What Your Keyboard Can See
Your keyboard is a separate piece of software from the app you are typing into, and it sees every character. The keyboard that shipped with your phone processes that text on the device and adds unusual words to a learned dictionary. A third-party keyboard you installed is a different matter, because it can request network access, and granting it means the text you type may leave your phone through a route that has nothing to do with the app you are using.
For a companion app this produces a specific, common, and genuinely surprising leak: names and phrases from private conversations appearing as autocorrect suggestions in your work email.
The learned dictionary crosses app boundaries
Both platforms improve prediction by learning words you use that are not in the dictionary. Names, nicknames, invented spellings, and repeated phrases all qualify.
That dictionary is device-wide, not per app. A name you type frequently in one app becomes a prediction candidate everywhere — in a message to a colleague, in a search box, in a document. Nothing malicious is happening; the feature is working exactly as designed, and the design does not know that some apps are more private than others.
It also appears in the predictive strip above the keyboard, which is visible to anyone looking at your screen, and it survives deleting the app entirely. The dictionary is keyboard state, not app state.
Resetting it is possible and blunt. Every platform offers a reset-keyboard-dictionary function, which clears everything learned rather than individual entries. It is usually near the keyboard settings, sometimes under a reset menu. Expect predictions to be worse for a while.
This is also why keyboard residue turns up in the discussion of what account deletion leaves on your device — closing an account does not touch it.
Third-party keyboards and full access
Installing a keyboard from an app store means choosing to route all your typing through software from a third party. Both platforms handle this with a permission gate, and the gate is worth taking seriously.
On iOS the setting is called Full Access, and it is what allows a keyboard to communicate over the network. Without it a third-party keyboard is confined to the device. The prompt says something plain about the developer being able to transmit what you type, and it means it.
On Android the warning is presented at activation, with similar substance: an input method can collect what you type, including passwords.
The privacy question is therefore simple. If you use a third-party keyboard with network access, add its operator to the list of parties who may receive your conversations. That may be entirely fine — some are run by reputable companies with clear policies — but it is a second operator, not an extension of the first, and its policy is the one that governs.
Password fields are partially protected. Platforms signal secure fields and well-behaved keyboards disable learning and suggestions in them. That is a convention rather than an enforced guarantee.
The practical recommendation is unglamorous: for anything you consider private, use the keyboard that shipped with the phone. It processes on the device, it is covered by the platform’s own privacy commitments, and it does not add a party.
Dictation is a different pipeline
Tapping the microphone on the keyboard is not the same as typing, and it is not the same as the app requesting microphone access either.
Dictation may be processed on the device or on a server, depending on the platform, the language, the device generation, and your settings. Where it is server-side, audio or a transcript is sent to the platform vendor. Most platforms now offer an on-device dictation option for supported languages and it is often not the default.
This is the keyboard’s microphone use, not the app’s. It will show up in your phone’s privacy log attributed to the keyboard or the system, which can be confusing when you are auditing what an app has accessed — see reading your phone’s privacy dashboard.
Check whether on-device dictation is available and enabled, if you dictate. It is one setting and it changes where the audio goes.
Clipboard is adjacent and separate
Pasting rather than typing bypasses the keyboard and introduces a different actor, because the clipboard is a shared system surface any app can read while in the foreground. That has its own set of behaviours, covered in what clipboard access means for what you paste.
What this does not tell you
The keyboard question is about an additional party, not about the app. The app receives your messages regardless of what you type them with, and no keyboard choice changes that — see what a permission prompt actually grants for the broader shape of what apps can and cannot reach.
It also does not tell you what any specific keyboard vendor does. Full Access is a capability, not evidence of use, and a keyboard with network access may use it only for cloud sync of your own settings. The point is that you cannot tell from the outside, which is why the conservative default is the one that removes the question rather than answers it.
The learned-dictionary leak, though, is not a hypothetical risk profile. It is an ordinary consequence of a feature that is switched on by default on every phone, and it is the part of this subject most likely to actually affect you.