way as if you had typed it.
7. Read Aloud, the Accessibility Feature
Read Aloud speaks text from the screen you are looking at, for people who are dyslexic, who find reading difficult, or who have low vision. It uses Android’s accessibility service, which you switch on yourself in Settings > Accessibility. It is off until you do, and you can switch it off again at any time.
7.1 What It Reads
The visible text of the screen you are currently looking at, read when you press the Read Aloud button. It also reads the package name of the app in the foreground, which is used only to apply the block list in section 7.3.
7.2 What Happens to That Text
It stays on your device. The part of the app that does this has no ability to make a network request at all: it contains no networking component of any kind. The text is held in memory for as long as it takes to outline the screen and speak the block you tapped, then it is discarded. It is never written to storage, never written to a log file, and never sent to us or to anyone else. The voice that speaks it is your device’s own offline voice. If your device has no offline voice for the language, the result is silence, not synthesis somewhere else.
What Read Aloud does report is counts, listed in section 4.2: how often the feature ran, was pressed, and began reading. A count says the feature was used, and nothing about what was on the screen or which app it was.
Read Aloud does not take screenshots, does not record the screen, and does not read apps you are not looking at.
7.3 What It Will Not Read
These are the protections the app states on the Read Aloud page and in Android’s Accessibility settings, in the same order:
- Screen text never leaves your device. It is never stored, never written to a log, and never sent to Clex.
- Password fields are never read, outlined, or spoken. This includes PIN fields and visible-password fields. A field is skipped together with everything inside it when Android marks it as a password field, or when its input type is any password variant.
- A built-in list of sensitive apps is blocked entirely. It covers banks, MitID, password managers, two-step login apps and payment apps. No Read Aloud button appears, and nothing is read. Your phone’s own Settings app is not on that list, because Read Aloud has to work on the settings pages themselves.
- If an app marks part of its screen as sensitive, Clex skips it, even though Android would allow Clex to read it.
- Clex sees which app is in front, so it can block those sensitive apps. It does not read their text.
- Clex never reads notifications, and never reads an app running in the background. The service is registered for window changes only, so notification events never reach it.
- Reading stops when you switch to another app.
7.4 Where That Protection Ends
We state the limit rather than overstate the guarantee: the password rule depends on the app you are using marking its fields correctly. An app that does not mark a field as a password will not be recognised as one.
What that limit cannot do is send anything anywhere. As section 7.2 describes, this part of the app has no networking component, so even in that case the text is spoken on the device and discarded. It does not reach Clex, and it is not stored.
8. Permissions, and Why
| Permission | Why |
|---|---|
| Accessibility service | The optional Read Aloud feature in section 7, which you enable yourself |
| Internet, network state | Licence validation, usage measurements, model downloads, offline-aware interface |
| Microphone | On-device speech to text. Optional, and the keyboard works without it |
| Vibrate | Haptic feedback on key presses |
| Notifications | Operational messages, such as a crash notice |
| Run at startup | So the daily update check in section 4.5 still happens after the device has been switched off and on again |
9. Backup and Device Transfer
The app is excluded from Android backup. Nothing the app holds is copied to your Google account, and nothing is carried over when you set up a new device from your old one.
10. Legal Basis (GDPR Article 6)
| Processing activity | Legal basis | Reference |
|---|---|---|
| Licence validation and activation | Performance of a contract | Art. 6(1)(b) GDPR |
| Model and language downloads | Performance of a contract | Art. 6(1)(b) GDPR |
| Usage measurements | Legitimate interest in keeping the app reliable and knowing which features are used | Art. 6(1)(f) GDPR |
Since the free text stays on the device and we receive no records about the people your organisation documents, a data processing agreement between the organisation and Clex is generally not required for that content. What we do process is our own organisation-level usage totals, which carry no identifier for any person, and for which Clex is the controller. If your organisation concludes that supplementary documentation is needed, we can support that assessment.
We carry out no automated decision-making or profiling within the meaning of Article 22. The app proposes draft sentences and corrections, and the care worker decides whether to use each one. No automated decisions are made about individuals and no profiles are built.
11. Your Rights Under the GDPR
You have the right to access the data we hold about you, to have it rectified, erased, or its processing restricted, to object to processing based on our legitimate interest, and to receive it in a portable form.
Write to Email us. We answer within one month, as Article 12 requires. Be aware of what the answer will be: because a usage total holds no identifier for any person, we have no way to search it for you, and no way to separate your share of it from your colleagues’. That is a consequence of the design in section 4.3, not a refusal. The direct and immediate way to stop the measurements is the switch in section 4.2, which acts at once and needs no request to us.
You can also do these things yourself, at any time, without asking us:
- Switch off the usage measurements, in the app’s settings, section 4.2, which also deletes any reports not yet sent.
- Delete everything held locally, by clearing the app’s data or uninstalling it.
- Switch off Read Aloud, in Settings > Accessibility, which stops everything in section 7 immediately.
- Decline the microphone permission. Speech to text is optional and the keyboard works without it.
- Delete the update log, with the Clear button on the log screen in section 4.7.
Your organisation can ask us to erase every usage total belonging to it, and we do that on request.
You may lodge a complaint with your supervisory authority:
| Country | Authority |
|---|---|
| Denmark | Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk |
| Sweden | Integritetsskyddsmyndigheten, imy.se |
| Germany | The competent federal or state data-protection authority |
12. Data Sharing and Sub-processors
We do not sell, rent, or trade personal data. These providers are involved in delivering the service:
| Provider | Role | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting | Germany (EU) | Not required (EU) |
| BunnyWay d.o.o. (Bunny.net) | Content delivery, DDoS protection, authoritative DNS | Slovenia (EU), EU-only edge routing | Not required (EU) |
| Key-Systems GmbH | Domain registrar (clex.ai) | Germany (EU) | Not required (EU), no traffic and no personal data |
No other third-party service receives data from the app in normal operation. The on-device components process data locally and transmit nothing.
13. Infrastructure and Data Residency
All Clex-managed processing of the data in section 4 takes place on servers in the European Union, hosted in Germany.
- Licence validation and usage measurements are received by our servers in Germany.
- Model files are delivered from European edge locations only, and visitor IP addresses are anonymised at the edge before any access log is written.
- The architecture is designed to keep external service dependencies few and to keep server-side operations inside the EU.
The full sub-processor register is available on request.
14. Data Security
Traffic between the app and Clex-managed servers is encrypted in transit. The access token travels only as a credential for that connection and is not stored or logged on our side. Data held on your device stays inside the app’s private storage area, protected by Android’s security model. Server infrastructure is protected using industry-standard security controls.
We apply commercially reasonable security measures. No method of electronic transmission or storage is completely secure, so we design the systems to keep the amount of exposed data small in the first place.
15. Data Retention
- On your device: until you clear the app’s data or uninstall it, which removes everything the app has stored. Text read aloud is never stored at all, and neither is the audio you speak. A usage report not yet sent is kept for at most 14 days, then deleted instead of sent, and switching the measurements off deletes unsent reports at once. The update log in section 4.7 keeps only a limited number of recent lines.
- Usage totals on our servers: deleted automatically 24 months after the day they describe, and sooner if your organisation asks or its contract ends. Individual reports are never retained at all, as section 4.3 describes.
- Licence validation records: kept for the duration of the customer contract.
- Free text from app usage: never held on Clex servers, because it is never sent there.
16. Children’s Privacy
Clex Keyboard is made for professional care workers in an organisational context, including students in care-sector vocational programmes. It is not directed at children, and we do not knowingly collect information from anyone under the age of 16.
17. Changes to This Policy
We update this policy as the app changes. When we do, we change the effective date at the top and post the revised version on our website. Material changes are described rather than made silently.
18. Contact
| Purpose | Contact |
|---|---|
| Data protection and general enquiries | Uffe Gorm Pal Hansen - Email us |
| Danish customers | Flakron Sojeva - Email us |
| Swedish customers | Ron Karlsson - Email us |
| Support | Email us |
| Address | Clex A/S, Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark |
