Tubby privacy policy
Tubby, the voice keyboard companion by app.tubby
Effective 19 July 2026
Tubby turns your speech into text and types it into the app you are using. This policy explains what data Tubby handles, where it goes, and what control you have. The short version: your voice is processed to make your text and is not stored, your account holds only what it needs, and nothing is sold or used for advertising.
What Tubby processes
- Microphone audio. Recording starts only when you tap the Tubby bubble. In Everyday mode the recording is sent over an encrypted connection to the Tubby cloud service, which passes it to an AI speech provider for transcription. The audio is processed and discarded. Tubby stores no voice recordings, on the server or in your account.
- Transcripts. When you choose Clean, Polished, or Translate, the transcript text is also processed by an AI language model to prepare the final insertable text. Transcripts are returned to your device and are not stored on the server.
- Screen text for Assistant, only when you ask. After you explicitly tap the bubble in Assistant mode, Tubby captures one text-only snapshot of the app window you are in (visible text, labels, the focused field) and sends it with your spoken instruction to create one draft. This is not continuous reading, it is never a screenshot, password fields are refused, and the snapshot is not stored in your account or in server logs.
- Account data. Signing in stores your email address, an optional display name, language and style preferences, your custom words, and your Quick Phrases (saved text blocks you create).
- Usage records. To meter the monthly free minutes, the service stores how many seconds you used, the request route and mode, language codes, and timestamps. Usage records contain no audio and no text.
What Tubby does not do
- No stored voice recordings, ever.
- No ads, no advertising identifiers, no analytics SDKs, and no selling or sharing of personal data for marketing.
- No continuous screen reading. Outside Assistant, the Android Accessibility service is used only to find the focused text field and insert your text, locally on the device.
- No sending of the app name you are typing in. The foreground app package name stays on your device.
- Tubby never presses Send and never operates other apps' controls. Inserting text is the only action it performs.
- Server logs contain request IDs, model names, counts, and timings only. They never contain your audio, transcripts, or screen text, and they age out automatically.
Who processes the data
Tubby runs on a small set of infrastructure providers acting as processors:
- Render hosts the Tubby cloud service.
- Supabase stores accounts and usage data in the EU (Ireland).
- OpenRouter routes transcription and text requests to AI model providers (for example Whisper-class speech models and language models). These providers process audio and text to produce your result and are not permitted to use it for advertising.
Requests to these providers travel over encrypted connections (HTTPS). Provider credentials stay on the backend, never on your device.
Developer mode is different and off by default: there, advanced users configure their own AI provider key on the device, and audio goes directly to that provider under its own terms.
Android Accessibility
Tubby uses the Android Accessibility API for a productivity purpose: finding the text field you are writing in and inserting your dictated text. In Assistant mode it additionally reads the visible text of the current window once per explicit request, as described above. The app shows this disclosure before you enable the service, and Assistant stays locked until you have accepted the current version of it. When direct insertion is unavailable, Tubby may place the final text on the clipboard as a fallback; it never submits anything.
Retention and deletion
- Audio: not retained. Processed and discarded per request.
- Assistant snapshots and drafts: request-scoped, not retained.
- Account, preferences, custom words, Quick Phrases, and usage records: kept until you delete your account.
- Sign-in sessions: expire automatically and are stored only as hashes.
You can delete your account in the app (Account, then Delete account) and it takes effect immediately. Without app access, follow the account deletion page or email info@tubby.pro; emailed requests complete within 30 days. Deletion removes your account, preferences, Quick Phrases, usage records, and sessions. Nothing tied to your identity remains.
Security
All network traffic uses HTTPS. On the device, your session token lives in Android Keystore backed storage. On the backend, database access is restricted to the service role, and abuse protections rate-limit sign-in attempts.
Children
Tubby is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Changes and contact
If this policy changes in a way that matters, the effective date above changes and significant changes are announced in the app's release notes. Questions and requests: info@tubby.pro.