Legal

Privacy Policy

Last updated: June 3, 2026

Quips is an AAC (Augmentative and Alternative Communication) app built for non-speaking individuals. We believe privacy is a right, not a feature. This policy explains exactly what data the app collects, where it goes, and how you control it.

Quips is available internationally. Our servers and several of our service providers are located in the United States, so using Quips from another country — including Singapore, the EU/EEA, and the UK — involves transferring your data internationally. See International Users & Data Transfers and the country-specific rights described below.

What We Collect

Account Data

Stored in Google Firebase when you create an account:

  • Email and display name — authentication and account identification
  • Age group — whether you are 13+ or under 13 (restricts AI features)
  • Account timestamps — when your account was created and last used
  • AI consent records — opt-in/out status, timestamp, and consent version

Users under 13 are signed in anonymously. No email or password is collected for under-13 accounts.

AI Feature Data

Optional · 13+ Only

If you are 13+ and consent, the app sends the following to OpenAI's API:

  • The letters you've typed so far (current word prefix)
  • Recent words in your current message (for context)
  • Personal vocabulary patterns (frequent words/phrases learned on-device)
  • A device identifier for rate limiting

Data is sent only while typing with AI enabled. Not stored after prediction. See OpenAI's privacy policy. You can revoke consent anytime in Settings.

Cloud Voice Synthesis Data

Optional · Consent required

If you select an "AI voice (cloud)" in Voice & Speech settings, the following is sent to Inworld AI for text-to-speech synthesis:

  • The text you tap Speak on (one utterance at a time)
  • The selected voice ID (e.g., "Ashley", "Diego") and audio configuration
  • A device identifier for rate limiting (handled by our server, not forwarded to Inworld)

No microphone audio is captured — this is text-to-speech only. Your name, email, and account ID are never sent. See Inworld's privacy policy. Apple's on-device voices remain available as the default and as a fallback.

Quiz & Learning Data

If you complete quizzes assigned through the app, the following is stored in Firebase:

  • Question ID, whether you answered correctly, number of attempts, and timestamp

Local Device Data

On-device by default

Created and stored on your device. While you're signed in with an account, Cloud Sync (see below) also backs up some of this to your private account so it follows you across devices:

  • Word learning history — usage frequency and context for on-device personalization
  • Saved documents — letters, math expressions, and other work
  • Board layouts and preferences — customized keyboard arrangements and settings
  • Language preference — English or Spanish
  • Recent message contacts — names and phone numbers saved for quick re-use (synced to your private account while you're signed in)

Word learning, board layouts, and recent contacts are included in optional Cloud Sync (see below). Saved documents and your language preference stay on the device only.

Cloud Sync & Backup

Optional · Your private account

When you're signed in with a standard (13+) account, Cloud Sync backs up the following to your own private, access-controlled space in Google Firebase so it stays in sync across your devices:

  • Communicator profiles, custom boards, and layout presets
  • Voice & speech settings, saved phrases, and word-learning history
  • Recent contacts (names and phone numbers)
  • Custom tile images and any audio you record for boards

Only you can read this data — it is protected by per-account authentication rules and encrypted in transit. It is never shared with other users or third parties, and never used for advertising or analytics. Cloud Sync is unavailable for anonymous (under-13) accounts, and deleting your account erases it.

Diagnostics & Crash Data

Released builds only

To find and fix bugs, the released app reports the following to Google Firebase Crashlytics when something goes wrong:

  • Crash and non-fatal error reports, including the operation that failed (e.g. "sign-in")
  • Device model, operating-system version, and diagnostic identifiers generated by Crashlytics
  • Your account ID, so a report can be linked to a support request

Your typed messages, spoken text, and communication content are never included in crash reports. This data is used only to diagnose and fix problems — never for advertising, profiling, or tracking. Crash reporting is disabled in development builds.

How We Use Your Data

Authentication

To sign you in and maintain your account

Word Prediction

Cloud AI requires consent; offline dictionary works without it

Personalization

Learn your vocabulary and improve predictions over time (all on-device)

Age-Appropriate Access

Ensures users under 13 cannot access cloud AI features without parental consent

Voice Synthesis

Apple voices work offline by default; cloud voices require consent and are spoken aloud only

Third-Party Services

Service What It Receives Why
Google Firebase Account data, age group, consent records, quiz results, Cloud Sync content (when signed in), and crash/diagnostic data Authentication, data storage, cross-device sync, and crash diagnostics
OpenAI Typed text context (with consent only) AI-powered word prediction
Inworld AI Utterance text and voice ID (with consent and a cloud voice selected only) High-quality cloud text-to-speech voices

All three providers are based in the United States, so using Quips from another country involves an international data transfer (see below). No other third-party services receive your data. The app contains no analytics SDKs, no ad networks, and no tracking pixels.

Children's Privacy

Quips takes children's privacy seriously:

Under-13 users sign in anonymously — no email or password collected

Cloud AI off by default for under-13 users — text is sent to OpenAI or Inworld only after a parent or guardian grants consent in caregiver settings

Full access to all boards with the offline 50,000-word dictionary

Quiz results are the only data stored remotely for under-13 users

Older minors and supported decision-making

Quips is likely to be used by children, and by people who communicate with support. Where a user is under 13 — or is a minor or adult who may not fully understand what enabling a cloud feature means — a parent, guardian, or authorised caregiver reviews and manages consent on their behalf, and AI and cloud features stay off until they choose to turn them on. For users aged 13–17 who manage their own account, we keep these choices and our explanations in plain language and default to the most protective settings.

This reflects the U.S. Children's Online Privacy Protection Act (COPPA) and Singapore's PDPC Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment. We act in the best interests of the child, collect only what a feature needs, and never use a child's data for advertising or profiling.

Your Controls

Revoke AI Consent

Go to Settings and turn off AI features at any time. Predictions switch to offline-only mode immediately.

Delete Your Account

In Settings, tap "Delete Account." This permanently removes all your data from Firebase, including consent records and quiz results.

Manage iOS Permissions

Camera, microphone, photos, and contacts permissions can be revoked anytime in iOS Settings. The app only uses these when you explicitly activate features that need them.

Clear Local Data

Signing out or uninstalling the app removes locally stored learning data, documents, and preferences.

Access or Correct Your Data

You can ask for a copy of the personal data we hold about you, or ask us to correct it. Email our Data Protection Officer at contact@quips.org and we'll respond within the timeframe required by your local law.

Control Cloud Sync

Cloud Sync runs only while you're signed in with a standard (13+) account; it never runs for anonymous or under-13 accounts. Sign out to stop syncing, and delete your account to erase the cloud copy.

Device Permissions

Permission Used For Data Sent Remotely?
Camera Head tracking (ARKit) and video recording No
Microphone Audio recording for communication videos No
Photos Adding images to communication boards No
Contacts Selecting recipients when sending messages No

Face Data & Head Tracking (TrueDepth API)

Quips includes an optional head tracking feature that uses Apple's TrueDepth camera and ARKit as an accessibility input method for users with motor differences. Head tracking is off by default and only activates when the user enables it in Settings. The TrueDepth camera is never accessed unless head tracking is turned on.

What face data is collected

When head tracking is enabled, the app reads the following from the TrueDepth camera via ARKit each frame:

  • Head orientation — pitch, yaw, and roll from the ARFaceAnchor transform matrix
  • Eye gaze direction — the ARFaceAnchor lookAtPoint (collected by the tracking framework but not currently used in any user-facing feature)
  • Blend shape coefficients — a limited subset (jaw open, smile, blink, eyebrow raise, tongue out, cheek puff, jaw left/right) collected by the tracking framework but not currently used in any user-facing feature

The app does not capture facial geometry, depth maps, or 3D face meshes. No biometric identifier or faceprint is created.

How this data is used

Currently, only head orientation is actively used — it is mapped to an on-screen cursor so the user can navigate the app by moving their head. Eye gaze and blend shape data are read by the underlying tracking framework but are not used in any feature today. No profiling, identification, expression analysis, or machine learning is performed on any of this data.

Storage, retention, and sharing

All face data is processed in volatile memory (RAM) only — each frame is consumed, converted to a cursor position, and immediately discarded. No face data is written to disk, saved to any database, or sent over the network. Face data is never shared with any third party. The only tracking-related data saved to the device is your configuration preferences (sensitivity, smoothing). These are user settings, not face data.

Disabling head tracking

Turn off "Enable Head Tracking" in Settings at any time. When disabled, the TrueDepth camera is not accessed and no face data is collected. You can also revoke camera permission in iOS Settings.

Data Storage & Security

🔒

All network communication uses HTTPS encryption

🔒

Custom API keys stored in the iOS Keychain (hardware-encrypted)

🔒

Learning data stays on your device and is never uploaded

🔒

Firebase data protected by authentication rules — only you can access it

Data Retention & Deletion

Account deletion permanently removes all Firebase data (user profile, consent records, quiz results) and your authentication credentials

Local data (documents, learning history, preferences) persists on the device until you sign out or uninstall the app

We do not retain data after account deletion

What We Don't Do

×

Collect analytics or usage metrics

×

Show ads or use ad networks

×

Sell or share data with data brokers

×

Track your location

×

Use crash or diagnostic data for anything but fixing bugs

×

Use fingerprinting beyond a device ID for rate limiting

Third-Party Content

Pictographic symbols used in this app are created by Sergio Palao for ARASAAC, funded by the Government of Aragon (Spain), and distributed under a Creative Commons BY-NC-SA license.

These symbols are used for non-commercial, educational communication purposes in accordance with the license terms.

International Users & Data Transfers

Quips is operated from the United States, and our service providers — Google Firebase (authentication, database, storage, and crash diagnostics), OpenAI (optional word prediction), and Inworld AI (optional cloud voices) — process data on servers in the United States.

If you use Quips from outside the United States — including Singapore, the EU/EEA, and the United Kingdom — your personal data is transferred to and processed in the U.S. We rely on the data-processing agreements and contractual safeguards offered by these providers to ensure your data receives a standard of protection comparable to that in your home country. We transfer only the data described in this policy, and we do not sell it or use it for advertising.

Your Rights in Singapore (PDPA)

If you are in Singapore, we handle your personal data in line with the Personal Data Protection Act 2012 (PDPA). This section summarises your rights and how we meet our obligations.

Consent & purpose

We collect, use, and disclose your personal data only for the purposes described in this policy — running your account, on-device personalisation, optional AI prediction and cloud voices, optional cross-device sync, and fixing bugs. We obtain your consent where the law requires it, and you can withdraw consent at any time (for example, by turning off AI features in Settings, by signing out to stop Cloud Sync, or by deleting your account).

Access & correction

You may request access to the personal data we hold about you and information on how it has been used, and you may ask us to correct anything inaccurate. Contact our Data Protection Officer (below) and we will respond as soon as reasonably possible, and in any case within the time the PDPA requires.

Transfers outside Singapore

Your data is processed in the United States (see International Users & Data Transfers). In line with the PDPA's Transfer Limitation Obligation, we take steps to ensure overseas recipients protect your data to a standard comparable to the PDPA, through their data-processing agreements and contractual commitments.

Children's data

We follow the PDPC's Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment. We obtain parental or guardian consent for children under 13 and apply the most protective settings by default. See the Children's Privacy section above.

Data Protection Officer

Our Data Protection Officer is responsible for ensuring we comply with the PDPA. You can reach our DPO with any question, request, or complaint at contact@quips.org (subject line: "DPO / PDPA"). If you are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC).

Data Breach Notification

We maintain safeguards to protect your data. If a data breach occurs that is likely to result in significant harm to you, or that otherwise meets the notification thresholds under applicable law, we will notify the relevant authority — including Singapore's PDPC where required — and affected users without undue delay and within the timeframes the law requires (for Singapore, within 3 calendar days of determining that a breach is notifiable). Our notice will explain what happened, what data was involved, and the steps you can take to protect yourself.

Changes to This Policy

If we make material changes, we'll update this page and the "Last updated" date. For significant changes affecting data collection, we'll notify users in the app.

Contact

Questions about this privacy policy or your data? Reach out at contact@quips.org or email quipsaac@gmail.com.

For data-protection requests (access, correction, deletion, or a complaint), contact our Data Protection Officer at contact@quips.org with the subject "DPO / PDPA".