Privacy Policy, Clex Keyboard for iOS
The privacy policy for Clex Keyboard on iOS: what stays on your device, what leaves it, and what happens to it afterwards.
Effective date: 21 August 2026
This policy covers Clex Keyboard for iOS. The other Clex products, and the Clex website, are covered by the general Clex privacy policy. Where the two describe iOS behaviour differently, this one is the accurate document.
At a Glance
| Question | Answer |
|---|---|
| Does Clex see what I type? | No. Your text is processed on the device. Clex does not store it and it is not sent to Clex; the licence and statistics requests have no field for free text, and each release is reviewed for this. |
| Does Clex hear what I dictate? | No. Speech is turned into text on the device; the audio is not stored and not sent. |
| What does leave the device? | A licence check, requests for model files, a daily set of usage counts, and the keyboard framework’s licence check with its vendor’s EU service. Section 4 lists every field. |
| Can a usage report be traced to me? | No identifier for you, your device or your installation is in a report; it carries a random one-time report number and your organisation’s access token, and its counts are added to your organisation’s totals on arrival. In a very small deployment the organisation’s totals can in practice describe few people, and our anonymity assessment states this openly. |
| Can I switch the counting off? | Yes, in the Clex app’s settings, at any time. |
| Where is the data processed? | On servers in Germany, behind an EU-only edge network; everything Clex manages is processed within the EU. |
1. Who We Are
This Privacy Policy is issued by Clex A/S, a Danish corporation (CVR 37750840) with registered address at Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark. For the Swedish market, Clex Sweden AB (org.nr 559544-8001) is the contracting party.
Clex develops language-technology writing support for the care sector. This policy describes how we handle information when you use Clex Keyboard for iOS.
| Field | Details |
|---|---|
| Legal name | Clex A/S |
| Country | Denmark (EU) |
| CVR | 37750840 |
| Website | clex.ai |
| Data-protection contact | Uffe Gorm Pal Hansen - Email us |
| General contact | Email us |
Clex A/S is an independent controller for the data it receives, described in section 4. The organisation that deployed Clex to you (municipality, care provider, or employer) is the controller for the records its staff write in its own systems, and Clex never receives those records. Section 7 sets out the roles activity by activity.
2. Scope
This policy covers Clex Keyboard for iOS, distributed through the App Store and through managed device deployment. The other Clex products, and the Clex website, are covered by the general Clex privacy policy on clex.ai. Where the two documents describe iOS behaviour differently, this one is the accurate document.
The app is designed for professional care workers who document care activities within their organization’s electronic health record (EHR/EOJ) systems.
3. Our Approach to Privacy
Clex Keyboard is built on a local-first, privacy-by-design architecture:
- The free text you write stays on your device. Clex does not store it and it is not sent to Clex.
- Word prediction, sentence suggestions, sentence correction, translation, speech to text, and read-aloud all run on the device, using language models stored in the app.
- What does leave the device is a licence check, a set of usage measurements, requests for model files, and the keyboard framework’s licence check with its vendor’s EU service. Section 4 lists every field.
- No keystrokes are logged, monitored, or transmitted at any point.
Clex has no integration with, and no access to, the EHR/EOJ system’s databases or interfaces. What the keyboard sees is what iOS makes available in the text field the user is typing in: word suggestions use the text before the cursor that iOS exposes to a keyboard, and sentence correction, rewrite and read-aloud read the whole content of the active field when the user asks for it. All of this is processed on the device. Clex stores none of this text, and none of it is sent to Clex. iOS uses its own keyboard, not Clex, in password and other secure fields, and an app can prevent third-party keyboards entirely.
The usage measurements are daily counts of feature use. They are counted per organisation and calendar day, they carry no identifier for a person, device or installation, and you can switch them off in the Clex app’s settings. Sections 4.2 and 4.3 describe the whole report and what becomes of it.
About the keyboard access warning. When you enable Clex Keyboard and grant it Full Access, iOS displays a standard warning that the keyboard developer may be able to transmit what you type. This warning is shown for all third-party keyboards and is not specific to Clex. Clex Keyboard does not collect, store or transmit the text you type. Section 4 lists everything the app does send, section 5 lists what it never sends, and section 6 describes what Full Access does and does not allow.
Clex is developed as reading and writing support, and it is rolled out to whole teams and used by people with and without reading or writing difficulties. Clex does not ask for, record or infer a diagnosis, and the usage statistics are never linked to a person, device or installation, so Clex cannot derive anything about an individual from them. If your organisation itself links the use of Clex to a named employee, for example as an agreed workplace accommodation, that is your organisation’s own processing and your organisation assesses its legal basis under Article 6 and, where relevant, Article 9. Counting per organisation, reading only organisation totals and the short life of the report number are safeguards, not a legal basis. Nothing in the app switches on or off on the basis of a diagnosis; every feature is available to every user.
4. What Data Is Processed
4.1 What Leaves Your Device
| What is sent | When | Purpose and legal basis |
|---|---|---|
| Your organisation’s licence key, exchanged for a short-lived access token | App start and token refresh | Confirms the app is licensed. Legitimate interest, Article 6(1)(f), see section 7 |
| Your organisation’s activation code (Bring Your Own Device only) | When you activate the app | Same |
| Usage measurements, listed in 4.2 | One report per day of use, uploaded when the device is online | Service reliability, and knowing which features are used. Legitimate interest, Article 6(1)(f), see section 7 |
| Requests for language and model files | First use of a language or feature, and when models are updated | Installs and updates the on-device models. Legitimate interest, Article 6(1)(f), see section 7 |
One further call exists: the third-party keyboard framework the keyboard is built on validates Clex’s framework licence with the framework vendor’s licence service (EU) when the keyboard starts. That request carries the framework licence key and the app identifier - never anything you type or dictate. Beyond this, nothing else is transmitted. There is no request that carries the text you write. A licence file bundled with the app, which removes this call, is decided and ships in a later release.
4.2 The Usage Measurements: What Is in a Report
One report describes one calendar day. This is the whole report, and nothing else:
- the date it describes, as a day only, with no clock times
- the app version, shortened to its first two numbers
- the keyboard language, if it is Danish, Swedish, English or German. Every other language is reported as “none”
- three fixed labels, identical in every report from every device: the name of the report format, the product (“keyboard iOS”) and the platform (“iOS”)
- a random report number, created for that one report, used only so a repeated upload of the same report is not counted twice, and deleted at most 15 days after the report arrives
- the counters: for each measured thing, the number of times it happened that day
If the keyboard language or the app version changes during a day, the day’s counts are split into one report per combination, each still describing only that calendar day.
The counters record how many times a feature was used or failed that day: a suggested word taken, a sentence correction started or accepted, a translation produced, text read aloud, a dictation started, finished, or cancelled, the language or a setting changed, and whether the keyboard and the app were used at all that day. They also record how licence checks, report uploads and model updates went. Response times are reported as counts within fixed ranges, never as individual measurements.
A report never contains what you typed, which app you were typing in, any time of day, any character count, or an identifier for a person, user, device, installation or session. It is sent with your organisation’s access token, section 4.4, so that Clex can tell which organisation the counts belong to, and no more.
You can switch the measurements off, in the Clex app’s settings, with the switch currently labelled “Share anonymous usage statistics”. It is on until you turn it off. Turning it off stops the counting at source and deletes every report not yet sent. To object to this processing in other ways, see section 8.
4.3 What Happens to a Report After It Arrives
This section describes our own servers, because what happens after upload is what decides whether a count can ever be connected to a person.
A report is checked, then added. Our service accepts only the field names listed in 4.2 and only counter names from a fixed list. Anything else is refused. The accepted numbers are validated and added to your organisation’s running daily totals on arrival, and the individual report is not kept.
What is stored is a total, not an event. One stored row is: the date, the organisation, the product, the platform, the app-version bucket, the language, the counter name, and the number. There is no row for a device, an installation, a session, or a person, because no such value reaches the service.
The counts are not held against a person or a device. A usage report contains no identifier for a person, user, device, installation or session. It contains a random report number created for that one report and used only to discard duplicates, and it is sent with your organisation’s access token so that Clex can tell which organisation the counts belong to. The report number cannot link reports from different days or devices; it is deleted at most 15 days after the report arrives. Clex’s service uses the access token only to read the organisation identifier it carries; the token itself is not stored or logged.
We do not store where the report came from. Every network connection necessarily carries the device’s IP address for as long as the connection lasts. Clex’s licence and usage-statistics services do not read or store it, and they do not store browser or device signatures. The usage-statistics endpoint has edge logging switched off. Section 10 describes network logging in full.
The statistics are aggregated, and only totals can be read back. Usage statistics are aggregated: they are counted per organisation and calendar day and carry no identifier for a person, device or installation. Clex reads them only as organisation totals, only internally and only with an internal credential; the language and app-version breakdowns are never returned by the read interface. An organisation can ask for its own totals; Clex then delivers organisation totals only. Clex does not use usage statistics to monitor, evaluate or discipline individual employees, to train models, or to market to individuals, and does not combine them with support cases, access logs or any other data. Clex keeps organisation totals for 24 months. The in-app statistics switch is available to every user on Android, iOS and in Clex Web.
Totals are deleted on a fixed schedule. Organisation daily totals are deleted 24 months after the day they describe, and sooner if your organisation asks or its contract ends. Server backups of licence and statistics data are encrypted, held in the EU and under Clex’s control; a deleted record leaves the most recent backups within 48 hours and every backup within 72 days.
4.4 The Access Token
The token identifies the licensed organisation, its expiry, and a wording label set by Clex (the word the app uses for the person being documented about); it is never a name and your organisation cannot change it. The label is used only on your device, to adapt suggestions. The token carries no name or contact detail for you. It is held in memory only and renewed automatically by the licence service; the organisation identifier and the display label read from it are stored with the app’s settings in the app’s protected shared storage. Clex’s service uses the access token only to read the organisation identifier it carries; the token itself is not stored or logged. The credential the app uses to upload cannot read anything back.
4.5 Model and Language Downloads
Requests for model files carry no account, no licence key and no device identifier. As with any network connection, the request carries your device’s IP address for as long as the connection lasts; the edge network that delivers the file writes its access logs with the last part of the address removed. Section 10 describes network logging in full.
Downloads happen on first use of a language or feature and when models are updated. Model and language files are downloaded over HTTPS from Clex’s servers and verified against the size published in Clex’s file manifest before they are activated; a file that fails the check is discarded. On mobile data the app asks before downloading.
4.6 Local Features (No User Text Transmitted)
These features run on your device. No user text is sent to Clex or to any third party for them:
- Word prediction.
- Sentence suggestions and sentence correction, produced by language models stored in the app.
- Translation. Language files are downloaded once on first use and then kept on the device.
- Read-aloud and text-to-speech, using the device’s built-in voices.
- Speech to text, described in section 6.
No user text is included in any download or network request related to these features. The models are static: they never learn from what is typed, dictated or read, and they are updated only as versioned files from Clex. Machine-generated text can contain errors. A suggestion enters the text only when the care worker accepts it, and checking it professionally before the note is saved remains the care worker’s responsibility; the record is the care worker’s, not the model’s.
4.7 What the App Keeps on Your Device
- Licence data and settings, held in the app’s protected shared storage so that the Clex app and the keyboard work from the same licence and the same settings. The access token itself is held in memory only, section 4.4.
- Model and language files, the versioned files described in 4.5. They hold no text of yours, and they are excluded from device backup.
- Dictated text on its way to the keyboard. Dictated text is transcribed in the Clex app and handed to the keyboard through the app’s protected shared storage; the keyboard deletes it from that storage as soon as it has inserted it, and any leftover from an interrupted hand-over is deleted the next time the keyboard starts. Apart from this hand-over and the Clex Academy profile name you choose, no free text is written to storage.
- Clex Academy. Clex Academy keeps a profile name you choose and your lesson progress in the Clex app’s own storage on the device; nothing of it is sent to Clex. The profile follows your device’s encrypted backup. You delete it by deleting the profile or the app.
Removing the app from your device removes everything in this list.
5. What We Do Not Collect
Through Clex Keyboard for iOS, Clex does not collect or store:
- The text you type or dictate into EHR/EOJ systems or any other application
- The name of the app you are typing in
- The length of what you write. No character counts leave the device
- The time of day you type. A usage report names only the calendar day it describes
- Keystrokes, keystroke timing, or input patterns
- Personal data such as names, addresses, phone numbers, or health records of any individual
- The audio you speak to the app
- Photographs or other user-generated media
- Information from the EHR/EOJ systems where text is entered
- Device contacts, location, call logs, SMS, or browsing history
- Any identifier for a person, user, device, installation or session
The app contains no third-party analytics, crash-reporting, advertising or attribution components. Usage measurements go only to Clex’s own servers.
6. Speech to Text and the Microphone
Speech to text writes down what you say. It is optional. The Clex app asks for microphone permission the first time you use it, and the keyboard works fully if you decline.
iOS does not allow a keyboard itself to use the microphone, so the recording runs in the Clex app: the first time you press the microphone key, and again whenever iOS has closed the Clex app in the background, the keyboard opens the Clex app, which asks for the microphone permission and switches dictation on. Dictation then stays on until you switch it off in the app, which you can do at any time, or until iOS closes the app; it does not switch itself off after a while.
- While dictation is switched on, your device shows the microphone indicator, because the app holds the microphone open so that a recording can start the moment you press the microphone key. Sound that arrives while you are not recording is discarded as it arrives. It is not kept, not interpreted, and not sent anywhere.
- You can switch dictation off in the Clex app at any time; the app then closes the microphone session.
- A recording starts when you press the microphone key and stops when you press it again. It also stops on its own after a pause in speech, and after 30 seconds at most.
- Audio is transcribed by a model stored on the device. It is held in memory while it is transcribed. It is not written to a file, not kept after the transcription, and not uploaded. It is not sent to Apple’s dictation service either.
- The transcription is handed to the keyboard through the app’s protected shared storage and deleted from that storage as soon as the keyboard has inserted it, section 4.7. It arrives in the text field you are writing in the same way as typed text, and no pasteboard is involved.
- Speech to text is available for Danish and Swedish.
About Full Access. iOS keeps a third-party keyboard in a strict sandbox without network access until the user grants Full Access. Clex needs Full Access for four things: the licence check, the daily usage counters, model and language downloads, and the hand-over of dictated text from the Clex app to the keyboard. Full Access is a capability, not a guarantee: it technically allows a keyboard to communicate over the network and to share storage with its app. What keeps typed text on the device is Clex’s design, verified by code review of each release, and the fixed format of the licence and statistics requests, which have no field for free text. iOS uses its own keyboard in password and secure fields, and an app can block third-party keyboards.
The permissions this involves:
| Permission | Why |
|---|---|
| Full Access (keyboard) | The licence check, the usage measurements and the model downloads in section 4, and the hand-over of dictated text from the Clex app to the keyboard |
| Microphone (Clex app) | On-device speech to text. Optional, and the keyboard works without it |
| Background audio (Clex app) | Keeps dictation ready while you write in other apps. The microphone indicator shows the whole time it is on |
7. Roles and Legal Basis (GDPR Article 6)
Who is responsible for what. Roles are assigned per processing activity.
- The notes, messages and other text that care workers write, dictate or have read aloud are processed on the organisation’s own devices and browsers and are never received by Clex. For that processing the organisation is the controller, exactly as for any other text its staff write, and Clex is the supplier of the software, neither a controller nor a processor.
- For licence validation and activation, the connection data that those requests carry, and the daily usage statistics, Clex A/S decides the purpose and the means and is therefore an independent controller. Hetzner Online GmbH and BunnyWay d.o.o. process that data for Clex A/S as processors. On the Swedish market Clex Sweden AB is the contracting party; Clex A/S remains the controller.
- Where Clex processes personal data on an organisation’s documented instructions, for example if the organisation grants Clex diagnostic access during a support case, Clex acts as a processor for that activity, and a data processing agreement under Article 28 is in place before that processing begins. Clex provides a per-activity overview on request; when an organisation’s data protection officer requests a data processing agreement for any other activity, Clex concludes one.
| Processing | Data | Legal basis |
|---|---|---|
| Licence validation and activation | Organisation licence key or activation code, app version, access token | Article 6(1)(f), legitimate interest: operating and securing the licensed service for the organisation. The licence key and the organisation identifier in the token describe the organisation, not a person. |
| Model, dictionary, voice and language downloads | File request, IP address during the connection | Article 6(1)(f), legitimate interest: delivering the product’s language resources. |
| Daily usage statistics | See section 4 (counts per organisation and day, report number, access token) | Article 6(1)(f), legitimate interest: keeping the service reliable and knowing which features are used. You can object at any time by switching statistics off in the app or extension settings. |
Clex’s legitimate-interest assessment for these activities is available from Clex. The care workers who use Clex are normally not party to the agreement between their organisation and Clex, which is why Clex does not rely on Article 6(1)(b) for them. The organisation’s own legal basis for the documentation work Clex assists with is the one it already has for that work; Clex adds no new purpose.
Activation codes for Bring Your Own Device installations expire automatically after a limited period.
We carry out no automated decision-making or profiling within the meaning of Article 22. The app proposes draft sentences and corrections, and the care worker decides whether to use each one. No automated decisions are made about individuals and no profiles are built.
8. Your Rights Under the GDPR
Where the conditions in the GDPR are met you have the right to access, rectify, erase and restrict the processing of personal data about you, and to object to processing based on Article 6(1)(f); the simplest way to object to the usage statistics is to switch them off in the settings. The right to data portability applies only to processing based on consent or contract; of Clex’s own processing, only the website contact form rests on contract, and you can ask us for a copy of what you sent through it. Because usage statistics are counted per organisation and carry no identifier for a person, Clex cannot look up data about an individual in them (Article 11); your organisation can ask Clex to delete all totals belonging to it. Contact: Email us. You can also complain to Datatilsynet (or, in Sweden, Integritetsskyddsmyndigheten).
We answer within one month, as Article 12 requires. That the usage totals cannot be searched for an individual is a consequence of the design in section 4.3, not a refusal. The direct and immediate way to stop the measurements is the switch in section 4.2, which acts at once and needs no request to us.
You can switch usage statistics off at any time in the app’s settings on Android and iOS and on the extension’s settings page in Clex Web; pending reports are deleted when you do.
You can also do these things yourself, at any time, without asking us:
- Switch off the usage measurements, in the Clex app’s settings, section 4.2, which also deletes any reports not yet sent.
- Delete everything held locally, by removing the app from your device.
- Disable the keyboard, in Settings, which stops the keyboard from processing anything further.
- Switch off dictation, in the Clex app, which closes the microphone session, section 6.
- Decline the microphone permission, or withdraw it in iOS Settings. Speech to text is optional and the keyboard works without it.
- Delete your Clex Academy profile, in the Clex app, section 4.7.
Your organisation can ask us to erase every usage total belonging to it, and we do that on request.
You may lodge a complaint with your supervisory authority:
| Country | Authority |
|---|---|
| Denmark | Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk |
| Sweden | Integritetsskyddsmyndigheten, imy.se |
| Germany | The competent federal or state data-protection authority |
9. Data Sharing and Processors
We do not sell, rent, or trade personal data. These providers are involved in delivering the service:
| Processor | Role | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting | Germany (EU) | Not required (EU) |
| BunnyWay d.o.o. (Bunny.net) | Edge network, DDoS protection, authoritative DNS | Slovenia (EU); EU-only edge routing | Not required (EU) |
The app is distributed through the Apple App Store and, in managed deployments, through Apple Business Manager. Apple processes account, device and download data for its own store and device services under its own terms; that processing is not part of Clex’s service and Clex receives none of it.
Read-aloud uses the device’s built-in voices; text is spoken on the device and not sent to any service.
Apart from the processors, the distributor and the framework vendor’s licence service named above, no other service receives data from the app in normal operation. The on-device components process data locally; the only uploads are the licence check, the framework licence check and the usage counters described in section 4.
10. Infrastructure and Data Residency
Clex’s services run on servers operated by Hetzner Online GmbH in Germany. In front of them sits an edge network operated by BunnyWay d.o.o. (Slovenia) that delivers model and language files, protects the services against attack and answers DNS queries; it is configured to route traffic within the EU only. Both companies process data for Clex as processors under written agreements. Everything Clex manages is processed within the EU.
IP addresses and network logs. Every network connection necessarily carries the device’s IP address for as long as the connection lasts. Clex’s licence and usage-statistics services do not read or store it, and they do not store browser or device signatures. The edge network that delivers model files and fronts Clex’s services writes its access logs with the last part of the address removed (the last octet of an IPv4 address, the host part of an IPv6 address); those logs are kept for 72 hours on a rolling basis by the edge provider and are not forwarded or archived. The usage-statistics endpoint has edge logging switched off. Clex’s own servers keep no per-request access log.
Key points:
- No data Clex manages is transferred outside the EU for processing; Apple processes its own store and device data under its own terms.
- Licence validation and usage measurements are received by Clex’s servers in Germany, and model files are delivered from European edge locations only.
- The architecture is designed to keep external service dependencies few and to keep server-side operations inside the EU.
Section 9 names the processors involved.
11. Data Security
Traffic between the app and Clex-managed servers is encrypted in transit. The access token travels only as a credential for that connection and is not stored or logged on our side. Data held on your device stays inside the app’s storage area, protected by iOS’s security model. Server infrastructure is protected using industry-standard security controls.
We apply commercially reasonable security measures. No method of electronic transmission or storage is completely secure, so we design the systems to keep the amount of exposed data small in the first place.
12. Data Retention
| Data | Where | Retained |
|---|---|---|
| Text typed, dictated audio, suggestions, corrections, translations | Device memory only | Discarded when the field or session ends; never stored by Clex |
| Dictated text on its way to the keyboard | Device, the app’s protected shared storage | Deleted as soon as the keyboard has inserted it; a leftover from an interrupted hand-over is deleted the next time the keyboard starts |
| Unsent daily usage report | Device | Until uploaded, at most 14 days; deleted immediately if you switch the measurements off |
| Received daily usage report | Clex usage-statistics service | Validated and added to the organisation’s totals on arrival; the individual report is not kept |
| Report number (duplicate check) | Clex usage-statistics service | At most 15 days |
| Organisation daily totals | Clex usage-statistics service | 24 months after the day they describe, or earlier on the organisation’s request or at contract end |
| Licence validation records | Clex licence service | For the duration of the customer contract |
| Clex Academy profile name and progress | Device, the Clex app’s own storage | Until you delete the profile or the app |
| Edge access logs | Edge provider (EU) | 72 hours, rolling, anonymised IP, not forwarded |
| Server backups of licence and statistics data | Clex-controlled encrypted backups in the EU | A deleted record leaves the most recent backups within 48 hours and every backup within 72 days |
Removing the app from your device removes everything the app has stored on it. Free text from app usage is never held on Clex servers, because it is never sent there.
13. Children’s Privacy
Clex Keyboard is made for professional care workers in an organisational context, including students in care-sector vocational programmes. It is not directed at children, and we do not knowingly collect information from anyone under the age of 16.
14. Changes to This Policy
We update this policy as the app changes. When we do, we change the effective date at the top and post the revised version on our website. Material changes are described rather than made silently. Superseded versions remain available: the version effective 20 August 2026 is archived here, the version effective 18 August 2026 here, and the version effective 11 August 2026 here.
15. Contact
| Purpose | Contact |
|---|---|
| Data protection and general enquiries | Uffe Gorm Pal Hansen - Email us |
| Danish customers | Flakron Sojeva - Email us |
| Swedish customers | Ron Karlsson - Email us |
| Support | Email us |
| Address | Clex A/S, Ewaldsgade 9, 1., 2200 Copenhagen N, Denmark |
