Does Your Keyboard Sync What You Type in a Private Diary?
If you’re deciding whether to use a third-party keyboard while writing a private diary, check two separate things: what the keyboard is allowed to do on your device, and what its maker says it collects or syncs. A permission is a capability, not proof that every keystroke is collected. Likewise, syncing learned words or a personalized dictionary is not the same as syncing every sentence you type.
What does Apple’s “Allow Full Access” permission mean?
On iPhone, find the third-party keyboard in Settings and inspect its **Allow Full Access** switch. Apple’s [custom keyboard documentation](https://developer.apple.com/documentation/uikit/configuring-open-access-for-a-custom-keyboard) explains the distinction: without open access, iOS blocks network access and writing to the containing app’s shared containers; reading those containers remains permitted; with it, the keyboard can send keystrokes and other input events for server-side processing. The keyboard’s developer must request open access, and the user must enable it.
That is a meaningful permission check, but it does not reveal what a particular keyboard actually transmits. Apple describes what the capability makes possible, not a finding that every keyboard with Full Access uploads every keystroke. Read the keyboard’s own privacy information as well. If the diary text feels too sensitive to entrust to that developer, use Apple’s built-in keyboard or another option whose documented behavior fits your boundary.
Does SwiftKey sync every diary entry?
Microsoft’s [SwiftKey privacy FAQ](https://support.microsoft.com/en-us/swiftkey-keyboard/microsoft-swiftkey-keyboard-privacy-questions-and-your-data) says that, absent a SwiftKey Account on Android, personal and language data generated by SwiftKey is stored locally. If an account is used, some data may be shared with Microsoft for specific cloud services, including Backup & Sync. Microsoft also says SwiftKey does not learn from password fields and does not remember long numbers such as credit card numbers. These are the maker’s statements about its product; they do not establish that every field in every app is protected in the same way.
Microsoft’s [Backup and Sync with OneDrive instructions](https://support.microsoft.com/en-us/swiftkey-keyboard/swiftkey-backup-and-sync-with-onedrive) describe personalized typing data, such as learned words, stored in the user’s OneDrive folder. A learned-word backup is not a transcript of every diary entry. If you use SwiftKey, inspect whether you are signed in and whether Backup & Sync or OneDrive backup is enabled; check the controls on your installed version. Microsoft’s page gave May 31, 2026 as the planned completion date for the phased OneDrive rollout; that date has passed, so “still rolling out” is not a current explanation for a missing control.
What does Gboard send or keep?
Google’s [Gboard Help page, “Learn how Gboard gets better”](https://support.google.com/gboard/answer/12373137?hl=en) distinguishes on-device personalization from federated learning. It says personalization saves audio recordings and transcripts of what you say and type on the device, while federated learning sends learnings to Google rather than the text you spoke or typed. Google says federated learning is on by default and can be turned off. This describes the learning features covered by that page; it is not a universal statement about every Gboard feature, setting, device, or other Google service.
On Android, follow the documented path **Settings → System → Language & input → On-screen keyboard → Gboard → Privacy**; device labels may vary. Review **Personalize for you**, **Improve for everyone**, and **Delete learned words and data**. Deleting learned data clears Gboard’s saved on-device data, not necessarily copies elsewhere.
A practical diary check in three steps
Stopping sync does not erase previous copies
Turning off a permission or sync feature changes a future capability or transfer setting; it does not, by itself, establish that previously transmitted or backed-up data has been deleted. Use the maker’s documented data controls for deletion requests and check what data and account they cover.
