About
ClearDeck is a local network firewall for Android. It uses Android’s VPN API to look at each app’s connections on the device: a connection that matches a rule is rejected on the spot, and everything else goes straight out to the internet. No traffic passes through any server of ours — there is no server to pass it through.
- v0.1.0
- GPL-3.0
- Android 10 – 17
The company
ClearDeck is developed and maintained by Beijing Fenghong Technology Co., Ltd. (北京烽鸿科技有限责任公司). The app, this website, and the licence obligations described below are all that company’s responsibility.
What it is built on
ClearDeck does not hide where it comes from. The Android front end is derived from ClashMetaForAndroid, and the networking engine inside it is derived from the mihomo kernel. Both are published under GPL-3.0, and ClearDeck as a whole is released under GPL-3.0 too.
These are licence obligations, and they double as the honest answer to how the app does so much with so little CPU: the hard parts of tunnelling and rule matching were not written from scratch. The credit belongs upstream.
The bundled ad and tracker rule data comes from anti-AD, which is published under the MIT licence.
The rule lists are compiled from these upstream sources
| Source | Feeds |
|---|---|
| EasyList | ads |
| EasyList Ad Servers | ads |
| 217heidai/adblockfilters | ads |
| AWAvenue Ads Rule | ads, trackers |
| EasyPrivacy | trackers |
| AdGuard Tracking Protection | trackers |
| Hagezi Threat Intelligence Feeds (TIF, mini) | malware |
Engineering notes worth telling
A few decisions that are invisible from the outside but shape how the app behaves.
The UI cannot take the VPN down
The interface runs in the app process, and the engine runs in a separate :tun process. If the UI crashes, the tunnel keeps running — protection does not drop because a screen threw an exception.
Both IPv4 and IPv6 are captured
Traffic on both address families is routed through the tunnel. Capture only one and an IPv6 network would carry traffic around every rule without touching it.
The control channel stays on loopback
The local control channel listens only on 127.0.0.1, on a random port, and generates a fresh random secret every time a configuration is loaded.
Core logic is testable on a desktop JVM
The project is split into 9 Gradle modules. The pure-Kotlin ones — core-rules and core-analytics — carry no Android dependency, so their logic runs in ordinary JVM unit tests (19 test files at the time of writing).
It does not capture itself
ClearDeck adds itself to the list of apps the tunnel leaves alone: on some devices, letting the tunnel capture its own relay socket takes the network down.
Contact
For questions about the app or this site, write to:
contact@example.com
This address is a placeholder. The real contact address will be published here before release.
Status
ClearDeck is version 0.1.0 and has not been publicly released. It is not on any app store, F-Droid or GitHub Releases, and there is no public download yet. When it does ship, the source has to be available alongside it — that is what GPL-3.0 requires.
Legal
The three documents that ship inside the app are published here as well:
Get notified when ClearDeck launches
We are finishing the first release. Leave an email and we will tell you when it is ready — once, and nothing else.
Signups will open shortly.
Only used to tell you about the launch. No newsletter, no sharing.