What your phone's keyboard can actually see
Every keyboard on a smartphone is technically an input method — an IME on Android, a custom keyboard extension on iOS. It's a separate app that everything passes through: messages in chat apps, search queries, addresses, and sometimes passwords. To the keyboard itself, there's no difference between a casual chat and a bank login form — it registers keystrokes the same way in both cases, unless the system steps in to stop it.
That's exactly why both major mobile platforms treat third-party keyboards with caution. Android shows a direct warning when you enable a new input method: the keyboard may collect all the text you type, including personal data such as passwords and credit card numbers. That's not boilerplate — it's an honest description of how IMEs are architected.
iOS takes a stricter approach: a third-party keyboard runs sandboxed without network access by default. It can only send data anywhere if the developer requested the RequestsOpenAccess capability and the user manually flipped the "Allow Full Access" switch in settings. Without that permission, the keyboard is technically unable to transmit a single keystroke anywhere — it's isolated from the internet at the system level.
There's also a built-in safeguard in specific fields: password fields, secure text entry, and the phone dialer. In those places, iOS silently swaps the third-party keyboard for the system keyboard, with no prompt and no option for the keyboard's developer to override it. Android's guarantee here is weaker: many keyboard vendors disable learning and suggestions in password fields on their own, but that's an application-level decision, not an OS-level lock like iOS — don't treat it as an absolute guarantee.
Four ways typed text can actually leak
Cloud predictions and dictionary sync
Modern keyboards predict your next word, adapt to your writing style, and sync your personal dictionary across devices. For any of that to work, part of what you type — sometimes whole fragments — gets sent to the developer's server to train the prediction model. That function isn't malicious by design; it's how cloud-based personalization works for most major vendors. The real question isn't whether anything is collected at all, but how it's transmitted and who has access to the server on the other end.
Weak transport encryption — the case Citizen Lab documented
In April 2024, the Citizen Lab research group at the University of Toronto published an analysis of keyboard apps from nine major manufacturers — Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi. Eight out of nine had vulnerabilities in how their cloud prediction features transmitted data: several vendors used custom, homegrown encryption instead of proven standards like TLS, and that encryption could be broken or bypassed. A network observer — a public Wi-Fi operator, or anyone intercepting traffic between the device and the keyboard's server — could potentially reconstruct the typed text. Citizen Lab estimated that up to a billion users of these keyboards were affected. The research focused on keyboards popular mainly on the Chinese market and optimized for pinyin input, but the underlying mechanism is universal: any keyboard sending data to the cloud without solid encryption carries the same risk. Most vendors shipped fixes after the disclosure, and the researchers' takeaway was simple — keep your keyboard app updated, and where possible, choose one that works entirely on-device without a cloud component.
A fake or malicious keyboard
A separate risk isn't a bug in an otherwise legitimate app — it's a keyboard built from the start as a surveillance tool. These spread outside official app stores: APK files on random websites, forums, or messaging apps disguised as an "enhanced" or "unlocked" version of a popular keyboard. The warning signs are the same on Android and in sideloading scenarios on iOS: the app asks for permissions a keyboard has no business needing — SMS, contacts, microphone access without a clear reason, and sometimes Accessibility Service access, which grants near-total control over the screen and input. If a keyboard insists on permissions like that, the right move is to remove it, not to investigate why.
Voice input and the clipboard
Voice typing is processed by the same keyboard app or a connected speech-recognition service, so it raises the same cloud-and-encryption questions as regular text. The clipboard is a related but separate concern — it can be read by any app with the right permission, not just the keyboard, and it's a large enough topic to cover on its own; a full breakdown is in our piece on how apps read your clipboard.
Which keyboards are safer, and what to check for
This section won't rank "the safest keyboard of 2026" — lists like that go stale faster than they're useful, and they push you to trust a brand name instead of checking actual settings. Instead, here are the traits worth checking on any keyboard, installed or about to be:
- The developer is known, with a real update history and a public privacy policy, not just a bare store listing.
- There's an on-device mode available — even as an option you have to turn on explicitly.
- Cloud features (predictions, dictionary sync) can be switched off with a single toggle, not just by uninstalling the app entirely.
- Requested permissions match the app's actual function: a keyboard doesn't need contacts or SMS access unless that's a separately disclosed feature, like quick number insertion.
- The app is updated on a regular cadence — a keyboard with no updates in over a year is a red flag regardless of brand.
- It was installed from an official store (Google Play, App Store), not sideloaded as an APK from a third-party site.
These criteria apply to any keyboard — a phone manufacturer's preinstalled one, Gboard, SwiftKey, Samsung Keyboard, Grammarly Keyboard, or anything else. The point isn't finding "the one perfect keyboard" — it's being able to answer every item on this list for whichever keyboard is actually on your phone.
How to check and secure your keyboard on Android
Menu wording varies slightly between Samsung, Xiaomi, and stock Android, but the logic is the same everywhere.
- Open Settings → System → Languages & input → On-screen keyboard (on some skins it's simply "Keyboard" under general settings) and review which input methods are enabled. If there's a keyboard you didn't deliberately install, or can't remember installing, disable or remove it.
- For the keyboard you actually use, open its own settings. In Gboard that's the Privacy section: personalization, dictionary cloud sync, and clipboard access are toggled separately there. Turn off anything you don't consciously rely on.
- Check the keyboard app's system permissions (Settings → Apps → [keyboard] → Permissions): microphone, contacts, network access. Microphone only needs to stay on if you actually use voice typing through that specific keyboard.
- Check Settings → Accessibility for any keyboard-related entry or unfamiliar service you didn't enable yourself. Accessibility access is one of the most powerful levels of device control, and a keyboard doesn't need it for plain text input.
- Remove any keyboards installed outside Google Play — leftovers from a custom ROM or a long-forgotten experiment are a common source of these.
How to set up your keyboard on iPhone
The steps on iOS are shorter, because the system restricts keyboards more aggressively by default:
- Open Settings → General → Keyboard → Keyboards and review the full list of installed input methods.
- Remove keyboards you no longer use by swiping left → Delete. Fewer active keyboards means fewer settings that can silently drift.
- For every remaining third-party keyboard, check the "Allow Full Access" toggle. If the keyboard doesn't need internet access — say, it doesn't sync a dictionary or use cloud predictions — keep that toggle off, and the app runs fully sandboxed with no network at all.
- Remember the system-level swap: in password fields, iOS automatically switches you to the built-in keyboard regardless of your default choice — this happens without any user action and can't be configured separately.
Worth being upfront here: LiMP VPN doesn't have an iPhone or iPad app — the service is available for Android, Windows, and Chrome. So this iOS section won't recommend installing LiMP — just the platform's own settings.
Does a VPN protect what you type
A VPN encrypts the connection between your device and the VPN server, and that closes exactly one category of the threats above — network-level interception. Everything else happens either on the device itself or on the keyboard vendor's own server, and a VPN has no bearing on either. It's clearest laid out as a table:
| Threat | Does a VPN protect against it |
|---|---|
| Interception of cloud predictions on public Wi-Fi | Yes — traffic to the VPN server is encrypted, so an observer on the same network can't see the content |
| The keyboard developer collecting typed text on its own server | No — a VPN doesn't stop an app from sending data where it's already designed to send it |
| A malicious keylogger keyboard running on the device itself | No — keystrokes are captured before anything reaches the network |
| The keyboard's server seeing the sender's IP and approximate location | Partially — the server sees the VPN server's IP, not your real one |
| A phishing form you willingly type your password into | No — a VPN doesn't evaluate who you choose to trust with what you type |
The practical takeaway is straightforward: keep a VPN on in any network you don't control — a café, an airport, a hotel — since that's exactly where traffic interception is most likely. On Android, the easiest way to do that reliably is Always-On VPN in the LiMP VPN Android app, so the connection doesn't drop when you switch networks and there's no unprotected gap between reconnects. For a broader breakdown of what a VPN does and doesn't cover, see what a VPN protects against, and for practical habits in cafés and airports, see our guide to public Wi-Fi security.
Passwords and payment details: better not typed at all
The most reliable defense against a password leaking through a keyboard is not typing it by hand in the first place. Password managers and passkeys fill in credentials through the system's autofill mechanism, bypassing the keyboard entirely — the password text never passes through the IME, so there's nothing for the keyboard to intercept. The same logic applies to card numbers and two-factor codes: the less sensitive data you type manually, the less your security depends on which keyboard happens to be installed. For a deeper look at choosing and configuring one, see our guide on password manager security.
A related habit worth building: don't store passwords or access codes in phone notes, and don't let a keyboard "learn" them through its prediction training. Most keyboards offer an incognito mode that temporarily disables personalization — it's worth switching on manually in moments when you have to type something sensitive without autofill, like reading an SMS code out loud to someone while also typing it in yourself.
Checklist: locking down your keyboard in 10 minutes
- Remove every input method in settings that you don't actively use.
- Confirm your keyboard was installed from an official app store, not sideloaded as an APK.
- Turn off cloud personalization and dictionary sync in keyboard settings unless you deliberately rely on them.
- On iPhone, disable "Allow Full Access" for any keyboard that doesn't need network access.
- Review the keyboard's permissions and the Accessibility settings menu for anything that doesn't belong.
- Switch password and card entry over to autofill from a password manager.
- Keep your keyboard app and OS updated — fixes like the ones Citizen Lab prompted ship through updates.
- Keep a VPN on in networks you don't control, ideally in Always-On mode.




