Privacy Policy
Last updated: August 5, 2026
InkTicker turns a photo of your handwriting into new writing in your style. Handwriting is personal, so this policy is written to be read: what we collect, what stays on your device, and who touches what.
The short version
- Your handwriting profiles and your sign history are stored on your device, not on our servers.
- To write a sign, your handwriting sample and the text you type are sent to our servers and processed by Google's Gemini API for the moments it takes to write it.
- We don't sell your data, we don't show ads, and we don't use your handwriting for anything except writing your signs.
What we collect
- Account information. When you sign in, our authentication provider (Clerk) processes your email address or Apple ID sign-in credential. We use this to keep your credit balance attached to you.
- Handwriting samples. Your profile — including the sample photo — is stored on your device. The photo itself is sent to our servers and on to Google's Gemini API when you capture it (to check the orientation, read your style, and pick out the words you wrote), and again each time you write a sign, because writing in your hand means looking at your hand. Neither our servers nor Google's are used to store it: our writing service keeps no database and no files, and our backend never writes the image to storage.
- The text of your signs. Sent to our servers to be written in your style. Your finished signs and history are stored on your device.
- Purchase records. Payments are handled by Apple. We and our purchases provider (RevenueCat) receive receipts and transaction records — never your card details.
- Reliability telemetry. We record how well writing worked — whether it succeeded, how many retries it took, how long it took, how long your message was, and which style you used — so we can keep quality high. These records are linked to your account. They never contain your handwriting images or the words of your signs.
- Crash reports. When the app or the writing service hits an unexpected error, we receive the error message, where in our code it happened, and your device model, OS version, and app version. Unlike the telemetry above, these are not linked to your account — no name, email, or account identifier is attached, and your IP address is not recorded. We do not record your screen. Handwriting images are stripped out of the report before it is sent; a report can, rarely, quote a fragment of the text you were writing, if that text is what triggered the error.
Who processes data on our behalf
- Google (Gemini API) — performs the image processing that writes your signs. It receives your handwriting and the text of your signs, but no name, email, or account identifier. We use the paid tier, where Google's terms state that your prompts and responses are not used to improve Google's products and are not read by human reviewers. Google logs requests for a limited period to detect abuse, then deletes them.
- Vercel — hosts the writing service your handwriting and sign text pass through. It stores neither; its short-lived request logs are kept for hours, not days.
- Convex — hosts our backend: your account record, credit ledger, and telemetry.
- Clerk — sign-in and account management. If you sign in with Apple, Google, or Facebook, that provider confirms your identity to Clerk.
- RevenueCat & Apple — purchases, receipts, and entitlements. RevenueCat is given your account identifier; it is not given your email.
- Sentry — crash and error reporting for the app and the writing service. It receives the error reports described above and nothing else. Sentry deletes them automatically; on our current plan that is after 30 days.
- Expo — builds the app. It receives no user data.
This website is hosted on Cloudflare and loads its typefaces from Google Fonts, which means visiting these pages tells Google your IP address and browser. The app itself bundles its fonts and makes no such request.
What stays on your device
Handwriting profiles, samples, and your full sign history. Deleting a profile removes it from your device; deleting the app removes everything stored on the device. Because history lives locally, we can't see your old signs — and neither can anyone else with access to our systems.
Other people's handwriting
Only capture handwriting you have permission to use — yours, your kids', a family member's who's happy about it. Don't use InkTicker to imitate someone's writing without their consent.
Data retention and deletion
Server-side we keep the minimum needed to run your account: your sign-in identity (email and display name), your credit ledger, and reliability telemetry. We keep these for as long as your account exists — the credit ledger in particular is append-only, because it is the record of what you bought and what you spent.
Deleting a handwriting profile removes it, and its photos, from your device; it does not remove your account record.
To delete your account, open the menu in the app, tap Account, then Delete account. That removes your sign-in identity (with us and with Clerk), your reliability telemetry, and every handwriting profile and saved sign on the device. What survives is the purchase record: our credit ledger of what was bought and spent, and the matching record at RevenueCat and Apple. We keep those for accounting. They are not attached to your name or email — RevenueCat is never given either one, only an account number that points at nobody once your sign-in is deleted. If you want the purchase record erased too, or you can't get into the app, email [email protected] from the address on the account and we'll do it for you.
Deleting your account does not cancel an InkTicker subscription — only Apple can do that, from Settings → your name → Subscriptions.
Children
InkTicker is not directed at children under 13, and we don't knowingly collect personal information from them. A parent capturing their child's handwriting into a profile on the parent's own device is a lovely and intended use.
Changes
If this policy changes in a way that matters, we'll say so in the app and update the date at the top of this page.