ok so 那个 这个 bugdeploy 上去 然后我明天 morningcheck 一下

这个 bugdeploy 上去,然后我明天 morningcheck 一下。

01

02

03

1

这个 bug 先 deploy 上去

2

3

RM14.90

RM39.90

RM399.90

RM699.90

Privacy policy

Privacy Policy — NoTimeType

Effective 8 August 2026 · Last updated 8 August 2026 · Published by Vic Tech, Sibu, Sarawak, Malaysia

Stays on your device
  • The recording on iPhone, iPad and Mac — turned into text on the device, then deleted
  • Settings, personal dictionary, writing-style samples
  • Your last 50 dictations and any meetings you record
  • Keyboard themes and any background photo you choose
  • The technical log on the device — timings and counts, not your words
Leaves your device
  • On Android only: the dictation audio — over HTTPS, through our relay, to Groq to be transcribed, then discarded
  • The transcript text — over HTTPS, through our relay, on to Groq
  • Text already in the field, but only when you tap the ✨ key
  • A short background prompt — only if you use AI-generated backgrounds, through our relay to Google
  • One usage row per request — when, which model, how many tokens or seconds of audio, how long, and a hashed device tag; never the text or audio itself, and deleted after 90 days
  • Apple’s speech-model download, the first time you use a language on an Apple device

That is the whole list. There is no account, no analytics, no advertising and no third-party SDK in either app. We do run one small relay server, and everything it keeps is in the right-hand column.

The short version. On iPhone, iPad and Mac, your voice never leaves the device — it is turned into text on the device itself. On Android there is no on-device engine we can use yet, so the recording is sent, over an encrypted connection, through a relay we run to be transcribed, and is then discarded. On every platform the resulting text passes through that same relay to one AI provider that tidies it. The relay keeps a short usage record of each request — when it happened, which model, how many words or seconds of audio — and never the words themselves and never the audio. Those records are deleted after 90 days.

Your voice

iPhone, iPad and Mac. When you dictate, the recording is handled entirely on your device and turned into text by Apple’s built-in speech recognition, running locally. The temporary audio file is deleted as soon as it has been transcribed. The audio is never uploaded anywhere and never stored.

Android. Android does not yet have an on-device engine we can rely on, so on Android transcription happens in the cloud. When you dictate, the recording is sent over an encrypted HTTPS connection through the same relay we run to Groq, which turns it into text and sends the text back. We do not keep the audio: the relay holds it in memory only long enough to pass it on, stores neither the recording nor the transcript, and keeps only the usage record described below (which notes how many seconds of audio there were, never the audio itself). Once the audio reaches Groq it is handled under Groq’s own privacy policy. This is the one place NoTimeType works differently on Android than on Apple devices, and we would rather say it plainly than bury it.

Your text, and the relay it passes through

Once your speech has become text — on the device on Apple platforms, or through Groq on Android — that text is sent over an encrypted HTTPS connection to a relay we operate on Cloudflare Workers, at notimetype-relay.victechmy.workers.dev. In our testing it answers from Cloudflare’s Singapore edge. The relay passes your text on to one AI provider — Groq, running the model qwen/qwen3.6-27b — which punctuates it, removes the filler words, and depending on what you asked for may also restructure, summarise, translate or adjust the tone of it. The result comes back to you the same way.

So the full path for your text is: your device → our relay on Cloudflare → Groq. That is the only text provider there is. An earlier version of this app let you choose from five and asked you for your own key, and until recently the relay could also reach Z.ai. DeepSeek, OpenAI, Anthropic and Z.ai are now all unused — their routes are gone from the relay and their credentials deleted from it rather than left sitting there. The narrowing was deliberate: one provider is one place your text can travel to.

One consequence of the relay is in your favour. The request reaches the AI from Cloudflare rather than from your handset, so Groq sees Cloudflare’s address, not your device’s IP.

All of the AI text features take this same path. Whether you are cleaning up a dictation, using AI mode — which rewrites what you said into a clear instruction for an AI assistant — asking for a summary, translating into another language, or turning on the tone-and-emoji option, the text is sent to the relay and on to Groq exactly as described here. Some of these features also send, alongside your text, the personal dictionary and writing-style samples you have set, so the model can respect them; those are treated as text and, like your text, are never stored by the relay.

There is one more case, and we want to be explicit about it: if you tap the polish key (✨) on the NoTimeType keyboard, the text already in the field — your selection, or a portion of the text near your cursor (up to about 2,000 characters on iPhone and iPad) — takes the same path, to be tidied. That happens only when you tap that key.

Once your text reaches Groq it is governed by Groq’s own privacy policy, not ours.

AI-generated keyboard backgrounds

NoTimeType offers an optional feature that generates a keyboard background picture from a short description you type. If — and only if — you use it, the short text prompt you write, together with the style you choose, is sent through our relay. The relay first checks it — automatically, using the same text provider (Groq) — so that it is not asking for a specific copyrighted character or for content unsuitable for a keyboard, and then passes it to Google’s image-generation model, which creates the picture and sends it back. As with everything else, the relay does not store your prompt or the picture; its usage record notes only that a background was generated, and at what size. Once your prompt reaches Google it is handled under Google’s own privacy policy. If you never use this feature, nothing is ever sent to Google.

The API key is ours, not yours

You are not asked for an API key and there is no key inside either app. The provider keys belong to us and stay on the relay. The app carries only the relay’s address and a token that identifies the app to it — if that token ever leaked it would buy someone our rate limit, not our provider account, and we can revoke it in seconds.

What the relay records — and what it does not

For each request the relay writes one row to a usage ledger. That row holds: the timestamp and date, which of our tokens was used, a hashed device tag, the model name, which provider handled it, whether the reply was streamed, the HTTP status code, the number of prompt, completion and total tokens, how many seconds of audio there were (for an Android transcription), the size of any generated background picture, how many milliseconds it took, and an error code if it failed.

It does not store the text you sent, the text that came back, the audio, or any image prompt. Nothing from your request is ever written to a log either. The relay writes exactly one log line, and only once a day: the receipt left by the clean-up job, which reads prune: retention=90d cutoff=2026-05-03 deleted=3 — a number of days, a date, and a count of rows. That is the entire logging surface. We checked this rather than assuming it: marked text was pushed down all three of the relay’s failure paths — a request it could not parse, a model that is not on its list, and an error raised by the provider — and then the entire database and the live log stream were searched for it. Nothing came back.

When a provider returns an error, we hand that error message straight back to the app so you can see what went wrong. We deliberately do not store it, because a provider’s error text can quote your own sentence back at you.

The device identifier never reaches our database in a form anyone could read. On iPhone and iPad your device sends identifierForVendor — a value iOS scopes to us alone, which is not the advertising identifier and resets when you delete the app. On Android the app sends a random identifier it generates on first launch and keeps only in its own private storage; it is likewise not an advertising identifier and is gone when you uninstall. Worth being exact about one thing: deleting the app breaks the link from that point on, it does not reach back and erase rows already written — those age out on the 90-day clock like any others. The relay hashes whatever it receives the moment it arrives, with SHA-256 and a secret salt, keeps the first 16 hexadecimal characters of the result, and throws the original away. The salt lives in the worker’s secrets, not in its code. We cannot turn a stored tag back into a device, and neither could anyone who walked off with the database.

The tag exists for one reason: the relay limits how many requests a device may make per minute, and without a per-device value that limit would fall on the shared app token, so one person dictating hard would throttle everyone else. Hashing keeps that working exactly as before — the same device produces the same tag every time — while making the tag useless for anything else.

Cloudflare’s own platform request logging — the layer that would carry your IP address, your city and rough coordinates — is switched off for this service, and we have verified that on the live worker.

The usage ledger is kept for 90 days. A scheduled job on Cloudflare runs once a day, at 03:00 UTC, and deletes every row older than that — a row on its 90th day is still there, a row past it is gone. We tested it against rows planted on both sides of that boundary and against real traffic before writing the number down. Every run leaves its own receipt: when it ran, the cut-off date, and how many rows went. If it misses two days running, we are warned.

Where the ledger lives. The database runs in Cloudflare’s Asia-Pacific region, with read replication switched off and no jurisdiction restriction set. That is as precise as we are able to be: Cloudflare reports the region and nothing finer — no country, no data centre — so we are not going to name one. (The Singapore mentioned above is the Cloudflare edge your request passes through on its way out; that is a different thing from where the ledger is stored.) One piece genuinely sits outside that region: the counter that enforces the per-minute rate limit lives in Cloudflare’s key-value store, which is distributed worldwide and cannot be pinned to a region. It holds a hashed tag and a number, nothing else, and every entry expires within 48 hours.

Asking us to delete it. Here is the awkward consequence of all of the above, and we would rather write it down than let you find it out. Because what we keep is a hash with no account attached to it, you cannot point at a row and show that it is yours — and neither can we. A deletion request is therefore something we have no way to carry out. The trade is deliberate, and it cuts both ways: the very property that makes this ledger useless to us, and to anyone who steals it, is what makes it impossible for us to search on your behalf. Every row leaves on the 90-day clock regardless, and not one of them contains anything you said or any audio. Do write to support@victech.my anyway if you have questions — we can explain how any of this works, we just cannot pick your rows out of the ledger.

Who else touches it

A few companies are involved besides us, and each is worth naming for what it actually is. Cloudflare hosts the relay, the ledger and the rate-limit counter; they are our infrastructure provider and handle this data on our behalf. Groq receives your text — and, on Android, your dictation audio — in order to process it and hand back the result; they are a service provider for that job, under their own privacy policy. Google receives a background prompt, and only that, if you use the AI-background feature, under its own privacy policy. On Apple platforms, transcription involves no outside company at all: it is done by Apple software already on your device.

That is the whole list. We do not sell any of this, to anyone, ever. We do not share it, trade it, or pass it to advertisers, data brokers or analytics companies. Nothing leaves our relay except to the provider answering your request, and nothing about you is a product we have anything to gain from selling. There is no third-party SDK in either app either — but that is a separate and much smaller promise about the app, not the one this paragraph is making about our server.

What we do not collect

There is no account and no sign-in. There is no analytics, no tracking, no advertising, and no third-party SDK of any kind in either the iOS or the Android app.

What stays on your device

Your settings, personal dictionary and writing-style samples; your last 50 dictations, if you use the history feature; any meetings you record (their transcript and summary are kept — the audio is deleted after transcription); any keyboard theme or background photo you choose; and a technical log of what the app did — timings, character counts and error messages, not your words. All of it stays on your device. Deleting the app removes it, and history can also be cleared from within the app.

The keyboard

On iPhone and iPad, the NoTimeType keyboard asks for Full Access, and iOS needs it for two things. The keyboard and the app talk to each other through a shared App Group container — that is how the start and stop commands and the finished text travel between them — and an extension without Full Access cannot reach a shared container at all. Second, the polish (✨) key makes an HTTPS request, which an extension without Full Access cannot make either. Without Full Access the keyboard still types: QWERTY, numbers, symbols and the pinyin input method all work; only dictation and the ✨ key do not.

Full Access does not hand us your keystrokes. The keyboard reads and writes only the text field you are typing into, through Apple’s public UITextDocumentProxy. It does not log what you type, it cannot see the contents or the identity of the app you are using, and it contains no audio or speech code at all — it declares no microphone use.

On Android, the keyboard asks for only three permissions: the microphone (for dictation), internet access (to reach the relay), and vibration (for typing feedback). It asks for nothing else — not your contacts, not notifications. Only the Android system itself is allowed to connect to the keyboard, and the keyboard reads and writes only the text field you are typing in. It does not log what you type.

Subscriptions and payment

During the launch period the whole app is free, including the AI features. If and when a paid tier begins, subscriptions are handled entirely by the Apple App Store or Google Play through their own in-app purchase systems. We never see or handle your card or payment details — Apple and Google do, under their own policies. There is no separate payment processor, and there is no payment code in the app today.

Network

On Apple devices, besides the relay the only other network activity is Apple’s own download of the speech-recognition model the first time you use a language; that is between your device and Apple. On Android there is no such download, because transcription goes through the relay.

Children

NoTimeType is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes, we will update this page and the dates above.

8 August 2026. NoTimeType came to Android, and this policy was rewritten to cover both platforms. The most important addition: on Android, transcription happens in the cloud — the recording is sent through our relay to Groq and then discarded — so on Android the audio does leave the device, whereas on iPhone, iPad and Mac it never does. The sections on your voice, on the sub-processors and on the device identifier were updated to say so, and sections on the AI text features, on the optional AI-generated backgrounds (which use Google), and on subscriptions were added.

1 August 2026. The app stopped talking to AI providers directly. Every request now passes through a relay we run, we supply the API key instead of you, and the choice of provider narrowed from five to two. The sections on your text, on the API key and on what the relay records were rewritten for this. Later the same day, Z.ai was dropped, leaving Groq as the only text provider; its routes were removed from the relay and its credentials deleted rather than left unused.

Contact

Vic Tech, Sibu, Sarawak, Malaysia — support@victech.my, or Telegram @vicvictor2011.