Privacy Policy, Clex Keyboard for Android
The privacy policy for Clex Keyboard on Android: what stays on your device, what leaves it, and what happens to it afterwards.
Effective date: 21 August 2026
This policy covers Clex Keyboard for Android. The other Clex products, and the Clex website, are covered by the general Clex privacy policy. Where the two describe Android behaviour differently, this one is the accurate document.
At a Glance
| Question | Answer |
|---|---|
| Does Clex see what I type? | No. Your text is processed on the device. Clex does not store it and it is not sent to Clex; the licence and statistics requests have no field for free text, and each release is reviewed for this. |
| Does Clex see what is read aloud from my screen? | No. Read Aloud contains no networking code; the text is held in memory only while it is spoken. |
| Does Clex hear what I dictate? | No. Speech is turned into text on the device; the audio is not stored and not sent. |
| What does leave the device? | A licence check, requests for model files, and a daily set of usage counts. Section 4 lists every field. |
| Can a usage report be traced to me? | No identifier for you, your device or your installation is in a report; it carries a random one-time report number and your organisation’s access token, and its counts are added to your organisation’s totals on arrival. In a very small deployment the organisation’s totals can in practice describe few people, and our anonymity assessment states this openly. |
| Can I switch the counting off? | Yes, in the app’s settings, at any time. |
| Where is the data processed? | On servers in Germany, behind an EU-only edge network; everything Clex manages is processed within the EU. |
1. Who We Are
This Privacy Policy is issued by Clex A/S, a Danish corporation (CVR 37750840) with registered address at Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark. For the Swedish market, Clex Sweden AB (org.nr 559544-8001) is the contracting party.
Clex develops language-technology writing support for the care sector. This policy describes how we handle information when you use Clex Keyboard for Android.
| Field | Details |
|---|---|
| Legal name | Clex A/S |
| Country | Denmark (EU) |
| CVR | 37750840 |
| Website | clex.ai |
| Data-protection contact | Uffe Gorm Pal Hansen, Email us |
| General contact | Email us |
Clex A/S is an independent controller for the data it receives, described in section 4. The organisation that deployed Clex to you (municipality, care provider, or employer) is the controller for the records its staff write in its own systems, and Clex never receives those records. Section 10 sets out the roles activity by activity.
2. Scope
This policy covers Clex Keyboard for Android, distributed through Google Play and through managed device deployment. The other Clex products, and the Clex website, are covered by the general Clex privacy policy on clex.ai. Where the two documents describe Android behaviour differently, this one is the accurate document.
The app is designed for professional care workers who document care activities within their organization’s electronic health record (EHR/EOJ) systems.
3. Our Approach to Privacy
Clex Keyboard is built on a local-first, privacy-by-design architecture:
- The free text you write stays on your device. Clex does not store it and it is not sent to Clex.
- Word prediction, auto-correction, sentence correction, live translation, speech to text and read aloud all run on the device, using models stored in the app.
- What does leave the device is a licence check, a set of usage measurements, and requests for model files. Section 4 lists every field.
- No keystrokes are logged, monitored, or transmitted at any point.
Clex has no integration with, and no access to, the EHR/EOJ system’s databases or interfaces. What the keyboard sees is what Android makes available in the text field the user is typing in: word suggestions use up to about 256 characters before the cursor and 128 after it, and sentence correction and rewrite read the whole content of the active field when the user asks for it. Read Aloud, when the user has switched it on and taps a text block, reads the visible text of the current screen through Android’s accessibility service. All of this is processed on the device. Clex stores none of this text, and none of it is sent to Clex.
The usage measurements are daily counts of feature use. They are counted per organisation and calendar day, they carry no identifier for a person, device or installation, and you can switch them off in the app’s settings. Sections 4.2 and 4.3 describe the whole report and what becomes of it.
About the keyboard access warning. When you enable Clex Keyboard, Android displays a standard warning that the keyboard may be able to collect everything you type, including passwords and credit card numbers. This warning is shown for all third-party keyboards and is not specific to Clex. Clex Keyboard does not collect, store or transmit the text you type. Section 4 lists everything the app does send, and section 5 lists what it never sends.
3.1 Who Clex Keyboard Is For
Clex Keyboard is a reading and writing aid for care workers. It is rolled out to whole teams, and it helps in particular those who are dyslexic, who find reading and writing difficult, or who have low vision. Read Aloud is registered with Google as an accessibility tool, and Android’s Accessibility settings say the same thing.
Each feature answers a particular writing situation:
| Feature | What it is for |
|---|---|
| Read Aloud, section 7 | Reading on screen. Text in any app is spoken instead of read. |
| Word prediction and auto-correction | Spelling. The next word is offered, so it does not have to be spelled out. |
| Sentence correction | Writing. Checks spelling and grammar in text you have already written and rewrites it, and shows you each change before you accept it. |
| Speech to text, section 6 | Writing. You speak, and the words are written for you. |
| Read-back of your own text | Hearing what you wrote before you save it. |
| Live translation | Writing in a language that is not your own. |
Live translation answers a language need rather than a disability. It is listed so that the list is complete.
3.2 What That Means for Your Privacy
Clex is developed as reading and writing support, and it is rolled out to whole teams and used by people with and without reading or writing difficulties. Clex does not ask for, record or infer a diagnosis, and the usage statistics are never linked to a person, device or installation, so Clex cannot derive anything about an individual from them. If your organisation itself links the use of Clex to a named employee, for example as an agreed workplace accommodation, that is your organisation’s own processing and your organisation assesses its legal basis under Article 6 and, where relevant, Article 9. Counting per organisation, reading only organisation totals and the short life of the report number are safeguards, not a legal basis. Nothing in the app switches on or off on the basis of a diagnosis; every feature is available to every user.
Read Aloud sends nothing it reads. Read Aloud contains no networking code. It runs inside the keyboard app, whose only uploads are the licence check and the daily usage counters described in section 4, and the text it reads is held in memory only while it is spoken. Section 7.2 describes what happens to it.
We count how often each feature is used, including Read Aloud, speech to text and sentence correction. For each one we count the number of times it was used that day and the number of times it failed. Nothing about what was read, said or written is recorded. Section 4.2 lists the whole report.
Those counts are not held against a person or a device. A usage report contains no identifier for a person, user, device, installation or session. It contains a random report number created for that one report and used only to discard duplicates, and it is sent with your organisation’s access token so that Clex can tell which organisation the counts belong to. The report number cannot link reports from different days or devices; it is deleted at most 15 days after the report arrives. Clex’s service uses the access token only to read the organisation identifier it carries; the token itself is not stored or logged. Section 4.3 describes this in full. What Clex keeps is a number such as “this organisation used speech to text 214 times on 3 August”, which is the same number whether it came from four people or forty.
We keep these counts because they are how we find out when a feature stops working on a customer’s devices, and these are the features people most depend on. If you would rather not send any counts, the switch in section 4.2 turns off every count, including these.
4. What Data Is Processed
4.1 What Leaves Your Device
| What is sent | When | Purpose and legal basis |
|---|---|---|
| Your organisation’s licence key, exchanged for a short-lived access token | App start and token refresh | Confirms the app is licensed. Legitimate interest, Article 6(1)(f), see section 10 |
| Your organisation’s activation code (Bring Your Own Device only) | When you activate the app | Same |
| Usage measurements, listed in 4.2 | One report per day of use, uploaded by a background check that runs about once every 24 hours when the device is online | Service reliability, and knowing which features are used. Legitimate interest, Article 6(1)(f), see section 10 |
| Requests for language and model files | First use of a language or feature, when you ask for an update yourself, and unattended about once every 24 hours, see 4.5 | Installs and updates the on-device models. Legitimate interest, Article 6(1)(f), see section 10 |
Nothing else is transmitted. There is no request that carries the text you write.
4.2 The Usage Measurements: What Is in a Report
One report describes one calendar day. This is the whole report, and nothing else:
- the date it describes, as a day only, with no clock times
- the app version, shortened to its first two numbers, such as 1.12
- the keyboard language, if it is Danish, Swedish, English or German. Every other language is reported as “none”
- three fixed labels, identical in every report from every device: the name of the report format, the product (“keyboard Android”) and the platform (“Android”)
- a random report number, created for that one report, used only so a repeated upload of the same report is not counted twice, and deleted at most 15 days after the report arrives
- the counters: for each measured thing, the number of times it happened that day
If the keyboard language or the app version changes during a day, the day’s counts are split into one report per combination, each still describing only that calendar day.
The counters measure use of the keyboard’s own features. Each is a number of times something happened that day, never the words involved: how many times a suggested word or symbol was taken, an auto-correction was applied or undone, your own text was read back, the voice failed, the translation panel was opened, a translation was produced, the language was changed, a setting was changed, and the keyboard was opened. Two of them record only whether the keyboard and the app were used at all that day.
They also count three more features, each as a number of uses and a number of failures:
- Speech to text: recordings started, finished, cancelled, clips that held no speech, and failures, split into a refused microphone permission, a model that would not load, and everything else
- Sentence correction: corrections started, accepted, closed without accepting, and refused because the text held too many words the model does not know
- Read Aloud: the accessibility service starting, the button being pressed, reading beginning, and the button failing to appear on screen. When the voice itself fails, that is counted together with the keyboard’s own read-back, named above
None of these records what was read, said or written, which app was in front, or when in the day it happened.
The remaining counters are operational rather than about you. They record how quickly the app responded, whether model downloads and updates succeeded or failed and for what technical reason, and whether licence checks and report uploads went through. They describe the software’s health, not your use of it.
A report never contains what you typed, which app you were typing in, any time of day, any character count, or an identifier for a person, user, device, installation or session. It is sent with your organisation’s access token, section 4.4, so that Clex can tell which organisation the counts belong to, and no more.
You can switch the measurements off, in the app’s settings under Privacy, with the switch currently labelled “Share anonymous usage statistics”. It is on until you turn it off. Turning it off stops the counting at source and deletes every report not yet sent. To object to this processing in other ways, see section 11.
4.3 What Happens to a Report After It Arrives
This section describes our own servers, because what happens after upload is what decides whether a count can ever be connected to a person.
A report is checked, then added. Our service accepts only the field names listed in 4.2 and only counter names from a fixed list. Anything else is refused. The accepted numbers are validated and added to your organisation’s running daily totals on arrival, and the individual report is not kept.
What is stored is a total, not an event. One stored row is: the date, the organisation, the product, the platform, the app-version bucket, the language, the counter name, and the number. There is no row for a device, an installation, a session, or a person, because no such value reaches the service.
The report number is used once, then deleted. The random number in 4.2 is kept on its own so that the same report cannot be counted twice, and it is deleted at most 15 days after the report arrives. It cannot link reports from different days or devices; it identifies a report, never an app or a user.
We do not store where the report came from. Every network connection necessarily carries the device’s IP address for as long as the connection lasts. Clex’s licence and usage-statistics services do not read or store it, and they do not store browser or device signatures. The usage-statistics endpoint has edge logging switched off. Section 13 describes network logging in full.
The statistics are aggregated, and only totals can be read back. Usage statistics are aggregated: they are counted per organisation and calendar day and carry no identifier for a person, device or installation. Clex reads them only as organisation totals, only internally and only with an internal credential; the language and app-version breakdowns are never returned by the read interface. An organisation can ask for its own totals; Clex then delivers organisation totals only. Clex does not use usage statistics to monitor, evaluate or discipline individual employees, to train models, or to market to individuals, and does not combine them with support cases, access logs or any other data. Clex keeps organisation totals for 24 months. The in-app statistics switch is available to every user on Android, iOS and in Clex Web.
Totals are deleted on a fixed schedule. Organisation daily totals are deleted 24 months after the day they describe, and sooner if your organisation asks or its contract ends. Server backups of licence and statistics data are encrypted, held in the EU and under Clex’s control; a deleted record leaves the most recent backups within 48 hours and every backup within 72 days.
4.4 The Access Token
The token identifies the licensed organisation, its expiry, and a wording label set by Clex (the word the app uses for the person being documented about); it is never a name and your organisation cannot change it. The label is used only on your device, to adapt predictions. The token carries no name or contact detail for you. Clex’s service uses the access token only to read the organisation identifier it carries; the token itself is not stored or logged. The credential the app uses to upload cannot read anything back.
4.5 Model and Language Downloads
Requests for model files carry no account, no licence key and no device identifier. As with any network connection, the request carries your device’s IP address for as long as the connection lasts; the edge network that delivers the file writes its access logs with the last part of the address removed. Section 13 describes network logging in full.
Model and language files are downloaded over HTTPS from Clex’s servers and verified against the size published in Clex’s file manifest, and against the file’s checksum where the manifest publishes one, before they are activated; a file that fails a check is discarded.
These downloads also run unattended, about once every 24 hours, with the app closed. One can transfer several hundred megabytes when a model has changed, so Android holds the transfer until four things are true at once: the device is charging, it is on wi-fi and not on mobile data, and neither the battery nor the storage is low. The unattended run only updates models that are already on your device. It never installs a new one on its own. It keeps the models current without making you wait for a download while you work.
You can also start the same check yourself, under Status, then Assets updater, then Update now. That one runs when you ask it to. If you are on mobile data, the app asks first.
4.6 Local Features (No User Text Transmitted)
These features run on your device. No user text is sent to Clex or to any third party for them:
- Word prediction and auto-correction.
- Sentence correction, which checks spelling and grammar in your text and rewrites it, using models stored in the app.
- Live translation. Language files are downloaded once on first use and then kept on the device.
- Symbol search and sentence suggestions, looked up in a read-only database inside the app.
- Speech to text, described in section 6.
- Read Aloud and text-to-speech, using the offline voices installed on your device. Read Aloud is described in section 7.
- Crash reports, which are stored locally and never uploaded. You can copy one to the clipboard yourself if you choose to send it to us.
No user text is included in any download or network request related to these features. The models are static: they never learn from what is typed, dictated or read, and they are updated only as versioned files from Clex. Machine-generated text can contain errors. A suggestion enters the text only when the care worker accepts it, and checking it professionally before the note is saved remains the care worker’s responsibility; the record is the care worker’s, not the model’s.
4.7 The Update Log on Your Device
The app can keep a short technical log of the model updates in section 4.5, so that support can answer why an update did or did not happen on a particular device. When a line is written, it holds:
- the date and time on your device, with the time-zone offset
- whether the update check ran, and the reason if it was skipped
- which of the app’s entry points started the check, and if Android stopped it, why
- the language the app was set to use
- which model and language files were checked, and the version each is at
- whether a download was started
- the type of any error, which is a short technical name and never a message
The most recent 1,000 lines are kept, and the oldest are removed as new ones arrive.
The log stays in the app’s private storage on your device. It is not sent to us, it is not included in any backup or device transfer, and it is removed when you clear the app’s data or uninstall the app. You can read it yourself under Status, then Assets updater, then Logs. On that screen you can copy it, if you decide to send it to support, and you can delete it.
The log contains none of the text you write, nothing from the screen, no audio, no licence key, no access token, and no identifier for a person, user, device, installation or session.
5. What We Do Not Collect
Through Clex Keyboard for Android, Clex does not collect or store:
- The text you type into EHR/EOJ systems or any other application
- The text you type, in any file the app keeps on your device, including the update log in section 4.7
- The name of the app you are typing in
- The length of what you write. No character counts leave the device
- The time of day you type. A usage report names only the calendar day it describes
- Keystrokes, keystroke timing, or input patterns
- The audio you speak to the app
- Your screen content, beyond the on-device, in-memory handling described in section 7
- Personal data such as names, addresses, phone numbers, or health records of any individual
- Photographs or other user-generated media
- Information from the EHR/EOJ systems where text is entered
- Device contacts, location, call logs, SMS, or browsing history
The app contains no third-party analytics, crash-reporting, advertising or attribution components. Usage measurements go only to Clex’s own servers.
6. Speech to Text and the Microphone
Speech to text writes down what you say. It is optional. Android asks for microphone permission the first time you start a recording, and the keyboard works fully if you decline.
- The microphone is active only while speech to text is running. It stops when you stop it, and it stops on its own after a pause in speech, and after 30 seconds at most.
- Audio is transcribed by a model stored in the app, on your device.
- The audio is held in memory while it is transcribed. It is not written to a file, not kept after the transcription, and not uploaded. It is not sent to Android’s speech service either.
- The transcription is inserted into the text field you are writing in, the same way as if you had typed it.
- Speech to text is available for Danish and Swedish.
7. Read Aloud, the Accessibility Feature
Read Aloud speaks text from the screen you are looking at, for people who are dyslexic, who find reading difficult, or who have low vision. It uses Android’s accessibility service, which you switch on yourself in Settings > Accessibility. It is off until you do, and you can switch it off again at any time.
7.1 What It Reads
The visible text of the screen you are currently looking at, read when you press the Read Aloud button. It also reads the package name of the app in the foreground, which is used only to apply the block list in section 7.3.
7.2 What Happens to That Text
It stays on your device. Read Aloud contains no networking code. It runs inside the keyboard app, whose only uploads are the licence check and the daily usage counters described in section 4, and the text it reads is held in memory only while it is spoken. Clex verifies this by dependency review of the Read Aloud component at each release. The text is held for as long as it takes to outline the screen and speak the block you tapped, then it is discarded. It is never written to storage, never written to a log file, and it is not sent to Clex or to anyone else. The voice that speaks it is your device’s own offline voice. If your device has no offline voice for the language, the result is silence, not synthesis somewhere else.
What Read Aloud does report is counts, listed in section 4.2: how often the feature ran, was pressed, and began reading. A count says the feature was used, and nothing about what was on the screen or which app it was.
Read Aloud does not take screenshots, does not record the screen, and does not read apps you are not looking at.
7.3 What It Will Not Read
These are the protections the app states on the Read Aloud page and in Android’s Accessibility settings, in the same order:
- Screen text never leaves your device. It is never stored, never written to a log, and never sent to Clex.
- Password fields are never read, outlined, or spoken. This includes PIN fields and visible-password fields. A field is skipped together with everything inside it when Android marks it as a password field, or when its input type is any password variant.
- A built-in list of 56 sensitive apps is blocked entirely. It covers banking, identity, payment, password and authentication apps, including MitID. The list ships with the app and is updated with each release. No Read Aloud button appears, and nothing is read. Your phone’s own Settings app is not on that list, because Read Aloud has to work on the settings pages themselves.
- If an app marks part of its screen as sensitive, Clex skips it, even though Android would allow Clex to read it.
- Clex sees which app is in front, so it can block those sensitive apps. It does not read their text.
- Clex never reads notifications, and never reads an app running in the background. The service is registered for window changes only, so notification events never reach it.
- Reading stops when you switch to another app.
7.4 Where That Protection Ends
We state the limit rather than overstate the guarantee: the password rule depends on the app you are using marking its fields correctly. An app that does not mark a field as a password will not be recognised as one.
What that limit does not change is where the text goes. As section 7.2 describes, Read Aloud contains no networking code and holds the text in memory only while it is spoken, so even in that case the text is spoken on the device and then discarded. It does not reach Clex, and it is not stored.
8. Permissions, and Why
| Permission | Why |
|---|---|
| Accessibility service | The optional Read Aloud feature in section 7, which you enable yourself |
| Internet, network state | Licence validation, usage measurements, model downloads, offline-aware interface |
| Microphone | On-device speech to text. Optional, and the keyboard works without it |
| Vibrate | Haptic feedback on key presses |
| Notifications | Operational messages, such as a crash notice |
| Run at startup | So the daily update check in section 4.5 still happens after the device has been switched off and on again |
9. Backup and Device Transfer
The app is excluded from Android backup. Nothing the app holds is copied to your Google account, and nothing is carried over when you set up a new device from your old one.
10. Roles and Legal Basis (GDPR Article 6)
Who is responsible for what. Roles are assigned per processing activity.
- The notes, messages and other text that care workers write, dictate or have read aloud are processed on the organisation’s own devices and browsers and are never received by Clex. For that processing the organisation is the controller, exactly as for any other text its staff write, and Clex is the supplier of the software, neither a controller nor a processor.
- For licence validation and activation, the connection data that those requests carry, and the daily usage statistics, Clex A/S decides the purpose and the means and is therefore an independent controller. Hetzner Online GmbH and BunnyWay d.o.o. process that data for Clex A/S as processors. On the Swedish market Clex Sweden AB is the contracting party; Clex A/S remains the controller.
- Where Clex processes personal data on an organisation’s documented instructions, for example if the organisation grants Clex diagnostic access during a support case, Clex acts as a processor for that activity, and a data processing agreement under Article 28 is in place before that processing begins. Clex provides a per-activity overview on request; when an organisation’s data protection officer requests a data processing agreement for any other activity, Clex concludes one.
| Processing | Data | Legal basis |
|---|---|---|
| Licence validation and activation | Organisation licence key or activation code, app version, access token | Article 6(1)(f), legitimate interest: operating and securing the licensed service for the organisation. The licence key and the organisation identifier in the token describe the organisation, not a person. |
| Model, dictionary, voice and language downloads | File request, IP address during the connection | Article 6(1)(f), legitimate interest: delivering the product’s language resources. |
| Daily usage statistics | See section 4 (counts per organisation and day, report number, access token) | Article 6(1)(f), legitimate interest: keeping the service reliable and knowing which features are used. You can object at any time by switching statistics off in the app or extension settings. |
Clex’s legitimate-interest assessment for these activities is available from Clex. The care workers who use Clex are normally not party to the agreement between their organisation and Clex, which is why Clex does not rely on Article 6(1)(b) for them. The organisation’s own legal basis for the documentation work Clex assists with is the one it already has for that work; Clex adds no new purpose.
We carry out no automated decision-making or profiling within the meaning of Article 22. The app proposes draft sentences and corrections, and the care worker decides whether to use each one. No automated decisions are made about individuals and no profiles are built.
11. Your Rights Under the GDPR
Where the conditions in the GDPR are met you have the right to access, rectify, erase and restrict the processing of personal data about you, and to object to processing based on Article 6(1)(f); the simplest way to object to the usage statistics is to switch them off in the settings. The right to data portability applies only to processing based on consent or contract; of Clex’s own processing, only the website contact form rests on contract, and you can ask us for a copy of what you sent through it. Because usage statistics are counted per organisation and carry no identifier for a person, Clex cannot look up data about an individual in them (Article 11); your organisation can ask Clex to delete all totals belonging to it. Contact: Email us. You can also complain to Datatilsynet (or, in Sweden, Integritetsskyddsmyndigheten).
We answer within one month, as Article 12 requires. That the usage totals cannot be searched for an individual is a consequence of the design in section 4.3, not a refusal. The direct and immediate way to stop the measurements is the switch in section 4.2, which acts at once and needs no request to us.
You can also do these things yourself, at any time, without asking us:
- Switch off the usage measurements, in the app’s settings, section 4.2, which also deletes any reports not yet sent.
- Delete everything held locally, by clearing the app’s data or uninstalling it.
- Switch off Read Aloud, in Settings > Accessibility, which stops everything in section 7 immediately.
- Decline the microphone permission. Speech to text is optional and the keyboard works without it.
- Delete the update log, with the Clear button on the log screen in section 4.7.
Your organisation can ask us to erase every usage total belonging to it, and we do that on request.
You may lodge a complaint with your supervisory authority:
| Country | Authority |
|---|---|
| Denmark | Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk |
| Sweden | Integritetsskyddsmyndigheten, imy.se |
| Germany | The competent federal or state data-protection authority |
12. Data Sharing and Processors
We do not sell, rent, or trade personal data. These providers are involved in delivering the service:
| Processor | Role | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting | Germany (EU) | Not required (EU) |
| BunnyWay d.o.o. (Bunny.net) | Edge network, DDoS protection, authoritative DNS | Slovenia (EU); EU-only edge routing | Not required (EU) |
The app is distributed through Google Play and through managed device deployment. Google processes account, device and download data for its own store services under its own terms; that processing is not part of Clex’s service and Clex receives none of it.
Read Aloud uses the speech engine installed on the device (on most devices Google’s offline voices); text is spoken on the device and not sent to any service.
Apart from the processors and the distributor named above, no other service receives data from the app in normal operation. The on-device components process data locally; the only uploads are the licence check and the usage counters described in section 4.
13. Infrastructure and Data Residency
Clex’s services run on servers operated by Hetzner Online GmbH in Germany. In front of them sits an edge network operated by BunnyWay d.o.o. (Slovenia) that delivers model and language files, protects the services against attack and answers DNS queries; it is configured to route traffic within the EU only. Both companies process data for Clex as processors under written agreements. Everything Clex manages is processed within the EU.
IP addresses and network logs. Every network connection necessarily carries the device’s IP address for as long as the connection lasts. Clex’s licence and usage-statistics services do not read or store it, and they do not store browser or device signatures. The edge network that delivers model files and fronts Clex’s services writes its access logs with the last part of the address removed (the last octet of an IPv4 address, the host part of an IPv6 address); those logs are kept for 72 hours on a rolling basis by the edge provider and are not forwarded or archived. The usage-statistics endpoint has edge logging switched off. Clex’s own servers keep no per-request access log.
Key points:
- No data Clex manages is transferred outside the EU for processing; Google processes its own store and device data under its own terms.
- Licence validation and usage measurements are received by Clex’s servers in Germany, and model files are delivered from European edge locations only.
- The architecture is designed to keep external service dependencies few and to keep server-side operations inside the EU.
Section 12 names the processors involved.
14. Data Security
Traffic between the app and Clex-managed servers is encrypted in transit. The access token travels only as a credential for that connection and is not stored or logged on our side. Data held on your device stays inside the app’s private storage area, protected by Android’s security model. Server infrastructure is protected using industry-standard security controls.
We apply commercially reasonable security measures. No method of electronic transmission or storage is completely secure, so we design the systems to keep the amount of exposed data small in the first place.
15. Data Retention
| Data | Where | Retained |
|---|---|---|
| Text typed, dictated audio, text read aloud, suggestions, corrections, translations | Device memory only | Discarded when the field or session ends; never stored by Clex |
| Unsent daily usage report | Device | Until uploaded, at most 14 days; deleted immediately if you switch the measurements off |
| Received daily usage report | Clex usage-statistics service | Validated and added to the organisation’s totals on arrival; the individual report is not kept |
| Report number (duplicate check) | Clex usage-statistics service | At most 15 days |
| Organisation daily totals | Clex usage-statistics service | 24 months after the day they describe, or earlier on the organisation’s request or at contract end |
| Licence validation records | Clex licence service | For the duration of the customer contract |
| Local update log, section 4.7 | Device, app-private storage | Most recent 1,000 lines; cleared with app data or uninstall |
| Local crash reports | Device, app-private storage | Until you view them, clear the app’s data or uninstall; never uploaded automatically |
| Clex Academy profile name and progress | Device, app storage per device user | Until you delete the profile, clear the app’s data or uninstall |
| Edge access logs | Edge provider (EU) | 72 hours, rolling, anonymised IP, not forwarded |
| Server backups of licence and statistics data | Clex-controlled encrypted backups in the EU | A deleted record leaves the most recent backups within 48 hours and every backup within 72 days |
Clearing the app’s data or uninstalling the app removes everything the app has stored on your device. Free text from app usage is never held on Clex servers, because it is never sent there.
16. Children’s Privacy
Clex Keyboard is made for professional care workers in an organisational context, including students in care-sector vocational programmes. It is not directed at children, and we do not knowingly collect information from anyone under the age of 16.
17. Changes to This Policy
We update this policy as the app changes. When we do, we change the effective date at the top and post the revised version on our website. Material changes are described rather than made silently. Superseded versions remain available: the version effective 20 August 2026 is archived here, the version effective 18 August 2026 here, and the version effective 7 August 2026 here.
18. Contact
| Purpose | Contact |
|---|---|
| Data protection and general enquiries | Uffe Gorm Pal Hansen, Email us |
| Danish customers | Flakron Sojeva, Email us |
| Swedish customers | Ron Karlsson, Email us |
| Support | Email us |
| Address | Clex A/S, Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark |
