DXY AI ("we", "our", or "us") is an AI keyboard extension for iOS and Android developed by Digital Yahiya and operated via dxy.leadboard.ae. This Privacy Policy explains how we handle information in connection with your use of the DXY AI apps and keyboard extension.
By installing and using DXY AI you agree to the terms described in this policy. If you do not agree, please discontinue use and delete the application.
This policy applies to:
- DXY AI AppsThe companion apps available on the Apple App Store and Google Play
- DXY AI Keyboard ExtensionThe custom keyboard that runs inside any app on your device
- DXY AI Backend APIThe Laravel-powered service at dxy.leadboard.ae that powers AI features
We collect only the data necessary to operate the service. Below is a complete breakdown:
| Data Type | What It Includes | Collected? |
|---|---|---|
| Account information | Name, email address, hashed password | Yes |
| AI transform requests | Text you submit to the AI panel (not ambient keystrokes) | Yes — see §5 |
| Usage & quota | Daily AI call count, remaining quota, plan tier | Yes |
| Device metadata | OS version, device model, app version (no persistent UDID) | Yes |
| Ambient keystrokes | Everything you type while the keyboard is active | Never |
| Clipboard content | Content you copy/paste | Never |
| Location data | GPS or IP-based location | Never |
| Contact / photos | Your contacts, camera roll, microphone | Never |
| Ad interaction | Whether a rewarded ad was watched (no ad profile) | Limited |
Full Access is required by the OS for keyboard extensions to function, but we do not use full access to read your general keystrokes. Full access is used solely to reach our API for AI transforms you explicitly trigger.
Service Delivery
Account authentication, AI transform processing, quota tracking, and subscription management.
Quality & Safety
Detecting abuse or policy violations. We review flagged requests only — not routine transforms.
Product Improvement
Aggregate, anonymised usage patterns (action types, error rates) to improve AI performance.
Communications
Service announcements, quota warnings, and policy updates to your registered email address.
We do not use your data for advertising profiling, sell it to data brokers, or share it with employers or government agencies except as required by law.
We share data only with the sub-processors needed to run the service:
- Groq, Inc. — AI InferenceText you submit to the AI panel is forwarded to Groq's API to generate a response. Groq's privacy policy governs their handling.
- Google AdMob — Rewarded AdsIf you watch a rewarded ad to restore quota, the Google AdMob SDK is invoked. Their standard ad privacy controls apply.
- Server InfrastructureOur backend runs on VPS infrastructure. No data is stored outside of this server.
We will disclose data if required by a valid court order or applicable law, and will notify you where legally permitted.
Only explicit AI requests are transmitted. DXY AI does not log, buffer, or transmit the general text you type in any app. Data reaches our server only when you tap an AI action button (Rephrase, Translate, Fix, etc.).
When you submit text to the AI panel:
- What is sentThe selected text, chosen action, and target language (if translate). Nothing else.
- TransmissionHTTPS/TLS 1.3 encrypted. Your Bearer token authenticates the request.
- RetentionTransform payloads are not stored on our server after the response is returned. Groq's data retention policies apply to their side.
- Avoid sensitive dataDo not submit passwords, financial details, or medical information through the AI panel.
| Data | Retention Period | Reason |
|---|---|---|
| Account (email, name) | Until account deletion | Required for service access |
| Daily quota counters | Rolling 30 days | Quota enforcement & history |
| AI transform payloads | Not retained (in-flight only) | Privacy by design |
| Server access logs | 7 days | Abuse detection & debugging |
| Subscription records | 7 years | Legal & financial obligation |
| Deleted account data | 30 days post-deletion | Fraud prevention window |
Transport Security
All client–server traffic uses HTTPS with TLS 1.2+ enforced by Nginx. HTTP requests are redirected automatically.
Authentication
Laravel Sanctum Bearer tokens. Passwords are hashed with bcrypt (cost factor 12). Tokens are scoped and revocable.
API Key Isolation
Third-party API keys (Groq, etc.) never leave the server. They are stored in server-side .env — never shipped in the app binary.
Rate Limiting
AI endpoints are rate-limited per user per day. Brute-force login attempts trigger automatic lockout via Laravel's throttle middleware.
No system is 100% secure. If you discover a security issue please report it to security@dxy.leadboard.ae before disclosing it publicly.
DXY AI is not directed at children under 13 years of age (or under 16 in the European Economic Area). We do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@dxy.leadboard.ae and we will delete that information promptly.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- AccessRequest a copy of the personal data we hold about you.
- CorrectionRequest that inaccurate or incomplete data be corrected.
- DeletionRequest deletion of your account and associated personal data.
- PortabilityReceive your data in a machine-readable format (JSON or CSV).
- ObjectionObject to processing based on legitimate interests.
- Withdraw ConsentWhere processing is consent-based, you may withdraw at any time by deleting the app.
To exercise any right, email privacy@dxy.leadboard.ae. We will respond within 30 days.
| Service | Purpose | Data Shared | Policy |
|---|---|---|---|
| Groq API | LLM inference | AI prompt text | groq.com |
| Google AdMob | Rewarded ads | Ad interaction signals | google.com |
| Apple App Store | App distribution & IAP | Purchase records (Apple-managed) | apple.com |
| Google Play | App distribution & billing | Purchase records (Google-managed) | google.com |
We may update this Privacy Policy from time to time. When we do:
- Minor changesUpdated silently with a revised "Effective" date shown at the top of this page.
- Material changesYou will receive an in-app notification and/or an email to your registered address at least 14 days before the change takes effect.
- Continued useUsing DXY AI after the effective date of a revised policy constitutes acceptance of the changes.
Previous versions of this policy are available on request.
Privacy questions or requests?
We aim to respond to all enquiries within 2 business days.
Developer
Digital Yahiya
Dubai, UAE
Service URL
dxy.leadboard.ae
Operated by Leadboard