← Back to AEIOU

App privacy policy

AEIOU privacy policy

AEIOU is an intelligent AAC (augmentative and alternative communication) keyboard for iPhone and iPad, built by Chardie. This page explains exactly what AEIOU does, and does not do, with your data. It is written to match the app's actual technical behaviour, and serves as the privacy policy submitted to Apple's App Store.

The short version. AEIOU collects no personal data. Everything you type, every phrase you pin, every blink calibration lives on your device. Camera frames used for blink detection are processed in real time in memory by Apple's ARKit framework and are never recorded, stored, or transmitted, so there is no face data to retain. If you switch on the optional Listen feature, the microphone is used the same way: speech is turned into text entirely on your device and is never recorded, stored, or sent anywhere. There is no Chardie account and no analytics SDK in the app.

Who operates AEIOU

AEIOU is built and operated by Chardie, based in Manchester, United Kingdom. Chardie is the data controller for any personal data processed in connection with the app. As set out below, though, that processing is intentionally minimal.

Data we collect: none

Chardie does not collect any personal data through AEIOU. We have no servers that AEIOU contacts. We do not have a Chardie account system. We do not track you, identify you, or build any profile of your behaviour.

In Apple's App Store privacy taxonomy, the relevant declaration is "Data Not Collected".

What's stored on your device

AEIOU stores the following on your device, in standard iOS storage (UserDefaults) provided by Apple, scoped to the AEIOU app:

  • App settings: your preferences for theme, voice, rate, pitch, scanning behaviour, and so on.
  • Pinned phrases: phrases you have explicitly chosen to keep one tap away.
  • Word and phrase learning: small frequency counts that let predictions improve as you type. Capped to keep storage bounded.
  • Recents: the most recent sentences you have spoken, so you can repeat them with one tap.
  • Blink calibration: the threshold and timing parameters AEIOU has learned for your blink, so the feature works accurately for you.

All of this is on your device. None of it is transmitted to Chardie. Deleting AEIOU removes it. Resetting it inside the app's settings removes it.

Face data and the TrueDepth camera

TrueDepth & face data: at a glance. Addressing App Store Review Guideline 5.1.1(i):

  • Data accessed: two numeric eye-blink values (0.0–1.0) from Apple's ARKit face tracking, never the camera image, depth map, or face mesh.
  • Purpose: solely to detect a deliberate blink as an on-screen selection method for people who cannot reliably tap.
  • Stored: nothing: the values are processed in memory and discarded frame by frame.
  • Retention: none. Real-time, in-memory only; there is no TrueDepth or face data to retain, expire, or delete.
  • Shared with third parties: never. No face data leaves the device, and the app makes no network requests.
  • Advertising & identification: never used for advertising, marketing, profiling, or identifying anyone.
  • Consent & control: optional and off until you enable it. It needs camera permission, and can be switched off in-app or revoked in iOS Settings at any time.

AEIOU is an accessibility keyboard where the user can make a selection in one of two ways: by tapping the screen, or, optionally, by blinking. Blink selection is an optional input method offered as an alternative for users who cannot reliably tap the screen. Granting camera access is not required to use the app; you can use AEIOU entirely with screen taps and never enable the camera.

When you turn on blink selection, AEIOU uses the TrueDepth front camera via Apple's ARKit ARFaceTrackingConfiguration for the sole purpose of detecting deliberate eye blinks. From each camera frame the app reads only two numeric values: the left-eye and right-eye blendShape closure values produced by ARKit (eyeBlinkLeft and eyeBlinkRight, each a number between 0.0 and 1.0).

AEIOU does not access, store, transmit, or share the camera image, the face mesh, the depth map, the face pose, or any other facial feature or blendshape. The two eye-closure values are used in memory in real time and are then discarded. They are not logged, persisted, accumulated, profiled, or used to identify the user.

Retention of face and camera data: none. The camera frames, and the two eye-closure values ARKit derives from them, exist only in volatile memory for the instant they are processed, and are released frame by frame. AEIOU writes no camera image, depth map, face mesh, face pose, or blendshape to storage at any point, so there is no TrueDepth or face data to retain, expire, or delete, on your device or anywhere else. This data is never used for advertising, analytics, profiling, or any purpose other than detecting the blink you are making in that moment, and it is never shared with Chardie or any third party. The camera is active only while blink selection is switched on.

No face data leaves the device. AEIOU contains no analytics, advertising, or crash-reporting SDKs and makes no network requests of any kind. iOS shows the green dot in the status bar whenever the camera is active, which lets you verify for yourself that the camera is only on when blink selection is in use.

When you run the in-app calibration, AEIOU derives a small set of numeric thresholds tuned to your natural blink: a closure threshold, a minimum hold time, a maximum blink duration, an open-eye baseline, a peak amplitude floor, and a minimum peak dwell time. These thresholds are stored locally in the iOS UserDefaults container on your device. They are not face data: they are detector settings, do not describe your face, and cannot be used to identify you. They are removed when you delete the app.

You can disable blink selection at any time from inside AEIOU. You can also revoke camera access entirely in iOS Settings → Privacy & Security → Camera.

Microphone and conversation listening

Microphone & Listen: at a glance. Addressing App Store Review Guideline 5.1.1(i):

  • Data accessed: microphone audio, turned into text on-device by Apple's Speech framework. Only while you have switched Listen on.
  • Whose speech: the other person in the conversation, not you — the point of Listen is to suggest replies to what they say, so you can select one with a blink instead of spelling it out.
  • Purpose: solely to turn nearby speech into text so AEIOU can suggest relevant replies. Nothing else.
  • Processing: entirely on-device, using Apple's on-device Speech recognition (requiresOnDeviceRecognition). AEIOU does not use any server-based or cloud-based speech recognition.
  • Stored: nothing. Audio is never recorded to a file, never saved, and never transmitted anywhere. Transcribed text is held in memory only, to generate suggestions, and is then discarded.
  • Retention: none. Real-time, in-memory only; there is no audio or transcript to retain, expire, or delete.
  • Shared with third parties: never. No audio or transcript leaves the device, and the app makes no network requests.
  • Advertising & identification: never used for advertising, marketing, profiling, or identifying anyone.
  • Consent & control: optional and off by default. It needs microphone and speech-recognition permission, and can be switched off in-app at any time or revoked in iOS Settings.

AEIOU includes an optional Listen feature. It is off by default and only runs while you have explicitly switched it on. Its purpose is to help you reply faster: it listens to what the other person in the conversation is saying and suggests possible replies you can select with a blink, instead of spelling every word out.

While Listen is switched on, AEIOU uses the microphone together with Apple's on-device Speech framework (SFSpeechRecognizer, with requiresOnDeviceRecognition enabled) to turn the other person's speech into text. This happens entirely on your device. AEIOU does not use any server-based or cloud-based speech recognition, and the app makes no network requests of any kind — this is true of every feature in AEIOU, including Listen.

Audio is never recorded to a file, saved, or transmitted anywhere. The transcribed text is held in memory only, for the sole purpose of suggesting replies, and is discarded shortly after. Where the app briefly needs the general shape of the conversation to suggest a relevant next reply (for example, a topic mentioned a moment ago), that context is also kept in memory on the device and is not written to persistent storage or sent off the device.

Reply suggestions, including those generated while Listen is on, are produced using Apple's on-device Foundation Models framework, which runs locally on the device. No transcript, suggestion, or conversation content is sent to Apple, to Chardie, or to any other party.

The microphone is active only while Listen is switched on and is released the moment you switch it off. Listen is entirely optional — AEIOU is fully usable for typing and speaking your own words without ever enabling it. You can revoke microphone or speech recognition access at any time in iOS Settings → Privacy & Security.

Speech and Personal Voice

AEIOU speaks the text you compose using Apple's AVSpeechSynthesizer. Speech happens locally on your device using the system voices installed by iOS. AEIOU does not send your text to any speech service operated by Chardie or any third party.

On iOS 17 and later, AEIOU can read text in your Personal Voice, an Apple feature that lets you record a model of your own voice. Personal Voice is recorded by you in iOS Settings → Accessibility → Personal Voice, not in AEIOU. Apple stores the voice model on your device and protects it under your device authentication. AEIOU only requests access to use voices you have already created, and that access can be granted or revoked at any time in iOS Settings.

iCloud sync (optional)

If you enable iCloud sync, AEIOU stores a small portable subset of your data (your pinned phrases, your most recent spoken sentences, and your app settings) using Apple's NSUbiquitousKeyValueStore. This places the data in your own iCloud account, encrypted by Apple, so that a paired iPhone or iPad signed in to the same iCloud account can pick it up. Word and phrase learning and blink calibration never sync. They stay local to each device.

Chardie cannot see this data. It is your iCloud, your encryption keys, and entirely under your control. You can disable iCloud sync inside AEIOU at any time, and you can revoke iCloud access for AEIOU in iOS Settings → [your name] → iCloud.

Data retention and deletion

Because AEIOU keeps everything on your device and sends nothing to Chardie, retention is entirely in your hands. Chardie holds no copy of any of it, because Chardie receives none of it. Here is how long each kind of data exists, and how it is removed:

  • TrueDepth camera frames and face data: not retained. Processed live in memory by Apple's ARKit and released frame by frame. No camera image, depth map, face mesh, face pose, or blendshape is ever written to storage. Retention period: none. Real-time, in-memory only.
  • Microphone audio and conversation transcripts (Listen, optional): not retained. Processed live, on-device, by Apple's Speech framework. Audio is never recorded to a file; transcribed text and reply suggestions are held in memory only and discarded shortly after use. Retention period: none.
  • Blink calibration settings: kept until you remove them. The small set of numeric thresholds produced by calibration is stored in on-device UserDefaults so blink selection keeps working accurately for you. These are detector settings, not face data. They remain until you recalibrate, reset them in the app's settings, or delete AEIOU.
  • Typed text: not retained as a log. AEIOU keeps no running record of everything you type. Text you compose exists only until it is spoken or cleared.
  • Word and phrase learning: kept until you reset or delete. Small, size-capped frequency counts held on your device. Removed when you reset learning in the app's settings or delete AEIOU.
  • Pinned phrases and Recents: kept until you remove them. Stored on your device so they stay one tap away. Deleted individually inside the app, or all at once by deleting AEIOU.
  • App settings: kept until reset or delete. Your preferences stay on your device until you reset them or remove AEIOU.
  • iCloud sync data (only if you enable it): kept until you disable it. A small subset (your pinned phrases, recent spoken sentences, and app settings) lives in your own iCloud account, encrypted by Apple, until you turn sync off or delete AEIOU. Chardie cannot see it.

Deleting AEIOU removes every piece of on-device data listed above. There is no Chardie-side copy to request, export, or erase, because none is ever created. The one exception is any support email you choose to send us, which lives in our mailbox. See Contact and the Chardie privacy policy.

Third parties

AEIOU does not embed any third-party analytics, advertising, attribution, crash-reporting, A/B-testing, or feature-flagging SDKs. The only external code in the app is Apple's own iOS frameworks (SwiftUI, UIKit, Foundation, ARKit, AVFoundation, NaturalLanguage, FoundationModels, Combine).

Use by children and vulnerable users

AEIOU is designed to be safe to use for people of any age, including children, and for users who may rely on a carer to set the app up. Because AEIOU collects no personal data, there is no Chardie-side profile that could be built about a child or vulnerable user. Carers and parents are responsible for any iOS Family Sharing controls they wish to apply at the device level.

Permissions AEIOU requests

  • Camera: only if you choose to use blink detection. Used live by ARKit to detect blinks, in memory, on-device.
  • Microphone and speech recognition: only if you switch on the optional Listen feature. Used to turn the other person's speech into text, entirely on-device, so AEIOU can suggest replies. Released the moment Listen is switched off.
  • Speech audio output: to play synthesised speech aloud through the device.
  • Personal Voice (iOS 17+): only if you have created a Personal Voice and choose to use it for AEIOU's speech.
  • iCloud: only if you turn on AEIOU's iCloud sync. Uses your existing iCloud account.

AEIOU does not request access to your contacts, calendar, photos, location, health data, motion data, Bluetooth devices, or local network.

Apple privacy manifest

AEIOU ships with an Apple PrivacyInfo.xcprivacy manifest declaring exactly which Apple "required reason" APIs it touches and why. Today that manifest declares:

  • NSPrivacyTracking: false. AEIOU does not track users across apps or websites.
  • NSPrivacyTrackingDomains: empty. AEIOU does not contact any tracking domains.
  • NSPrivacyCollectedDataTypes: empty. AEIOU collects no data types.
  • NSPrivacyAccessedAPITypes: UserDefaults under reason CA92.1 (access info from same app, per Apple documentation), used for word/phrase learning history, blink calibration parameters, and the user's app settings.

Camera and microphone access are not "required reason" API categories under Apple's privacy manifest system; they are governed by the camera, microphone, and speech-recognition usage descriptions iOS shows you the first time each is used, and by the permission toggles in iOS Settings.

Your rights under UK GDPR

Under the UK General Data Protection Regulation, you have the right to ask whether we hold personal data about you, to ask us to correct it, to ask us to delete it, and to complain to the Information Commissioner's Office (ico.org.uk) if you believe we have mishandled it.

Because Chardie does not collect personal data through AEIOU, there is nothing on Chardie's side to disclose, correct, or delete. Your data is on your device. To remove the on-device data, delete AEIOU from your device, or use the reset controls inside the app.

Changes to this policy

If we materially change how AEIOU handles data, we will update this page, change the "last updated" date at the top, and submit the updated policy to the App Store. Where appropriate we will also surface the change inside AEIOU itself the next time you open it.

Contact

Questions, concerns, or requests under UK GDPR: please email contact@chardie.co.uk. We aim to reply within five working days.

Data controller: Chardie · Manchester, United Kingdom · chardie.co.uk