Privacy
What stays on the device, what leaves it, and the one place where that distinction needs care.
Speech never depends on a network
Vocabulary, topic routing, the grammar engine and the voice all run on the iPad itself. There is no server in the speech path, no cloud inference, and no difference in behaviour offline.
Audio
The app stores no audio and transmits no audio. Nothing the AAC user themselves does is ever recorded as audio at any point — tile taps are taps.
The one place audio exists at all is Listening Mode, the button that transcribes what a conversation partner says in order to choose which tiles to show. Transcribed text is used to pick tiles and then discarded: not saved, not logged, not backed up.
Practically: Listening Mode is optional. Nothing is captured unless the button is pressed, and every word in the app is reachable without it through Topics, Search and Type. If your school or clinic requires that no student or patient speech leaves the device, staff can simply not use it, and the system remains fully functional.
What is backed up
Only where a school or clinic has configured an account. Without one, the app runs entirely locally and nothing is sent anywhere at all.
When an account is configured, the app backs up:
- People and pets, with their photos
- Custom words and saved phrases
- Pinned words and home screen arrangement
- Recently spoken sentences
- Word-prediction learning
- Voice and app settings
Sign-in tokens and licence state stay on the device and are never synced.
Reports
Sentences the user speaks are stored on our servers when an account is configured. Each spoken sentence is recorded as an individual event, which is what the progress reports are calculated from. The reports themselves are counts and word inventories, not transcripts — there is no screen anywhere that plays back what somebody said — but the underlying sentence text is retained so those reports can be produced.
A report is reachable only by someone the user has explicitly linked, using an invite code the user generated. There is no directory and no way to look a user up from the other side. The user can see everyone linked to their account and remove any of them at any time. Clearing history in the app also erases the stored events behind these reports.
Anything spoken with Supporter modeling on is excluded entirely.
Usage analytics
The app records aggregate daily counters — how many sentences were spoken, how many tiles were tapped, how many times Listening Mode was used — attached to the account and the date. No content is in them: not what was said or typed, not which words were chosen, not which topics were opened, and no timestamp finer than the day.
This is separate from the reports above: turning analytics off does not affect reports, and clearing history does not affect analytics. It is on by default and can be turned off in Settings → Share anonymous usage data; switching it off discards anything not yet uploaded, and applies to every device on the account. Counters are kept for around 13 months and are erased with the account.
Sharing
Nothing is shared with any third party. If that ever changes, it will be opt-in: off by default and never switched on by an update, explained before you choose, with no penalty for declining, and revocable at any time.
Voices
No voice data ships with the app. Speech is synthesised by the iPad, using voices Apple has already licensed to that device. Nothing is sent anywhere to produce it.
Payment
There is no purchasing inside the app, and no payment information passes through it. Licensing is arranged institutionally, outside the app entirely.