ClearDeck

Features

ClearDeck has a small, bounded feature set, and this page goes through all of it in the order the app presents it. Everything described below is implemented in the 0.1.0 build; the numbers come from the rule files that ship inside it.

  • 452,521 bundled rules
  • 5 function modules
  • Android 10 – 17
  • no root

Blocking, in two layers

ClearDeck packs five rule modules into the APK, so they are there the moment you install and they work with no network connection. Three of them are domain lists: the connection names a host, the host is on the list, and the connection is rejected on the phone before it leaves.

The other two are URL lists. They only take effect once deep inspection is on, because judging them means reading the full address rather than just the hostname.

Module Layer Entries
Ad blocking Domain 81,143
Tracker blocking Domain 121,037
Deep ad blocking URL 1,597
Deep tracker blocking URL 9,538
Malicious site blocking Domain 239,206

452,521 entries in total, about 12 MB inside the installed APK.

The two URL modules are on by default but show as Paused until deep inspection is switched on — and the screen gives you a one-tap way to go and turn it on.

Every module applies to every app. A domain module says it in as many words: “Blocks this list’s domains for every app.” Turning one off asks for confirmation first and warns that its domains will no longer be blocked.

missing src/assets/shots/en/modules.png
Function modules

See each app’s traffic

Tap the active-connections number on the dashboard and you land on the app list. It has two tabs: Live shows what is connected right now, and History shows how many times an app tried, how many were blocked, and how long ago it last acted.

Open one app and you get Upload / Download / Saved, its blocked categories (deep-inspection hits are marked Deep), and its own access log. Every record in that log has a Block and an Allow button beside it. Either one opens Apply to…, where you choose This app only or All apps — so a single line in the log becomes a rule scoped exactly as wide as you meant.

Live and history

Two tabs: what is connected right now, and what each app has done over time — attempts, blocks, and the last time it acted.

A rule from one line

Block or Allow on any access-log record, then Apply to… — This app only or All apps.

Filters, grouping, export

All / Blocked only / Allowed only; By time or Group by site; remove a rule you added; Export log from the detail screen.

missing src/assets/shots/en/app-detail.png
App detail · access log

Your own lists

Two ways in, and both end up as modules you control, sitting alongside the bundled ones.

Import file

Import a .yaml, .txt or .mrs file. ClearDeck detects the kind — Domain list, IP list, Mixed list or Full URL matching — and the action, block or allow, and shows what it read before anything is applied. One file can be up to 32 MB.

Import link

Paste a subscription address. Only https:// links are accepted, because a rule list is firewall rules and a plaintext download could be rewritten in transit. Update refreshes it in one tap and shows when it last updated.

My block & allow

Everything you add by hand collects in one card alongside the modules. It is deliberately not a one-tap off switch. When it is empty it tells you how to fill it: open an app, expand its access log and tap Block or Allow on a record.

Deep inspection

Deep inspection is optional and off until you turn it on. It is the only part of ClearDeck that reads a connection, and that is only possible with a certificate you install on the device: an app’s requests are encrypted, and the certificate is what lets ClearDeck show them to you. The certificate stays on the phone and is never uploaded.

With it on, matching moves from the hostname to the URL path, so an article and an ad slot on the same host can be told apart. The screen carries a three-state badge — On / Off / Paused — and if the certificate is missing it says so plainly: “Not working yet: the ClearDeck certificate is not installed.”

Scope
All apps, or Only the apps I pick — with search and a Selected only filter.
Wi-Fi only
On mobile data, deep inspection turns itself off.
Content inspection limit
128 KB / 256 KB / 512 KB / 1 MB, default 256 KB. Content above the limit is passed through without a byte-by-byte check; a larger limit inspects more and uses more memory, a smaller one saves power and can miss an ad inside a large file.
Certificate
Install certificate writes cleardeck-ca.crt to Downloads and opens the system dialog; remove it under Trusted credentials → User.
missing src/assets/shots/en/deep-inspection.png
Deep inspection

Statistics

The dashboard leads with four numbers, switchable across Today / 7 days / 30 days:

Connections active right now — tap it to reach the app list
Traffic upload and download combined
Blocked how many connections were rejected
Traffic saved traffic that never left, because it was blocked
  • Blocked breakdown is a ring split by module, with a My rules slice and at most six slices — anything past that merges into Other.
  • Traffic destinations is a ring grouped by registrable domain (eTLD+1), so subdomains of one CDN do not fragment into dozens of entries.
  • Top 5 apps ranks by usage, with More opening the full history.
  • Two more read-outs sit at the bottom: the DNS resolvers currently in effect (those from your network are marked), and the intranet IP.
missing src/assets/shots/en/dashboard.png
Dashboard · today

Everyday operation

The things you set once and then stop thinking about.

Start with system
Start with system jumps to Android’s VPN list; open ClearDeck’s settings there and switch on Always-on VPN. After that the tunnel comes up at boot with no tap. The app ships no boot receiver, no WakeLock and no scheduler — the tunnel is held by a foreground service, not by a lock.
Encrypted DNS
Domain lookups travel over an encrypted connection. The default address is https://223.5.5.5/dns-query and you can swap it at any time.
Access log window
How many records to keep: 100 / 500 / 1000 / 2000, default 500. A bigger window keeps more records and costs more memory.
Power saving
One switch. It slows the speed read-out and pauses deep inspection to stretch the battery; while it is on, deep blocks and recent-activity records become fewer. Exactly which sampling periods it relaxes is written up on the privacy page.
missing src/assets/shots/en/settings.png
Settings
export

Export access log

Tools has one job: Export access log. It writes a CSV (RFC 4180, UTF-8 with BOM) named cleardeck-access-<subject>-<yyyyMMdd-HHmm>.csv with localized column headers. Records are cleared when protection stops, so export first if you want to keep them.

Measured on a OnePlus 6T (Android 11): over a 30-minute protected session the :tun process used 20.67 s of CPU — 1.148% of one core — while the UI process used almost none (it is frozen in the background). That is a measurement from one device, not a promise.

Requirements and licensing

What you need, and what it costs.

System
Android 10 – 17 (minSdk 29, targetSdk 37).
Processor
arm64-v8a only. It will not run on an x86_64 emulator.
Root
Not needed. ClearDeck uses Android’s own VPN API.
Price
Free. No subscription, no in-app purchase, no ads.
License
Open source, GPL-3.0.
Account
None. No sign-up, no login.

Get notified when ClearDeck launches

We are finishing the first release. Leave an email and we will tell you when it is ready — once, and nothing else.

Signups will open shortly.

Only used to tell you about the launch. No newsletter, no sharing.