ClearDeck
  • Beginner
  • 4 min read
  • Updated 2026-10-09

Install ClearDeck and turn on protection

What ClearDeck needs from your phone, why it asks for a VPN connection, and how to get protection running in about two minutes.

ClearDeck filters network connections on the phone itself. Setting it up means answering two prompts — one about privacy, one about the VPN connection Android requires — and then pressing one button.

What you need

Android 10 or later (Android 10 through 17 are supported)
Device An arm64 phone or tablet — essentially every phone sold since 2017
Root Not required, and not used
Account None. There is no sign-up and no subscription.

Step 1 — First launch: the privacy notice

The first thing ClearDeck shows is a privacy notice, and it is a hard gate: the app will not run until you decide. That is deliberate — a network tool should say what it does before it does anything.

missing src/assets/shots/en/consent.png
First launch · privacy notice

What the notice says, in short:

  • Collected, if you agree: device model and system version, app usage statistics, and crash and performance reports.
  • Never collected: the content of your network traffic. Protection runs on your phone, so the sites you visit and the requests you make are not uploaded.
  • Who processes it: the Umeng SDK, on the vendor’s behalf.

If you decline, the app cannot run, and it tells you so plainly rather than hiding behind a disabled button. You can reopen it later and agree then. Tap Agree and continue.

Step 2 — Why Android asks about a VPN

Android has exactly one supported way for an app to see the traffic of other apps: the VpnService API. So ClearDeck asks for it — but the wording Android shows you is generic, and it sounds alarming, because most apps that request a VPN connection are routing your traffic through a server somewhere.

ClearDeck explains itself first, before the system dialog appears:

missing src/assets/shots/en/vpn-rationale.png
ClearDeck explains before Android asks

ClearDeck needs to set up a VPN connection to check every app’s traffic on this device. The traffic stays on your phone — nothing is sent anywhere.

Tap Continue, and Android’s own consent dialog appears. Accept it. Android will then show a persistent key icon in the status bar — that icon means a VPN service is running, which in this case means ClearDeck is filtering locally.

Step 3 — Start protection

Open the dashboard and tap Start protection.

missing src/assets/shots/en/dashboard.png
Protection running

When protection is on, the dashboard begins filling in: live upload and download rates with a 60-second chart, active connections, total traffic, how many connections were blocked, and how much traffic those blocks saved. On a fresh install these are all near zero — they start counting as your apps do things in the background.

Step 4 — Survive a reboot

By default Android tears the tunnel down when the phone restarts, so you have to remember to start it again. Two settings fix that.

  1. In ClearDeck, open Settings → Start with system. This opens Android’s VPN settings screen directly.
  2. In that list, tap the gear icon next to ClearDeck and turn on Always-on VPN. If the system also offers Block connections without VPN, consider enabling it too.

Step 5 — Confirm it is actually working

Protection is working if all three of these are true:

  • The dashboard says Stop protection (not Start protection), so the tunnel is up.
  • Android shows the VPN key icon in the status bar.
  • The Blocked number on the dashboard climbs over a few minutes of normal phone use.

If the blocked count stays at zero after ten minutes of browsing, the most common causes are a second VPN app holding the connection, or the system killing the service after the screen has been off for a while. Both are covered in when protection will not start.

Next

This guide is also available in 简体中文

← All guides