QUILL — PRIVACY POLICY
Last updated: 6-Sep-2026. Applies to: Quill for Android (com.tihor.quill), v1.0.
Privacy/legal contact: quillapp@agentmail.to
THE SHORT VERSION
Quill is a "bring your own key" (BYOK) voice-dictation app developed by Mr. Tikmany, an individual developer based in Mumbai, India ("we", "us", "I"). You supply your own API key for the speech-to-text provider of your choice.
We do not operate any backend server that receives your dictation audio, transcripts, or API keys. Your keys are encrypted on your device; your audio goes directly from your device to the provider you chose, authenticated with your key.
Data that Quill stores itself is stored locally on your device as described below.
Quill has no account system, no analytics, no ads, and no telemetry.
WHO IS RESPONSIBLE FOR QUILL
Quill is developed by Mr. Tikmany, an individual developer based in Mumbai, India.
For users in India, this policy is intended to be consistent with the Digital Personal Data Protection Act, 2023 (DPDPA).
WHAT QUILL HANDLES AND WHERE IT GOES
Your provider API key(s) — one per provider you configure
- Stored: on your device only, encrypted (Android Keystore, AES-256-GCM, non-exportable key; a separate encrypted slot per provider).
- Sent to us: no.
- Sent to third parties: each key is sent only as the authentication credential to that same provider, never to any other provider and never to us.
Dictation audio
- Stored: a temporary file on your device, deleted after transcription. It may be kept briefly if transcription fails so that you can retry.
- Sent to us: no.
- Sent to third parties: sent over HTTPS to the speech provider you selected, using your key.
Transcribed text
- Stored: inserted into the app you are typing in; optionally saved to a local, on-device history.
- Sent to us: no.
- Sent to third parties: if you enable the optional AI clean-up, the text — never the audio — is sent to Groq using your Groq key.
Custom-word vocabulary
- Stored: on your device only.
- Sent to us: no.
- Sent to third parties: if you add a word by voice, that short recording goes to your selected speech provider for transcription, like any other dictation.
Crash reports (optional, off by default)
- Stored: written on your device as a scrubbed text report containing no audio, transcripts, or API keys.
- Sent to us: no automatic upload of any kind.
- Sent to third parties: only if you tap "Send" and choose an app through your own Android share sheet.
Analytics, advertising, identifiers
- Not collected.
- Quill includes no analytics or advertising SDKs.
KEY VALIDATION REQUESTS
When you save a key, or manually re-test it, Quill makes one small test request to that provider using a fraction-of-a-second silent audio clip. This confirms that the key works before you rely on it.
Where a provider distinguishes free and paid keys, Quill may make one additional minimal request to detect your key's tier, solely so the model picker can hide models your key cannot use.
These requests use your key, go only to that provider, and contain no speech.
THE ONE THING QUILL FETCHES FROM US
Quill may periodically fetch a small, static, cryptographically signed bundle of interface text, such as wording and translations, over a read-only HTTPS request.
This occurs at app start and when the app returns to the foreground if the "Check for updated text" setting is enabled. That setting is on by default and can be changed under Settings > Advanced.
The bundle is identical for every user and the request contains no dictation audio, transcripts, API keys, account identifier, analytics identifier, or other Quill-generated personal profile.
As with any ordinary web request, the content host necessarily receives standard connection metadata such as your IP address.
Bundles are cryptographically verified against a signing key built into the app.
Privacy, consent, and disclosure wording cannot be changed through this mechanism. That wording is fixed in the app binary and can change only through an app update.
YOUR PROVIDERS ARE SEPARATE DATA CONTROLLERS
Quill supports five provider configurations.
When your audio, or text used for optional clean-up, reaches a provider, that provider's own privacy policy and terms govern what it does with the data, including retention and any model-training practices. Quill cannot control those practices.
As of this writing:
- Groq — https://groq.com/privacy-policy - OpenAI — https://openai.com/policies/privacy-policy - OpenRouter — https://openrouter.ai/privacy OpenRouter is a router, so your audio may be forwarded to the underlying model provider you select through it. - Google (Gemini API) — https://ai.google.dev/gemini-api/terms and https://policies.google.com/privacy - Custom endpoint — an OpenAI-compatible server you configure. You are responsible for that endpoint. Quill sends your audio and key wherever you point it.
A note on free tiers:
Some providers treat free-tier API traffic differently from paid traffic.
For example, as of this writing, Google's Gemini API terms state that content submitted on the unpaid tier may be used to improve Google's products, while paid-tier content is not used that way.
Review your provider's current terms before dictating sensitive material using a free key.
AI CLEAN-UP (OPTIONAL)
If you enable "Tidy my dictation", the transcribed text is sent to Groq using your Groq key and a chat model, and the tidied version is inserted instead.
If your dictation provider is not Groq, clean-up runs only when you have also saved a Groq key. Otherwise, clean-up is skipped and the raw transcript is used.
The audio itself is never sent to the clean-up model.
HOW YOUR DATA IS PROTECTED
- API keys are encrypted using Android Keystore and AES-256-GCM, with a non-exportable key and a separate encrypted slot per provider. A key saved for one provider is never sent to another.
- All provider and content-host network requests use HTTPS.
- Audio is transient. Recordings are temporary files and are deleted after the transcription attempt, except when temporarily retained following a failure so that you can retry.
- Encrypted secrets, settings, and dictation history are excluded from Android cloud backup and device-to-device transfer.
- Quill refuses to type into fields Android identifies as password inputs, including native password fields and standard web password inputs. A website that incorrectly identifies its password field may not be detectable through Android's accessibility layer.
- Quill only writes into the text field you have focused.
- When direct text insertion fails and a transcript must temporarily be placed on the clipboard, the clipboard item is flagged as sensitive and automatically cleared shortly afterwards, approximately 60 seconds later.
DICTATION HISTORY (LOCAL, TIME-LIMITED, OPTIONAL)
If history is enabled, as it is by default, transcribed text is saved only on your device.
You control the retention period. The default is 1 hour, with options extending up to "forever", together with a configurable row cap and automatic pruning.
Private mode disables history saving entirely.
You can delete individual history entries or clear all history.
PERMISSIONS AND WHY QUILL ASKS FOR THEM
Microphone (RECORD_AUDIO)
Used to capture your dictation. Recording is user-initiated by tapping the bubble and is capped at 300 seconds per session.
Display over other apps (SYSTEM_ALERT_WINDOW)
Used to display the floating bubble and to allow the microphone foreground service to operate while you are using another app.
Accessibility service disclosure
Quill uses the Android Accessibility Service to insert your dictation into the text field you are typing in, in any app. Android provides no standard API for a third-party app to detect the focused text field in another app or insert text into it without replacing your keyboard, so an accessibility service is required for this to work.
Quill uses the Accessibility Service exclusively to: - Detect the currently focused editable text field, via focus and window-change events, so the floating bubble knows where to type. - Check whether that field is a password field, so Quill can refuse to type into it. - Insert the transcribed text into that field using the accessibility input connection, without replacing your keyboard.
Quill does not use the Accessibility Service to read screen content, read the contents of other apps, log keystrokes, collect data, or take any action other than inserting the text you dictated. Nothing obtained through the Accessibility Service is stored, logged, or transmitted — Quill has no backend server. This is true whether or not dictation is active.
Quill does not work around Android's privacy controls, does not change system settings without your permission, and does not use deceptive interface practices.
The service is enabled only after a separate in-app disclosure and your explicit consent, and you can turn it off at any time in Android Settings > Accessibility.
Foreground service (microphone / special use)
Used to keep the bubble available and record while you are in another app.
Notifications (POST_NOTIFICATIONS)
Used for recording status, bubble show/stop controls, and alerts such as "couldn't insert" or "re-enable".
Run after reboot (RECEIVE_BOOT_COMPLETED)
Used to restore the bubble after a restart if you previously had it enabled. Quill does not automatically launch its user interface.
Internet (INTERNET)
Used to send audio or text to the provider you configured and to fetch the signed interface-text bundle described above.
Quill does not hold the restricted "ignore battery optimisations" permission. At most, it opens the Android system battery-settings page so that you can make that choice yourself.
DATA RETENTION AND DELETION
- API keys: retained until you remove them, clear all app data, or uninstall Quill.
- Audio: deleted after successful transcription, or after a failed transcription is retried or abandoned.
- Dictation history: automatically deleted according to your retention setting and can also be deleted individually or in bulk.
- Custom-word vocabulary: retained locally until you delete it or clear Quill's data.
- Everything at once: Settings > Advanced > "Clear all data & keys" removes all stored provider keys, settings, dictation history, and custom-word vocabulary.
- Uninstalling Quill removes its local app data. Because Quill's secrets and other app data are excluded from Android backup, they are not retained through Quill's cloud backup configuration.
Data already sent to a provider is governed by that provider's retention policy. Requests concerning deletion of provider-held data must be made to the provider under your own account.
CHILDREN
Quill is not directed at children under 18, and we do not knowingly process their data.
YOUR RIGHTS (INCLUDING DPDPA 2023)
Because data handled by Quill itself stays on your device, or is sent directly to a provider you selected under your own account, you can exercise many access, correction, and erasure controls directly through the app.
These include the history view, per-item and bulk deletion, and Settings > Advanced > "Clear all data & keys".
For any privacy request or grievance concerning this policy, contact:
quillapp@agentmail.to
DPDPA grievance contact: Mr. Tikmany.
We will respond to privacy grievances within 30 days of receipt.
Data already sent to a provider is subject to that provider's own rights and request processes under your account with them.
SOURCE-CODE TRANSPARENCY
Quill's source code may be made publicly available so that users, researchers, and security reviewers can inspect how the app operates and evaluate its privacy, security, data-handling, and network behaviour.
Public availability of the source code does not itself change how personal data is handled and does not make Quill open-source software.
The rights granted in relation to Quill's source code are governed separately by the Quill Source Code License published with that source code.
CHANGES TO THIS POLICY
We will update this policy as Quill changes and revise the "Last updated" date.
Material changes will be noted in the app's release notes.
The in-app privacy, consent, and disclosure wording is fixed in the app binary and can change only through an app update, never through the remotely fetched interface-text bundle.
CONTACT
All enquiries: quillapp@agentmail.to