Privacy and data

Privacy Policy

Version v20260820 · Effective August 20, 2026 · Last updated August 20, 2026

1. Scope and Developer

This Privacy Policy applies to the ShynAi mobile application and its related backend services.

ShynAi is developed and operated by Yurii Shynkar, an individual developer, under the ShynDi project name.

ShynAi is a productivity, notes, diary, writing, translation, and AI-assisted organization application.

Privacy and support contact:
support@shynai.app

This Privacy Policy explains what information ShynAi stores locally, what information may leave the user's device, which service providers may process that information, and what choices are available to users.

2. General Privacy Approach

ShynAi is designed primarily as a local-first application.

Notes, notebooks, drawings, attachments, personalization settings, security settings, and most other user-created content are stored locally on the user's device by default.

ShynAi does not currently require users to create a ShynAi account.

ShynAi does not sell personal data and does not currently use advertising SDKs or behavioral advertising.

Online processing occurs only when the user activates a feature that requires an internet connection, such as AI, translation, map search, support communication, or AI response reporting.

3. Information Stored Locally

Depending on how the user uses ShynAi, locally stored information may include:

  • Notes and notebooks.
  • Diary entries and other text.
  • Drawings.
  • Images, files, audio files, videos, and other attachments selected by the user.
  • Stickers, page styles, colors, wallpapers, and editor settings.
  • App language and personalization settings.
  • Trash and deleted-item metadata.
  • App lock and note-protection settings.
  • Nickname, email address, phone number, or other profile information entered by the user.
  • Text produced through voice input.
  • AI responses inserted into notes by the user.

Local information remains on the device until the user deletes it, clears the trash, removes associated files, resets the application, or uninstalls ShynAi.

Deleting ShynAi may permanently remove locally stored information unless the user has separately exported or backed it up.

4. AI Features

When the user activates ShynAi Friend or the AI assistant, text is transmitted from the device to the ShynAi backend over an encrypted HTTPS connection.

This may include:

  • A question or message entered in ShynAi Friend.
  • Text selected in a note and sent to the AI assistant.
  • Instructions selected by the user, such as improve, shorten, expand, summarize, continue, or fix.
  • Up to 16 of the most recent messages in the current ShynAi Friend conversation when needed to provide conversational context.

ShynAi Friend conversation messages are held in the active application session. ShynAi does not currently provide a cloud account or a server-side chat-history database.

The ShynAi backend is hosted using Render and sends AI requests to OpenAI.

AI input and generated output may also be sent to OpenAI's moderation service to identify potentially harmful content. Moderation may be used to block dangerous instructions or replace unsafe output with a safer response.

Requests sent by the ShynAi backend to OpenAI use the store setting set to false. This disables storage of the Chat Completion for OpenAI model distillation or evaluation features.

The store setting does not necessarily prevent all temporary security or abuse-monitoring processing. According to OpenAI's API data controls, abuse-monitoring logs may contain prompts, responses, and classifier information and may normally be retained for up to 30 days, unless longer retention is required by law or needed to protect the service or third parties.

Users should not submit highly sensitive personal, medical, financial, legal, authentication, or confidential information to AI features.

AI responses may be inaccurate. They must not be treated as professional medical, legal, financial, emergency, or other critical advice.

5. Translation

When the user requests translation, the submitted text, source-language setting, and target-language setting are transmitted to the ShynAi backend.

The backend may use DeepL to process the translation. If DeepL is unavailable, OpenAI may be used as a fallback translation provider.

Only text intentionally submitted for translation is sent. ShynAi does not automatically send all notes, notebooks, attachments, images, or protected content for translation.

Translation providers may process request metadata such as the request time and number of characters according to their own policies and contractual terms.

Users should not submit confidential or highly sensitive information for translation unless they understand the privacy implications of online processing.

6. AI Response Reports

Users may voluntarily report a ShynAi Friend or AI assistant response.

A report may include:

  • A generated report identifier.
  • The date and time of the report.
  • The selected report reason.
  • An optional user comment.
  • The reported AI response.
  • The user's original prompt, only when the user chooses to include it.
  • AI mode and provider information.
  • App language and application version.

The report is transmitted to the ShynAi backend and delivered through an email service to feedback@shynai.app.

Reports are used to investigate incorrect, unsafe, offensive, or otherwise problematic AI responses and to improve ShynAi.

Reports are not sold or used for advertising.

7. Support and Feedback Communication

When the user chooses to contact support or send feedback, ShynAi may open an external email application selected by the user.

The user's email provider and email application may process the sender address, recipient address, subject, message content, attachments, IP address, and related delivery metadata according to their own privacy policies.

Technical support, privacy, security, and general support inquiries may be sent to support@shynai.app.

Product feedback, ideas, suggestions, reviews, and AI response reports may be sent to feedback@shynai.app.

ShynAi uses email infrastructure, including Namecheap-hosted email services, to receive or deliver these communications.

8. Map and Location Search

ShynAi may allow the user to manually search for or select a place on a map when adding location information to a note.

ShynAi does not currently request the device's precise GPS location permission for this feature.

When the user performs a manual place search, the entered search term and technical network information may be transmitted to OpenStreetMap services, including Nominatim.

Map tiles may also be loaded from OpenStreetMap infrastructure.

Users should not enter personal, confidential, or sensitive information into map-search fields.

9. Device Permissions

ShynAi may request or use device capabilities only when required for a feature selected by the user.

These capabilities may include:

  • Internet access for AI, translation, map services, reporting, and backend communication.
  • Microphone access for voice input.
  • System file or media pickers when the user chooses an image, file, audio file, video, or other attachment.
  • Biometric authentication for app or note security when enabled by the user.

Voice input may be processed by the speech-recognition service available on the user's device. Depending on the device and operating-system configuration, microphone audio or recognized text may be processed by the operating-system provider or another speech-recognition provider.

ShynAi does not directly store biometric identifiers such as fingerprints or face templates. Biometric verification is handled by the device operating system.

ShynAi does not currently require contacts, calendar, SMS, call-log, or precise device-location permissions.

10. Technical and Network Data

When online features are used, the ShynAi backend and infrastructure providers may process limited technical information such as:

  • IP address.
  • Request date and time.
  • Request route.
  • Request size or character count.
  • Response status.
  • Rate-limit information.
  • Basic server and security logs.

This information may be processed to deliver requests, prevent abuse, enforce rate limits, diagnose failures, and maintain service security.

ShynAi is configured not to intentionally write full AI prompts, AI responses, translation text, or complete note content to its application diagnostic logs.

Infrastructure providers may maintain their own technical and security logs according to their policies.

11. Service Providers

ShynAi currently relies on the following service providers for optional online features:

  • Render: backend hosting and network infrastructure.
  • OpenAI: AI response generation, fallback translation, and content moderation.
  • DeepL: text translation.
  • Namecheap-hosted email services: delivery and receipt of support, feedback, and AI response reports.
  • OpenStreetMap and Nominatim: map tiles and manual place search.
  • Device platform providers: speech recognition, biometric verification, system file pickers, and related operating-system services.

These providers process information only as needed to provide the relevant service and are governed by their own privacy policies and terms.

12. Data Sharing and Sale

ShynAi does not sell personal data.

ShynAi does not share user information with advertising networks or data brokers.

Information may be transmitted to service providers only when necessary to perform a feature requested by the user, secure the service, investigate a report, comply with law, or protect users and the service from harm.

13. Data Retention and Deletion

Local content remains on the user's device until the user deletes it, clears the trash, resets the application, removes associated files, or uninstalls ShynAi.

The ShynAi backend does not currently maintain a user-account database or permanently store complete AI and translation request bodies in a ShynAi content database.

AI and translation providers may temporarily retain or process information according to their own privacy, security, abuse-prevention, and legal obligations.

OpenAI states that default API abuse-monitoring logs may be retained for up to 30 days, unless longer retention is legally required or reasonably necessary for safety and abuse prevention.

Support emails, feedback emails, and AI response reports may be retained while needed to investigate and respond to the communication and for up to 12 months afterward for service improvement, abuse prevention, and record keeping, unless a longer period is required by law.

Users may request earlier deletion of a support message, feedback message, or AI report by contacting support@shynai.app and providing enough information to locate the communication, such as the report identifier and approximate date.

Some information may remain temporarily in provider backups, security logs, email-delivery systems, or legally required records.

14. Security

ShynAi uses reasonable technical measures intended to protect information, including:

  • Encrypted HTTPS communication for backend requests.
  • Server-side storage of provider API keys and email credentials.
  • Rate limits for AI, translation, and AI-report endpoints.
  • Input and output moderation for AI features.
  • Local app-lock, note-protection, and biometric options.
  • Removal of full AI and translation content from normal application diagnostic logs.

No application, transmission method, or storage system can guarantee absolute security.

Users remain responsible for protecting their device, device account, backups, exported files, email account, and any passwords or security patterns they use.

15. User Choices and Rights

Users can choose not to use AI, translation, map search, voice input, reporting, support email, or other online features.

Users may delete local notes, notebooks, attachments, profile information, and other local content using ShynAi or by uninstalling the application.

Users may contact support@shynai.app to:

  • Ask questions about privacy.
  • Request information about a submitted support message or AI report.
  • Request correction or deletion of a support message, feedback message, or AI report when it can be reasonably identified.
  • Raise a privacy or security concern.

Applicable law may provide additional privacy rights depending on the user's location.

16. Children

ShynAi is not directed to children under 13.

Users who are under the age required to consent to online data processing in their country should use optional online features only with the involvement and permission of a parent or legal guardian.

Children and guardians should not submit sensitive personal information through AI, translation, map search, support, or reporting features.

17. International Processing

The service providers used by ShynAi may process information in countries other than the user's country of residence.

Those countries may have different data-protection laws.

By intentionally using an online feature, the user requests the processing necessary to provide that feature, subject to applicable law and the relevant provider's safeguards.

18. Changes to This Policy

This Privacy Policy may be updated when ShynAi features, service providers, legal requirements, or data-handling practices change.

The updated policy will include a new version number and last-updated date.

Material changes may also be communicated in the application or through the public ShynAi website when appropriate.

19. Contact

Privacy, security, technical support, and general support:
support@shynai.app

Product feedback, ideas, suggestions, reviews, and AI response reports:
feedback@shynai.app