← All trends
PrivacyUpdated as of July 28, 2026

Rizz Keyboards (2026): What the App Store Listings Actually Say

By the appsappsapps.app team

A rizz keyboard promises to write your dating-app replies for you. You install it, switch to it inside Tinder or iMessage, tap a button, and it drafts the line. The category is not fringe: the biggest name in it, RIZZ, has 38,851 US App Store ratings and more than five million Google Play downloads — though RIZZ is a screenshot app rather than a keyboard, a distinction we come back to. Among the apps that really do ship a keyboard, Smoothspeak has 14,431 ratings and RizzKey 2,732.

We read the App Store listings, the declared privacy labels, and the privacy policies linked from those listings for every rizz app we could find. This piece is about what those documents say. The finding, in one sentence: of the eight apps we confirmed ship a real iOS keyboard extension, not one discloses anywhere in its App Store listing that it will ask for Full Access — the permission that takes a keyboard out of its sandbox and puts it on the network.

What you are actually installing

Apple designed custom keyboards to be harmless by default. In Apple Platform Security, third-party keyboards “run by default in a very restrictive sandbox that blocks access to the network, to services that perform network operations on behalf of a process, and to APIs that would allow the extension to exfiltrate typing data.” Left alone, a keyboard cannot phone home. It cannot even ask something else to phone home for it.

One switch changes that. In the app’s configuration, RequestsOpenAccess is documented as “a Boolean value indicating whether a custom keyboard uses a shared container and accesses the network.” Flip it on and iOS shows the user the Full Access prompt. Apple’s own list of what a keyboard gains at that point includes, verbatim: “Keyboard can send keystrokes and other input events for server-side processing.” It also gets a shared container with its parent app, and — with separate user permission — Location Services and the Address Book.

Apple is unusually direct with keyboard developers about what this means. “Your custom keyboard gives you access to what a user types, so trust between you and your user is essential,” the documentation says, adding that users “want their keystrokes to go to the document or text field they’re typing into, and not to be archived on a server or used for purposes that are not obvious to them.”

Now the part that gets exaggerated everywhere else, stated correctly: this is not about your banking password. A custom keyboard “is not eligible to type into” any field marked as secure text entry — the system temporarily swaps your keyboard for Apple’s own. Phone-pad fields are excluded the same way, and Apple Platform Security adds passcode input and secure text views. The exposure is not your credentials. It is the content of your conversations, which for a dating keyboard is the entire point of the product.

One fair caveat on that protection: the secure-field flag is set by each app’s own developer. The operating system enforces the rule; it does not detect sensitivity on its own. A field some developer forgot to mark is not protected by it.

Android has no equivalent switch at all. INTERNET is a normal permission — “the system automatically grants your app the permissions when the user installs your app” — and users cannot revoke it. And Android’s password-field protection is advice to the keyboard developer rather than an enforced boundary; the platform cautions developers to “handle text correctly when you send it to a password field” and not to store passwords on the device. The input method still receives the text. iOS structurally removes the keyboard from secure fields; Android asks nicely.

The finding

Eight apps sit at the centre of this finding, all confirmed to ship a real iOS keyboard extension: RizzMode, WRizz, RizzKey, RizzPRO, RizzPlus, Smoothspeak, Rizzio and CharmKey. Not one discloses the Full Access requirement anywhere in its App Store listing — not in the description, not in the promotional text, not in the screenshots.

The only genuine occurrence of the concept we found across all of those listings is in a user review of RizzKey, dated 11 December 2024, from a reviewer posting as “jet pioneer”: “even though it says allow access that gives it a lot of data including personal, so should I trust it?” A customer documenting a permission prompt the listing never mentions.

Set that against App Review Guideline 4.4.1, which requires keyboard extensions to “remain functional without full network access and without requiring full access” and to “collect user activity only to enhance the functionality of the user’s keyboard extension on the iOS device.” The tension is the story. A rizz keyboard’s entire advertised feature is a network round-trip to a language model. The wording of 4.4.1 has not changed between 2020 and 2026.

What this finding is not. This is a finding about disclosure, not about observed behaviour. We did not install these apps, run them, or capture their network traffic. Whether any given app actually sets RequestsOpenAccess is visible only on-device or through binary inspection, and we did neither. Nothing below should be read as a claim that any of these apps is transmitting your messages. The claim is narrower and, we think, more damning: you are not told what you are about to be asked for.

The privacy-label loophole

The obvious next move is to check the privacy label on the store listing. That move does not work, and the reason is written into both platforms’ own rules.

Apple defines “collect” as “transmitting data off the device in a way that allows you and/or your third-party partners to access it for a period longer than what is necessary to service the transmitted request in real time.” If the data is discarded immediately after the request is serviced, developers “do not need to disclose this in your answers in App Store Connect.” Google’s ephemeral-processing rule is the same shape: data “only stored in memory and retained for no longer than necessary to service the specific request in real-time” is not shown on the public listing. Google adds something worth reading twice — its review process is “not designed to verify the accuracy and completeness of your data safety declarations,” and “you alone are responsible for making complete and accurate declarations.”

Put plainly: an AI keyboard whose whole function is sending your sentence to a remote model can, under both stores’ written rules, display a privacy label that says nothing whatsoever about typed text — provided the server discards it after replying. A clean label is not evidence that your text stayed on your device. It is evidence that someone answered a questionnaire.

Document by document

Here is the verified store data, pulled on 28 July 2026, for the apps in this space that ship real keyboard extensions — the eight above, plus Zinger and YourMove AI, two more keyboards in the same category that sit outside that group. Read the last column against the first.

AppPublisherRatingDeclared privacy label
Smoothspeak: AI Dating CoachProdTrace, Inc.4.75 (14,431)User content (messages, photos), coarse location, phone number — linked to you
RizzKey – AI Emoji KeyboardMETASTONE PTE. LTD.4.58 (2,732)Tracking: identifiers
WRizz: Rizz KeyboardDH Creations Inc.4.75 (2,343)Tracking: purchases, identifiers, usage data
CharmKey: AI Rizz KeyboardSEARCHADREAM LTD4.68 (1,113)Tracking: identifiers
YourMove AI KeyboardSquip AI LLC4.43 (98)Diagnostics / crash data only
RizzMode: AI Keyboard for Rizz佳慧 朱 (individual seller)4.95 (19)Data Not Collected
RizzPRO – AI Flirt KeyboardArt Hub Studio DOO4.94 (16)Data Not Collected
RizzPlus: AI Dating Keyboard文清 刘 (individual seller)3.80 (5)Linked to you: financial info, identifiers
Zinger: Rizz & Dating KeyboardShanghai Cheman Network Technology— (0)Linked to you: location, user content, identifiers, usage, diagnostics
App Store data via Apple’s public lookup API, 28 July 2026. Ratings are US storefront; the count is in brackets. Rizzio also ships a keyboard extension but is not shown here. Zinger had no ratings at all when we checked.

RizzModeis the cleanest documented contradiction in the set, and it is the one we have to own — more on that below. Its App Store privacy label says “Data Not Collected.” The privacy policy linked from that same listing says, in section 1.2: 「本应用的核心功能是为您提供AI辅助回复。为了实现此功能,我们需要访问您在键盘上的输入内容。」 — “the core function of this app is to provide AI-assisted replies. To achieve this, we need to access the content you type on the keyboard.” Section 1.1 adds device model, OS version, device identifier and IP address. Both statements cannot be a complete account of the same app. Three further details: the policy is Chinese-only on an English-only US listing; it is dated 20 May 2024 while the app was released on 24 November 2025, so it predates its own product by roughly eighteen months; and it never mentions screenshots or images, despite “Screenshot Analysis” being an advertised feature. The seller is an individual, 佳慧 朱, while the copyright line claims “RizzMode Inc.”, for which we found no independent web presence. It charges $8.00 per week — $416 a year — on a base of nineteen ratings.

WRizzdeclares that it tracks users across other companies’ apps, and publishes a privacy-policy URL that does not exist. Both legal links in its App Store listing — wrizz.app/privacy and wrizz.app/terms — returned 404 when we checked them twice in a browser on 28 July 2026.

RizzPROdeclares “Data Not Collected” while selling seven subscription SKUs. Its marketing makes claims no one can falsify: “+150% more dates - GUARANTEED!” and “3X more matches GUARANTEED!” — on a base of sixteen ratings. In fairness, this is the one where the paperwork holds up: rizz-pro.com loads and hosts a genuine, app-specific policy naming Art Hub Studio DOO, revised 23 May 2024.

RizzPluspoints its “Privacy Policy” and “App Support” links at the same address: lumina-3d.com/legal/privacy, a live page belonging to an unrelated AI 3D-model service that never mentions RizzPlus or keyboards at all. Four different entity names attach to this one app — the seller 文清 刘, a copyright line reading “Magic Core Liminted” (the typo is theirs), “CrazyDiamond”, and genworld.io. Five ratings.

Zingercarries the broadest privacy label we found anywhere in the category, and zero ratings. Released 27 May 2026, it declares location, user content, identifiers, usage data and diagnostics all as linked to you — with user content declared for the developer’s own advertising or marketing. It is age-rated 4+ for a dating product. Its privacy policy is hosted at car-slow.club, a Chinese-only site titled 梦想家亲子 (“Dreamer Parent-Child”). Credit where it is due, though: that policy does disclose that user input is sent to third-party AI. Of all the apps here, the one with the most alarming label is the one being straightest with you.

CharmKeypublished privacy and terms URLs on charmkeyboard.com, which returned a 504 Gateway Time-out on repeated attempts on 28 July 2026 — a 504 can be transient, so date-stamp that rather than treat it as permanent, but on the day we looked, the legal documents were unreachable. Its description also claims it “works with every keyboard” and “seamlessly integrates with iPhone like SwiftKey, Google Keyboard & Gboard,” which iOS keyboard extensions cannot do — they replace other keyboards, they do not integrate with them. It lists a “Lifetime Membership” at $0.00 next to another at $39.99.

RizzKeyis the same publisher on both stores, which is a good sign and rarer here than it should be. Its numbers differ sharply by platform: 4.58 from 2,732 ratings on iOS, against 3.8 from roughly 1,020 reviews across 100,000+ downloads on Google Play. We note the gap as a fact and draw no conclusion from it. Its Play data-safety panel manages to declare “No data collected” and “Data can’t be deleted” simultaneously. It is rated 4+ while shipping an “AI PicAsk” feature that generates, in its own words, seductive dialogues based on a photo.

Smoothspeakis the useful counter-example, and the reason the rest of this section is damning rather than merely untidy. It is unambiguously a keyboard — “bring Cue into any app: Tinder, Bumble, Hinge, iMessage, Instagram DMs, WhatsApp, Snap, and more” — with 14,431 ratings, a real corporate seller, and an update dated 21 July 2026. Its privacy label is by far the most expansive of any at-scale keyboard in this group: user content, specified as emails or text messages and photos or videos, declared as linked to you, plus coarse location and phone number. That is what an AI keyboard declares when it declares honestly. Which makes every “Data Not Collected” label above harder to read charitably. Smoothspeak is not blameless on marketing — it claims to be “trusted by 200,000+ people” against a US rating count of 14,431, and to be “built by AI experts from Stanford and Google”, neither of which we could verify — but on the disclosure question it is the one doing it properly.

The money

Almost everything here is a weekly subscription, which is the pricing model you choose when you expect people to cancel. RizzMode charges $8.00 a week, which is $416 a year. WRizz is $6.99 a week or $99.99 a year. RizzKey runs $5.99 to $19.99 a week and $59.99 to $79.99 a year. RizzPRO is $6.99 to $9.99 weekly, $48.99 to $69.99 annually. CharmKey is $4.99 to $9.99 weekly and $39.99 to $69.99 annually. RizzPlus is $5.99 a week or $69.99 a year. Smoothspeak spans $2.99 to $49.99.

Those ranges are not indecision — they are price ladders. RizzKey, CharmKey and RIZZ each publish ten in-app purchase SKUs, and Apple caps the displayed list at ten, so the ladders may well be longer than what is visible. Treat every figure above as a price someone saw, not a price everyone gets. You may be shown a number that is not listed here.

What is not true

This category attracts bad reporting, so here are the limits of what anyone can honestly say. iOS excludes custom keyboards from password and passcode fields, so no rizz keyboard is stealing your banking login. More importantly: across 2020 to July 2026 there is no confirmed case of a named AI or LLM keyboard being caught by researchers exfiltrating typed text. The capability is documented, the labelling loophole is documented, the commercial incentive is obvious — and the public record contains no smoking gun. Capability is not abuse. Relatedly, the last independent traffic analysis of Gboard and SwiftKey we could find dates from April 2022, which predates every generative feature either has shipped since, and nobody appears to have re-run it.

The historical incidents are real but narrower than they are usually made to sound. In December 2017, Kromtech Security Center found an unsecured MongoDB belonging to the keyboard app ai.type: 577 GB and 31,293,959 user records, including 6,435,813 contact-book records totalling over 373 million name-and-phone entries. The typed-text element came from ZDNet, which obtained and analysed the database and reported more than 8.6 million entries of text that had been entered using the keyboard, including search terms and, in some cases, email and password strings. ai.type disputed the characterisation — co-founder Eitan Fitusi said the company was not collecting, storing or sending password or credit card information, and that “there is no sensitive data there … the data is completely flat and non-personal.” It was never adjudicated.

In April 2024, Citizen Lab published The not-so-silent type, which tested nine vendors and found that eight of the nine had exploitable flaws revealing keystrokes in transit — most of them to a purely passive network eavesdropper, and Samsung’s Chinese build sent keystrokes over plain HTTP. Huawei was the only vendor with no issues found. Citizen Lab estimated that “up to one billion users are affected by these vulnerabilities.” The scope matters enormously and is almost always dropped: these were Chinese-market Pinyin input methods, and the flaws exist becauselogographic input drives cloud-based prediction. Citizen Lab states in the same report that Gboard and Apple’s keyboard are not cloud-based and could not be tested this way. This is not a finding about Western keyboards. Samsung’s issue was Chinese-ROM and Pinyin only, and was fixed. The nation-state reading of it is Citizen Lab’s own stated surmise, not evidence.

The closest thing to a keyboard threat aimed at ordinary users is Certo Software’s December 2023 write-up of custom keyboards used for cyberstalking, distributed primarily through TestFlight — which sidesteps full App Review — with keylogger-as-a-keyboard services sold from around $30. Certo named no product and established no case count.

One last warning, and it is a strange one. A number of confident-sounding keyboard-privacy statistics circulate widely on this topic — survey percentages, tracker counts, regulator investigation totals — that have no source at all. Several of them appear on the content-marketing blogs of AI-keyboard vendors themselves. If a keyboard privacy statistic reaches you without a linked primary source, assume it was invented.

What the honest ones look like

It is worth being clear that the category is not doomed by design, because several of the biggest keyboards handle exactly this problem well.

Citizen Lab, in a report whose entire premise is cloud keystroke transmission, notes that “keyboards that are not cloud-based include Google’s Gboard and Apple’s default iOS keyboard.” Microsoft SwiftKey states that without an account, “all personal and language data generated by Microsoft SwiftKey is stored locally on your device and is never transferred,” and that it “does not learn anything from fields marked as password fields, nor does it remember long numbers such as credit card numbers” — with typing-data snippets an opt-in. Grammarly is worth quoting precisely because it is candid: its support page says the keyboard “needs full access in order to connect to the internet … we use powerful servers to check your text,” that it “checks only the text you type while using it,” and that sensitive text “is ignored or excluded by our software on a best-effort basis.” That last phrase is Grammarly’s own, and it is the most honest four words written about this entire category.

A structurally different answer also exists. HeliBoard declares no INTERNET permission at all — a claim you can check yourself in its F-Droid permission listing rather than take on marketing faith. A keyboard that cannot reach the network is a keyboard whose promises you do not have to believe.

So the fair conclusion is not that keyboards are malicious. It is that the trust decision is invisible, one-time, system-wide and unverifiable. You grant it once, in a dialog, for every app you will ever type in, and after that you have no way of confirming what was done with it. That is a bad design for a decision this large — and it is why refusing to mention the decision in your store listing is not a small omission.

Our own correction

We listed RizzMode. It sat at the bottom of our best AI keyboards collection as the niche pick for dating replies, and it was named in our AI keyboard guide on the same basis. The research above is why it is no longer there. Its privacy label says data is not collected; the policy linked from its own listing says the app needs to read what you type. We should have opened that policy before we recommended it. The collection is now eight, and it does not include a rizz keyboard, because we could not find one we would stand behind.

What to do instead

If you already have one of these installed, Full Access is a per-keyboard toggle in iOS Settings, under that keyboard’s own entry in the keyboards list, and you can switch it off at any time. Guideline 4.4.1 requires keyboard extensions to remain functional without it, so a compliant keyboard should still type — if it stops working entirely without network access, that is itself informative.

To see where an app actually sends data, use Apple’s App Privacy Report — Settings › Privacy & Security › App Privacy Report, on iOS 15.2 and later. It lists the domains each app contacts — one of the few things in this article you can verify for yourself rather than take on someone’s word.

One clarification before the picks: RIZZ, Plug AI and Flirt AI are screenshot apps, not keyboards. You send them an image of a conversation and they suggest a reply. The Full Access argument above does not apply to them at all — they never sit between you and your typing. They have their own questions to answer about what happens to an uploaded screenshot, but they are not the subject of this piece.

And if what you actually wanted was a keyboard that writes better than you do, that product exists and is mostly free. The three biggest options — Gboard, Grammarly and SwiftKey — are all documented on this question, which is the minimum bar, and one no rizz keyboard cleared.

The keyboards we do recommend

ToolBest forPricingRatingApp Store
1Gboard logoGboardBest free defaultFree4.1(59K)
2Grammarly Keyboard logoGrammarly KeyboardBest for writing qualityFreemium4.7(220K)
3Microsoft SwiftKey logoMicrosoft SwiftKeyBest prediction + CopilotFree4.6(121K)
4
T
TypeAI
Best indie keyboardFreemium4.7(19K)
5CleverType logoCleverTypeBest for tone & translationFreemium4.1(123)
6BossAI logoBossAIBest for voiceFreemium4.7(6)
7
A
AI Keyboard — Orki
Best for draftingFreemium4.6(332)
8Omera logoOmeraBest lifetime pricingFreemium4.7(26)

App Store ratings checked July 29, 2026

Full comparison — platforms, free tiers, open source →

See the full comparison: Best AI Keyboards →

Get the digest

What changed in your tools — new picks, price shifts, and acquisitions. A short weekly email, no spam.

See the full comparisonBest AI Keyboards