Skip to main content
AIToAsk
|

Privacy Policy — AIToAsk

Last Updated: February 2026
Version: 3.3 (Final)
App: AIToAsk — AI Voice & Text Assistant
Developer: Labeat Krasniqi

Note: This Privacy Policy describes the data processing by the App provider (AIToAsk) as well as the related data transmissions to OpenAI that you trigger with your own OpenAI API key. For processing at OpenAI and for App Store distribution, the terms of the respective providers additionally apply.


Privacy Policy (English)

1. Controller

The controller within the meaning of the GDPR for providing the App and the processing described in this Privacy Policy is:

Labeat Krasniqi
Kreutzerstr. 4, 50672 Cologne, Deutschland
Email: labeat.krasniqi@aitoask.com
Support: support@aitoask.com

We have not appointed a data protection officer, as we are not legally required to do so.

2. What the App does

AIToAsk is a client/interface that lets you use the OpenAI API under your own OpenAI account on a pay‑as‑you‑go basis (Bring Your Own Key). The App provides a user interface for API usage.

  • No server-side content processing by us: We do not operate our own servers that store or analyze your chat content, audio, or documents.
  • Direct connection to OpenAI: When you actively use a feature (send a message, start a voice session, upload a document), your device sends the content directly to OpenAI via encrypted transport (HTTPS/WSS).
  • On-device storage by default: Chat history, settings, and (local) memory are stored on your device. Optional features may store additional objects in your OpenAI account (e.g., Knowledge Base/Vector Store, Cloud Memory).
  • No tracking/ads/analytics: The App contains no tracking or advertising SDKs and no analytics services.

Roles: We are the controller for providing the App, on-device processing, and support communications. OpenAI acts as an independent controller for processing on its systems under your OpenAI account settings and OpenAI's terms. Apple may process personal data in connection with App Store distribution and iOS platform services under Apple's own privacy practices.

3. What data is processed and where?

3.1 On-device processing

The following data may be stored locally on your device. We do not have access to it.

Category Location (example) Purpose
OpenAI API key iOS Keychain Authenticate to the OpenAI API
Chat history SwiftData (local) Display and continue conversations
Memory facts & summaries UserDefaults (local) Personalization/context inside the App
Local document copies (for in-app viewing) App Documents (iOS Data Protection) Show uploaded documents in the App
Settings UserDefaults (local) Configuration (models, options)

Backups: Local app data may be included in iCloud or Finder/iTunes backups. Keychain items are only included in encrypted backups.

3.2 Transfer to OpenAI (only when you actively use the App)

When you actively use the App, content is transmitted directly from your device to OpenAI over encrypted transport (HTTPS/WSS).

Content Trigger Purpose
Text messages & conversation context Send a message / API call Generate AI responses
Audio data (real-time stream) Start a voice session (microphone) Real-time voice interaction
Documents (e.g., PDF, DOCX, CSV) Upload to Knowledge Base RAG/file processing at OpenAI
Search queries (KB/Memory) Trigger a search Retrieve relevant information
Connection metadata (e.g., IP, timestamps) Any connection Technically necessary networking

We do not receive a copy of this content and we do not have access to the data transmitted to OpenAI.

3.3 Storage at OpenAI (under your OpenAI account)

Certain objects may persist at OpenAI beyond immediate request processing. These objects are stored in your OpenAI account and can be managed/deleted there.

Object Typical retention (per OpenAI) Deletion
API request logs (abuse/safety monitoring) Typically up to 30 days; may be longer if legally required or depending on account settings Deleted by OpenAI automatically
Uploaded files (Files API) Until you delete them Delete via the App or OpenAI dashboard
Vector Store entries Until you delete them Delete via the App or OpenAI dashboard (removing from a Vector Store may not delete the underlying file)

According to OpenAI, API data is typically retained for a limited period (commonly up to 30 days) for safety/abuse monitoring, and data from the OpenAI API is not used to train models by default (unless you opt in). Details: https://openai.com/enterprise-privacy.

Manage your OpenAI objects in the dashboard: https://platform.openai.com.

3.4 Support (email)

If you contact us by email, we process your email address and the content you provide in order to handle your request.

Data Purpose Retention
Email address, optional name Respond to/assign your request Until resolved + typically 6 months
Message content/attachments Handle your request Same as above unless longer retention is required

Service providers: Email communication and website hosting are technically handled by our hosting provider (dogado GmbH, Germany) acting as a processor. We only share data where necessary to handle your request or where legally required.

3.5 Website logs

When you visit our website (https://aitoask.com), server logs may be generated (e.g., IP address, timestamp, requested resource, referrer, user agent). This is processed for technical operation, troubleshooting, and security and is typically deleted within 30 days.

3.6 App Store and platform services (Apple)

When you download/update the App via the Apple App Store, and when you use iOS platform services (e.g., optional diagnostic data sharing), Apple may process personal data. We have no influence over this processing. Apple's privacy information applies.

3.7 Data we do not collect

  • No advertising identifiers (IDFA) and no cross‑app tracking
  • No in‑app analytics or usage profiling
  • No location, contacts, or health data
  • No payment/financial data (OpenAI billing is handled exclusively through your OpenAI account)

4. Consents, permissions, and notices

Core functionality (text chat) requires transmitting your input to OpenAI. Without this transmission, the App cannot provide its service.

Separate permissions/consents are used for optional features:

  • Microphone: enabled via the native iOS permission dialog; can be revoked in iOS Settings.
  • File access/document picker: only when you actively select and upload documents.
  • Cloud Memory (optional): opt‑in in App settings; can be turned off at any time.

5. Legal bases (Art. 6 GDPR)

Where GDPR applies, we rely on the following legal bases:

Processing Legal basis
Providing the App and storing necessary on-device data Art. 6(1)(b) GDPR (contract/performance)
Transmitting text/context to OpenAI for core functionality Art. 6(1)(b) GDPR
Microphone/voice feature Art. 6(1)(a) GDPR (consent)
Document upload / Knowledge Base (optional) Art. 6(1)(a) GDPR (consent via active action)
Cloud Memory (optional) Art. 6(1)(a) GDPR (opt-in consent)
Support requests Art. 6(1)(f) GDPR (legitimate interest in support communication)
Website server logs Art. 6(1)(f) GDPR (security/operations)

6. Recipients and international transfers

OpenAI is the recipient of your content because AI processing happens on OpenAI systems. OpenAI may process data outside the EEA (including the United States). The specific transfer mechanisms and safeguards follow from your agreement with OpenAI as the API account holder (e.g., SCCs/DPAs depending on account type). OpenAI provides details in its documentation.

Relevant OpenAI links: Enterprise Privacy, Terms, Usage Policies.

Note: Third countries may not provide a level of data protection equivalent to EU law.

7. Retention and deletion

You can delete local data in the App (chat history, memory, documents). Removing your API key stops OpenAI functionality. Upon uninstall, most local data is removed by iOS; Keychain items may remain until actively removed.

Objects stored at OpenAI (files/vector stores) can be deleted via the App's delete functions or directly in your OpenAI dashboard.

8. Special notes (audio, documents, memory, sensitive data)

  • Voice feature: audio is transmitted as a stream to OpenAI during a voice session. The App does not permanently store audio; only transcribed text is stored in chat history.
  • Document uploads/Knowledge Base: uploaded documents may be stored in your OpenAI account (Files/Vector Stores) until you delete them.
  • Memory: memory facts are stored on-device and may be sent to OpenAI as context. Cloud Memory is disabled by default and only enabled via opt‑in.
  • Sensitive data: please avoid submitting special categories of personal data (Art. 9 GDPR) if you are not willing to share them with OpenAI.

9. Your rights

You have the rights under Art. 15–21 GDPR (access, rectification, erasure, restriction, data portability, objection). Since we do not store your content on our own servers, many requests relate to on-device data or to your OpenAI account.

  • Local access/deletion: in the App.
  • OpenAI account data: via the OpenAI dashboard and/or OpenAI support.
  • Complaint: you may lodge a complaint with a supervisory authority.

We do not make automated decisions within the meaning of Art. 22 GDPR. AI outputs are non-binding and have no legal effect.

10. Security

  • iOS Keychain for API key storage
  • iOS App Sandbox and iOS Data Protection
  • Encrypted transport to OpenAI (HTTPS/WSS)
  • No server-side storage of user content by us

11. Minors

The App may carry a low age rating in the App Store. However, using the App requires an OpenAI API key; OpenAI account creation is governed by OpenAI's terms. We do not collect age data and cannot verify age. Minors should only use the App under parental supervision.

12. Changes

We may update this Privacy Policy to reflect changes to the App, legal requirements, or the services used. The current version is available in the App and on our website.

13. Apple App Store — privacy labels

The App Store privacy labels are maintained in App Store Connect and are intended to reflect the processing described in this Privacy Policy.

  • Data collected by the developer: none.
  • Third-party processing inside the App: OpenAI (API infrastructure).

14. Contact

For privacy questions, contact labeat.krasniqi@aitoask.com.

AIToAsk
Privacy Terms Support Imprint

© 2026 Labeat Krasniqi. All rights reserved.