Privacy and trust
When a network tool says "we do not upload your data", that sentence only means something if you can check where the data actually goes. This page lays out every path.
Where every piece of data goes
| Data | Where it goes | Detail |
|---|---|---|
| Your network traffic | never leaves the device | decisions are made locally; there is no remote server to forward to |
| Access records | local database only | cleared when protection stops; exportable to CSV that stays yours |
| Rule lists | bundled inside the app | work offline from a fresh install; nothing is fetched from a server |
| Engine control channel | loopback only | listens on 127.0.0.1 only, on a random port, with a fresh random secret each config load |
| Analytics and crash reports | Huawei / Xiaomi builds only | processed by the Umeng SDK; the Google and OPPO builds contain no analytics code |
The local control channel
The interface and the engine live in two processes and talk over a local HTTP interface. How that interface is handled is worth stating explicitly:
- Bind address
127.0.0.1— loopback only, so nothing else on your network can reach it- Port
- randomly assigned, never fixed
- Authentication
- a fresh random secret is generated on every config load — not a constant compiled into the app
- Cleartext scope
- the network security config permits cleartext for
127.0.0.1andlocalhostonly, and the file documents why
Why the app excludes itself
ClearDeck keeps its own traffic out of the capture. That is not laziness: on some ROMs (observed on Huawei) the VPN blackholes the network entirely when its own relay sockets get captured by itself. It is an earned exception, not a casual one.
Both protocols captured
IPv4 and IPv6 are both taken over. Capture only IPv4 and every IPv6 connection bypasses the entire rule table — at which point the size of the lists stops mattering.
Rule downloads are HTTPS-only
Subscription links must be `https://`. The reason is plain: a rule list **is** the firewall rule, so a cleartext download would let a man in the middle rewrite what you block. Downloads also carry a connect timeout, a 32 MB ceiling, and SSL redirect following is disabled so an https URL cannot be downgraded to http.
Analytics and consent
The privacy notice on first launch is a hard gate: decline and the app will not run. What is collected after you agree is itemised there rather than buried in a long document.
| Huawei / Xiaomi builds | include Umeng usage statistics plus crash and performance reports |
| Google / OPPO builds | no Umeng code, no Umeng permissions, no Umeng manifest entries |
| How that is enforced | by module structure — those builds simply do not depend on :core-analytics-umeng. It is not a runtime flag. |
Deep inspection is the one feature that can see content
What it cannot do
- It cannot see the encrypted content of connections while deep inspection is off — the domain layer only gets a hostname.
- There is no account system, so there is no "cloud sync" feature that could carry data off the device.
- There is no remote node, so there is no copy sitting on a server somewhere.
The contact address on the legal pages is not final and will be replaced before release.
Get notified when ClearDeck launches
We are finishing the first release. Leave an email and we will tell you when it is ready — once, and nothing else.
Signups will open shortly.
Only used to tell you about the launch. No newsletter, no sharing.