Privacy Policy — AIToAsk
Last Updated: February 2026
Version: 3.3 (Final)
App: AIToAsk — AI Voice & Text Assistant
Developer: Labeat Krasniqi
Note: This Privacy Policy describes the data processing by the App provider (AIToAsk) as well as the related data transmissions to OpenAI that you trigger with your own OpenAI API key. For processing at OpenAI and for App Store distribution, the terms of the respective providers additionally apply.
Privacy Policy (English)
1. Controller
The controller within the meaning of the GDPR for providing the App and the processing described in this Privacy Policy is:
Labeat Krasniqi
Kreutzerstr. 4, 50672 Cologne, Deutschland
Email: labeat.krasniqi@aitoask.com
Support: support@aitoask.com
We have not appointed a data protection officer, as we are not legally required to do so.
2. What the App does
AIToAsk is a client/interface that lets you use the OpenAI API under your own OpenAI account on a pay‑as‑you‑go basis (Bring Your Own Key). The App provides a user interface for API usage.
- No server-side content processing by us: We do not operate our own servers that store or analyze your chat content, audio, or documents.
- Direct connection to OpenAI: When you actively use a feature (send a message, start a voice session, upload a document), your device sends the content directly to OpenAI via encrypted transport (HTTPS/WSS).
- On-device storage by default: Chat history, settings, and (local) memory are stored on your device. Optional features may store additional objects in your OpenAI account (e.g., Knowledge Base/Vector Store, Cloud Memory).
- No tracking/ads/analytics: The App contains no tracking or advertising SDKs and no analytics services.
Roles: We are the controller for providing the App, on-device processing, and support communications. OpenAI acts as an independent controller for processing on its systems under your OpenAI account settings and OpenAI's terms. Apple may process personal data in connection with App Store distribution and iOS platform services under Apple's own privacy practices.
3. What data is processed and where?
3.1 On-device processing
The following data may be stored locally on your device. We do not have access to it.
| Category | Location (example) | Purpose |
|---|---|---|
| OpenAI API key | iOS Keychain | Authenticate to the OpenAI API |
| Chat history | SwiftData (local) | Display and continue conversations |
| Memory facts & summaries | UserDefaults (local) | Personalization/context inside the App |
| Local document copies (for in-app viewing) | App Documents (iOS Data Protection) | Show uploaded documents in the App |
| Settings | UserDefaults (local) | Configuration (models, options) |
Backups: Local app data may be included in iCloud or Finder/iTunes backups. Keychain items are only included in encrypted backups.
3.2 Transfer to OpenAI (only when you actively use the App)
When you actively use the App, content is transmitted directly from your device to OpenAI over encrypted transport (HTTPS/WSS).
| Content | Trigger | Purpose |
|---|---|---|
| Text messages & conversation context | Send a message / API call | Generate AI responses |
| Audio data (real-time stream) | Start a voice session (microphone) | Real-time voice interaction |
| Documents (e.g., PDF, DOCX, CSV) | Upload to Knowledge Base | RAG/file processing at OpenAI |
| Search queries (KB/Memory) | Trigger a search | Retrieve relevant information |
| Connection metadata (e.g., IP, timestamps) | Any connection | Technically necessary networking |
We do not receive a copy of this content and we do not have access to the data transmitted to OpenAI.
3.3 Storage at OpenAI (under your OpenAI account)
Certain objects may persist at OpenAI beyond immediate request processing. These objects are stored in your OpenAI account and can be managed/deleted there.
| Object | Typical retention (per OpenAI) | Deletion |
|---|---|---|
| API request logs (abuse/safety monitoring) | Typically up to 30 days; may be longer if legally required or depending on account settings | Deleted by OpenAI automatically |
| Uploaded files (Files API) | Until you delete them | Delete via the App or OpenAI dashboard |
| Vector Store entries | Until you delete them | Delete via the App or OpenAI dashboard (removing from a Vector Store may not delete the underlying file) |
According to OpenAI, API data is typically retained for a limited period (commonly up to 30 days) for safety/abuse monitoring, and data from the OpenAI API is not used to train models by default (unless you opt in). Details: https://openai.com/enterprise-privacy.
Manage your OpenAI objects in the dashboard: https://platform.openai.com.
3.4 Support (email)
If you contact us by email, we process your email address and the content you provide in order to handle your request.
| Data | Purpose | Retention |
|---|---|---|
| Email address, optional name | Respond to/assign your request | Until resolved + typically 6 months |
| Message content/attachments | Handle your request | Same as above unless longer retention is required |
Service providers: Email communication and website hosting are technically handled by our hosting provider (dogado GmbH, Germany) acting as a processor. We only share data where necessary to handle your request or where legally required.
3.5 Website logs
When you visit our website (https://aitoask.com), server logs may be generated (e.g., IP address, timestamp, requested resource, referrer, user agent). This is processed for technical operation, troubleshooting, and security and is typically deleted within 30 days.
3.6 App Store and platform services (Apple)
When you download/update the App via the Apple App Store, and when you use iOS platform services (e.g., optional diagnostic data sharing), Apple may process personal data. We have no influence over this processing. Apple's privacy information applies.
3.7 Data we do not collect
- No advertising identifiers (IDFA) and no cross‑app tracking
- No in‑app analytics or usage profiling
- No location, contacts, or health data
- No payment/financial data (OpenAI billing is handled exclusively through your OpenAI account)
4. Consents, permissions, and notices
Core functionality (text chat) requires transmitting your input to OpenAI. Without this transmission, the App cannot provide its service.
Separate permissions/consents are used for optional features:
- Microphone: enabled via the native iOS permission dialog; can be revoked in iOS Settings.
- File access/document picker: only when you actively select and upload documents.
- Cloud Memory (optional): opt‑in in App settings; can be turned off at any time.
5. Legal bases (Art. 6 GDPR)
Where GDPR applies, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Providing the App and storing necessary on-device data | Art. 6(1)(b) GDPR (contract/performance) |
| Transmitting text/context to OpenAI for core functionality | Art. 6(1)(b) GDPR |
| Microphone/voice feature | Art. 6(1)(a) GDPR (consent) |
| Document upload / Knowledge Base (optional) | Art. 6(1)(a) GDPR (consent via active action) |
| Cloud Memory (optional) | Art. 6(1)(a) GDPR (opt-in consent) |
| Support requests | Art. 6(1)(f) GDPR (legitimate interest in support communication) |
| Website server logs | Art. 6(1)(f) GDPR (security/operations) |
6. Recipients and international transfers
OpenAI is the recipient of your content because AI processing happens on OpenAI systems. OpenAI may process data outside the EEA (including the United States). The specific transfer mechanisms and safeguards follow from your agreement with OpenAI as the API account holder (e.g., SCCs/DPAs depending on account type). OpenAI provides details in its documentation.
Relevant OpenAI links: Enterprise Privacy, Terms, Usage Policies.
Note: Third countries may not provide a level of data protection equivalent to EU law.
7. Retention and deletion
You can delete local data in the App (chat history, memory, documents). Removing your API key stops OpenAI functionality. Upon uninstall, most local data is removed by iOS; Keychain items may remain until actively removed.
Objects stored at OpenAI (files/vector stores) can be deleted via the App's delete functions or directly in your OpenAI dashboard.
8. Special notes (audio, documents, memory, sensitive data)
- Voice feature: audio is transmitted as a stream to OpenAI during a voice session. The App does not permanently store audio; only transcribed text is stored in chat history.
- Document uploads/Knowledge Base: uploaded documents may be stored in your OpenAI account (Files/Vector Stores) until you delete them.
- Memory: memory facts are stored on-device and may be sent to OpenAI as context. Cloud Memory is disabled by default and only enabled via opt‑in.
- Sensitive data: please avoid submitting special categories of personal data (Art. 9 GDPR) if you are not willing to share them with OpenAI.
9. Your rights
You have the rights under Art. 15–21 GDPR (access, rectification, erasure, restriction, data portability, objection). Since we do not store your content on our own servers, many requests relate to on-device data or to your OpenAI account.
- Local access/deletion: in the App.
- OpenAI account data: via the OpenAI dashboard and/or OpenAI support.
- Complaint: you may lodge a complaint with a supervisory authority.
We do not make automated decisions within the meaning of Art. 22 GDPR. AI outputs are non-binding and have no legal effect.
10. Security
- iOS Keychain for API key storage
- iOS App Sandbox and iOS Data Protection
- Encrypted transport to OpenAI (HTTPS/WSS)
- No server-side storage of user content by us
11. Minors
The App may carry a low age rating in the App Store. However, using the App requires an OpenAI API key; OpenAI account creation is governed by OpenAI's terms. We do not collect age data and cannot verify age. Minors should only use the App under parental supervision.
12. Changes
We may update this Privacy Policy to reflect changes to the App, legal requirements, or the services used. The current version is available in the App and on our website.
13. Apple App Store — privacy labels
The App Store privacy labels are maintained in App Store Connect and are intended to reflect the processing described in this Privacy Policy.
- Data collected by the developer: none.
- Third-party processing inside the App: OpenAI (API infrastructure).
14. Contact
For privacy questions, contact labeat.krasniqi@aitoask.com.