Updated: 2026-10-11 · 2026-10-11.1
1. Apple Translation, Vision and Speech
ios
iOS uses Apple Translation to download selected language models and translate on device on supported systems, devices and languages. Apple Vision recognizes image text on device. Speech requires on-device recognition and reports unsupported devices or languages instead of switching to cloud recognition. The Noise Light computes local sound levels without uploading recordings.
2. Apple StoreKit and Keychain
ios
StoreKit loads products, starts purchases, restores lifetime Pro and subscriptions, and opens subscription management. Apple handles store accounts and payment. Baiboki receives signed transactions, product and transaction identifiers, subscription state and necessary account or installation identifiers for verification, grants, restoration, refunds and duplicate prevention, without full payment-card details. Keychain protects credentials and BYOK keys with device-only storage and no Keychain cloud sync.
3. Google ML Kit and Google Play Billing
android
Android uses Google ML Kit On-device Translation 17.0.3 and Text Recognition 16.0.1 for local translation and OCR; selected model downloads need a connection. Google Play Billing Library 9.1.0 handles products, purchases, restoration and acknowledgement or consumption. Google Play processes payment details; Baiboki receives necessary purchaseTokens, product and order state, and account or installation identifiers. Android Keystore-supported encryption protects local API keys. These components do not provide the corresponding iOS functions.
4. Expo, React Native and local storage
Expo and React Native components connect cameras, audio, sensors, brightness, haptics, files, photo selection and UI. AsyncStorage holds preferences, history and non-sensitive local state without uploading it. Sensitive API keys use platform secure storage. Expo Notifications registers only local reminders and badges, without obtaining a remote push token.
5. System speech and sharing
Text-to-speech, camera and sharing use system services you initiate. iOS recognition follows the on-device requirement above. Android recognition network behavior depends on the selected service and device settings. Availability depends on system, language, device and permission.
6. Hosted AI APIs
Baiboki forwards inputs, authorized images and selected context through api.baiboki.com for tasks you initiate, and records account or installation identifiers, usage, credits and necessary diagnostic state. Current providers include Alibaba Cloud Model Studio (DashScope, Beijing region). The actual provider, capability and estimated credits are shown before sending. Providers may retain content under their terms for safety and legal purposes; zero retention is not promised. API services are not third-party SDKs installed on your phone.
7. Bring Your Own Key APIs
Your selected OpenAI, Gemini, Qwen, DeepSeek, Kimi or other preset or custom HTTPS provider is contacted directly by the device. First send and endpoint changes require confirmation. Withdrawing send consent blocks sending and keeps the local key; deleting the provider deletes its key. Providers receive request content, credentials and necessary network metadata. Individual information-card AI translation sends the selected original field, potentially including medical, insurance or identity data; minimize sensitive inputs first. Gemini requires users aged 18 and over; do not send personal, sensitive or confidential information to unpaid services. See https://ai.google.dev/gemini-api/terms
8. Cloudflare, accounts and support
Cloudflare hosts, delivers and protects the website and routes email, potentially processing IP addresses, access times, browser details and security logs. Account services handle email addresses, protected verification and login digests, sessions and necessary abuse-prevention records. Support email handles contact details, messages and attachments you submit. See the website Privacy Policy.
9. Advertising, analytics and tracking
Baiboki currently has no advertising, cross-app tracking, third-party behavioral analytics, remote push or third-party crash-reporting SDK. New services will be reflected in website policies and applicable store disclosures. The website is the only policy-body source; the app caches only the same webpages it actually downloads for offline reading.

