LiMP VPN

Are Third-Party Keyboard Apps Safe? Privacy Risks in 2026

Are Third-Party Keyboard Apps Safe? Privacy Risks in 2026

What your phone's keyboard can actually see

Every keyboard on a smartphone is technically an input method — an IME on Android, a custom keyboard extension on iOS. It's a separate app that everything passes through: messages in chat apps, search queries, addresses, and sometimes passwords. To the keyboard itself, there's no difference between a casual chat and a bank login form — it registers keystrokes the same way in both cases, unless the system steps in to stop it.

That's exactly why both major mobile platforms treat third-party keyboards with caution. Android shows a direct warning when you enable a new input method: the keyboard may collect all the text you type, including personal data such as passwords and credit card numbers. That's not boilerplate — it's an honest description of how IMEs are architected.

iOS takes a stricter approach: a third-party keyboard runs sandboxed without network access by default. It can only send data anywhere if the developer requested the RequestsOpenAccess capability and the user manually flipped the "Allow Full Access" switch in settings. Without that permission, the keyboard is technically unable to transmit a single keystroke anywhere — it's isolated from the internet at the system level.

There's also a built-in safeguard in specific fields: password fields, secure text entry, and the phone dialer. In those places, iOS silently swaps the third-party keyboard for the system keyboard, with no prompt and no option for the keyboard's developer to override it. Android's guarantee here is weaker: many keyboard vendors disable learning and suggestions in password fields on their own, but that's an application-level decision, not an OS-level lock like iOS — don't treat it as an absolute guarantee.

Four ways typed text can actually leak

Cloud predictions and dictionary sync

Modern keyboards predict your next word, adapt to your writing style, and sync your personal dictionary across devices. For any of that to work, part of what you type — sometimes whole fragments — gets sent to the developer's server to train the prediction model. That function isn't malicious by design; it's how cloud-based personalization works for most major vendors. The real question isn't whether anything is collected at all, but how it's transmitted and who has access to the server on the other end.

Weak transport encryption — the case Citizen Lab documented

In April 2024, the Citizen Lab research group at the University of Toronto published an analysis of keyboard apps from nine major manufacturers — Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi. Eight out of nine had vulnerabilities in how their cloud prediction features transmitted data: several vendors used custom, homegrown encryption instead of proven standards like TLS, and that encryption could be broken or bypassed. A network observer — a public Wi-Fi operator, or anyone intercepting traffic between the device and the keyboard's server — could potentially reconstruct the typed text. Citizen Lab estimated that up to a billion users of these keyboards were affected. The research focused on keyboards popular mainly on the Chinese market and optimized for pinyin input, but the underlying mechanism is universal: any keyboard sending data to the cloud without solid encryption carries the same risk. Most vendors shipped fixes after the disclosure, and the researchers' takeaway was simple — keep your keyboard app updated, and where possible, choose one that works entirely on-device without a cloud component.

A fake or malicious keyboard

A separate risk isn't a bug in an otherwise legitimate app — it's a keyboard built from the start as a surveillance tool. These spread outside official app stores: APK files on random websites, forums, or messaging apps disguised as an "enhanced" or "unlocked" version of a popular keyboard. The warning signs are the same on Android and in sideloading scenarios on iOS: the app asks for permissions a keyboard has no business needing — SMS, contacts, microphone access without a clear reason, and sometimes Accessibility Service access, which grants near-total control over the screen and input. If a keyboard insists on permissions like that, the right move is to remove it, not to investigate why.

Voice input and the clipboard

Voice typing is processed by the same keyboard app or a connected speech-recognition service, so it raises the same cloud-and-encryption questions as regular text. The clipboard is a related but separate concern — it can be read by any app with the right permission, not just the keyboard, and it's a large enough topic to cover on its own; a full breakdown is in our piece on how apps read your clipboard.

Which keyboards are safer, and what to check for

This section won't rank "the safest keyboard of 2026" — lists like that go stale faster than they're useful, and they push you to trust a brand name instead of checking actual settings. Instead, here are the traits worth checking on any keyboard, installed or about to be:

  • The developer is known, with a real update history and a public privacy policy, not just a bare store listing.
  • There's an on-device mode available — even as an option you have to turn on explicitly.
  • Cloud features (predictions, dictionary sync) can be switched off with a single toggle, not just by uninstalling the app entirely.
  • Requested permissions match the app's actual function: a keyboard doesn't need contacts or SMS access unless that's a separately disclosed feature, like quick number insertion.
  • The app is updated on a regular cadence — a keyboard with no updates in over a year is a red flag regardless of brand.
  • It was installed from an official store (Google Play, App Store), not sideloaded as an APK from a third-party site.

These criteria apply to any keyboard — a phone manufacturer's preinstalled one, Gboard, SwiftKey, Samsung Keyboard, Grammarly Keyboard, or anything else. The point isn't finding "the one perfect keyboard" — it's being able to answer every item on this list for whichever keyboard is actually on your phone.

How to check and secure your keyboard on Android

Menu wording varies slightly between Samsung, Xiaomi, and stock Android, but the logic is the same everywhere.

  1. Open Settings → System → Languages & input → On-screen keyboard (on some skins it's simply "Keyboard" under general settings) and review which input methods are enabled. If there's a keyboard you didn't deliberately install, or can't remember installing, disable or remove it.
  2. For the keyboard you actually use, open its own settings. In Gboard that's the Privacy section: personalization, dictionary cloud sync, and clipboard access are toggled separately there. Turn off anything you don't consciously rely on.
  3. Check the keyboard app's system permissions (Settings → Apps → [keyboard] → Permissions): microphone, contacts, network access. Microphone only needs to stay on if you actually use voice typing through that specific keyboard.
  4. Check Settings → Accessibility for any keyboard-related entry or unfamiliar service you didn't enable yourself. Accessibility access is one of the most powerful levels of device control, and a keyboard doesn't need it for plain text input.
  5. Remove any keyboards installed outside Google Play — leftovers from a custom ROM or a long-forgotten experiment are a common source of these.

How to set up your keyboard on iPhone

The steps on iOS are shorter, because the system restricts keyboards more aggressively by default:

  1. Open Settings → General → Keyboard → Keyboards and review the full list of installed input methods.
  2. Remove keyboards you no longer use by swiping left → Delete. Fewer active keyboards means fewer settings that can silently drift.
  3. For every remaining third-party keyboard, check the "Allow Full Access" toggle. If the keyboard doesn't need internet access — say, it doesn't sync a dictionary or use cloud predictions — keep that toggle off, and the app runs fully sandboxed with no network at all.
  4. Remember the system-level swap: in password fields, iOS automatically switches you to the built-in keyboard regardless of your default choice — this happens without any user action and can't be configured separately.

Worth being upfront here: LiMP VPN doesn't have an iPhone or iPad app — the service is available for Android, Windows, and Chrome. So this iOS section won't recommend installing LiMP — just the platform's own settings.

Does a VPN protect what you type

A VPN encrypts the connection between your device and the VPN server, and that closes exactly one category of the threats above — network-level interception. Everything else happens either on the device itself or on the keyboard vendor's own server, and a VPN has no bearing on either. It's clearest laid out as a table:

ThreatDoes a VPN protect against it
Interception of cloud predictions on public Wi-FiYes — traffic to the VPN server is encrypted, so an observer on the same network can't see the content
The keyboard developer collecting typed text on its own serverNo — a VPN doesn't stop an app from sending data where it's already designed to send it
A malicious keylogger keyboard running on the device itselfNo — keystrokes are captured before anything reaches the network
The keyboard's server seeing the sender's IP and approximate locationPartially — the server sees the VPN server's IP, not your real one
A phishing form you willingly type your password intoNo — a VPN doesn't evaluate who you choose to trust with what you type

The practical takeaway is straightforward: keep a VPN on in any network you don't control — a café, an airport, a hotel — since that's exactly where traffic interception is most likely. On Android, the easiest way to do that reliably is Always-On VPN in the LiMP VPN Android app, so the connection doesn't drop when you switch networks and there's no unprotected gap between reconnects. For a broader breakdown of what a VPN does and doesn't cover, see what a VPN protects against, and for practical habits in cafés and airports, see our guide to public Wi-Fi security.

Passwords and payment details: better not typed at all

The most reliable defense against a password leaking through a keyboard is not typing it by hand in the first place. Password managers and passkeys fill in credentials through the system's autofill mechanism, bypassing the keyboard entirely — the password text never passes through the IME, so there's nothing for the keyboard to intercept. The same logic applies to card numbers and two-factor codes: the less sensitive data you type manually, the less your security depends on which keyboard happens to be installed. For a deeper look at choosing and configuring one, see our guide on password manager security.

A related habit worth building: don't store passwords or access codes in phone notes, and don't let a keyboard "learn" them through its prediction training. Most keyboards offer an incognito mode that temporarily disables personalization — it's worth switching on manually in moments when you have to type something sensitive without autofill, like reading an SMS code out loud to someone while also typing it in yourself.

Checklist: locking down your keyboard in 10 minutes

  • Remove every input method in settings that you don't actively use.
  • Confirm your keyboard was installed from an official app store, not sideloaded as an APK.
  • Turn off cloud personalization and dictionary sync in keyboard settings unless you deliberately rely on them.
  • On iPhone, disable "Allow Full Access" for any keyboard that doesn't need network access.
  • Review the keyboard's permissions and the Accessibility settings menu for anything that doesn't belong.
  • Switch password and card entry over to autofill from a password manager.
  • Keep your keyboard app and OS updated — fixes like the ones Citizen Lab prompted ship through updates.
  • Keep a VPN on in networks you don't control, ideally in Always-On mode.

Frequently asked questions

Can a keyboard steal my banking app password?

It depends on how that bank app implemented its input field and which keyboard is installed. Banks often use secure fields that force the system keyboard, but autofill from a password manager is the more reliable option.

Is Gboard or SwiftKey safe to use?

There's no fixed verdict by brand name since behavior shifts with updates. Check the developer, cloud features, requested permissions, and update cadence for the version actually installed on your phone.

What does incognito mode do on a keyboard?

A temporary toggle that stops the keyboard from saving typed text to its dictionary or using it for prediction training, without changing how it processes text in the moment.

Should I remove my phone manufacturer's preinstalled keyboard?

You usually can't fully uninstall a manufacturer's system keyboard, only switch the default. It's more realistic to disable its cloud features and keep it updated.

How do I tell if an installed keyboard is a keylogger?

Warning signs: unknown developer, installation outside an official store, requests for Accessibility Service or SMS access without reason, and unexplained background data use.

Can a keyboard see what I paste from the clipboard?

Not every keyboard reads the clipboard on paste, but many have a dedicated clipboard history feature, and when enabled, the keyboard does have access to that content.

Does antivirus software protect against a malicious keyboard?

Antivirus can flag a known threat by signature, but it's no guarantee against new or obscure clones — avoiding sideloaded keyboards is the more reliable first layer.

Read also

Security & Privacy

How to Stop Google Tracking: Activity & Location Settings

9 min read
Security & Privacy

Who Is Connected to My Wi-Fi? How to Check and Kick Them Off

12 min read
Security & Privacy

Encrypted Client Hello (ECH): What It Is and How to Enable It

11 min read

Secure your connection in a minute

Download LiMP VPN for free and feel the difference within a minute.

Download for AndroidPricing