Back to Privacy Hub
FlickDeck: Gesture Shortcuts Privacy Policy
Last Updated: October 5, 2026
Quick Summary
FlickDeck is a local-first Android and Wear OS gesture-shortcut utility. It stores configuration on the user's phone/watch, sends network requests only to user-configured endpoints after deliberate actions, and uses Google Play Billing for an optional one-time FlickDeck Pro Lifetime purchase. FlickDeck has no developer account, cloud backend, ads, analytics/tracking, remote configuration, or crash-reporting SDK.
App-Specific Details
Specific data handling practices for FlickDeck: Gesture Shortcuts.
- Stores gesture profiles, mappings, action configuration, bounded calibration/settings state, local sync/test state, a last-verified Pro entitlement flag, and a bounded phone execution ledger in app-private storage.
- Uses motion sensors only during explicit user-armed gesture sessions or practice/calibration flows; raw calibration sensor windows are not retained as long-term history or uploaded to a developer server.
- Uses Wear Data Layer to synchronize reduced configuration and one-shot execution metadata between paired devices; secret header values are not synchronized to the watch.
- Sends webhook/Home Assistant requests only to endpoints the user configured and deliberately triggers, either directly from the watch or via the paired phone according to the selected execution route.
- Uses Google Play Billing for one optional non-subscription FlickDeck Pro Lifetime purchase. FlickDeck does not receive payment-card/bank details or send purchase tokens or entitlement state to a developer backend.
- Report a bug and Copy technical details are explicit user actions. The allowlisted technical summary excludes profiles, mappings, endpoint URLs, headers/bodies, secrets, request/session IDs, purchase data, logs, and arbitrary user content.
- Android backup is disabled for both phone and watch. Delete local setup, clearing app data, or uninstalling removes app-owned local state on the relevant device.
- Does not use a developer account system, developer cloud backend, advertising SDK, analytics/tracking SDK, remote configuration, or crash-reporting SDK.
Detailed Official Policy
Full technical and legal disclosure for FlickDeck: Gesture Shortcuts.
# FlickDeck Privacy Policy
Last updated: October 5, 2026
## Overview
FlickDeck is a Wear OS gesture shortcut utility. It lets you configure gesture profiles and webhook actions on your Android phone, sync a reduced configuration to your Wear OS watch, arm a short gesture-listening session, practice/calibrate supported gestures, and trigger configured actions.
FlickDeck is local-first. It does not require a developer account, does not use a developer-operated cloud backend, does not show ads, does not use analytics/tracking/remote configuration, and does not include a crash-reporting SDK.
## Data FlickDeck stores on your devices
FlickDeck stores app data locally in app-private storage on your phone and watch. Depending on the features you use, this may include:
- gesture profiles;
- gesture-to-action mappings;
- action names/descriptions;
- execution location (Run on watch / Run via phone) and action revision;
- webhook URLs you configure;
- Home Assistant webhook URLs/IDs you configure;
- optional request headers and bodies you configure;
- timeout, cooldown, risk, confirmation, session, and screen-awake settings;
- bounded Gesture Coach/calibration parameters such as wrist/crown orientation and derived gesture thresholds;
- local sync/test state;
- a local last-verified FlickDeck Pro entitlement flag on the phone;
- a bounded phone execution request ledger used to prevent duplicate Run-via-phone side effects.
The Gesture Coach may temporarily hold derived feature samples from a short calibration session in memory while building a preview. FlickDeck does not persist those raw sensor windows as a long-term motion history and does not upload them to a developer server.
## Phone-to-watch configuration sync
FlickDeck uses the Wear Data Layer between your paired devices.
The phone is the source of truth for user configuration. The watch stores a reduced app-private mirror needed to recognize mapped gestures and execute/request actions.
For an action configured **Run on watch**, the watch mirror may contain the non-secret request information needed for direct watch execution, subject to FlickDeck's sync restrictions.
For an action configured **Run via phone**, the watch receives only metadata needed to safely identify/request that action, such as action/profile identity, safety policy, revision, and mapping. The canonical phone action's URL, HTTP method, headers, body, timeout, and Home Assistant target remain on the phone and are not copied into the PHONE action's watch mirror.
Secret header values are not synced to the watch.
## Run via phone
When you deliberately trigger an action configured **Run via phone**, your watch sends a one-shot same-app message to an eligible paired FlickDeck phone containing execution metadata such as:
- protocol/request ID;
- action ID and revision;
- source gesture/session identity;
- confirmation state;
- timestamp.
It does not send the canonical endpoint or HTTP request configuration for the phone to trust.
The phone reloads the action from its own local configuration and rechecks the current action revision, enabled/profile/mapping state, execution target, confirmation/cooldown overrides, and risk policy before it can execute the webhook.
To reduce duplicate external side effects, the phone stores a bounded local request ledger. A new request is recorded as in-flight before the external network action starts. Duplicate, conflicting, unreadable, or otherwise unsafe ledger states fail closed instead of blindly executing again. The ledger is app-private and is not sent to the developer.
If a cross-device result is lost after the command may have been accepted, FlickDeck can report the result as uncertain. It does not automatically retry a potentially mutating action merely because the reply was lost.
## Google Play Billing
FlickDeck offers an optional one-time purchase named **FlickDeck Pro Lifetime**. It unlocks unlimited profiles, actions, and gesture mappings. It is not a subscription.
The purchase is presented and processed by Google Play. FlickDeck does not receive or store your payment-card number, bank-account details, billing address, or Google Account password.
The phone app receives only the Google Play product information and purchase state needed to:
- display the localized price;
- start the Google Play purchase flow;
- determine whether FlickDeck Pro is owned;
- acknowledge a completed purchase;
- restore entitlement on reinstall/another compatible device; and
- remove local Pro access after Google Play reports a refund/revocation.
FlickDeck does not send purchase tokens, purchase history, payment information, or entitlement state to a developer-operated server. Google Play's handling of purchase/account information is governed by Google's terms and privacy policy.
## Secrets and sensitive values
Webhook URLs, Home Assistant webhook IDs, headers, and request bodies can be sensitive because they may grant access to systems you control.
FlickDeck uses app-private storage and redaction safeguards. Sensitive-looking values are not intended to appear in logs, diagnostics, or default exports. Secret header values are not synced to the watch.
Run-via-phone can keep canonical request material on the phone, but it does **not** make general phone configuration universally encrypted at rest. Do not put long-lived credentials in URLs/bodies unless you are comfortable storing them in FlickDeck's local app data and transmitting them to the endpoint you selected when the action runs.
## Network requests
FlickDeck sends network requests only when required for an app feature you use, including:
- Google Play product/purchase operations;
- Wear Data Layer communication between your paired devices;
- user-configured webhook/Home Assistant actions after deliberate gesture/confirmation execution.
A configured network action can run directly from the watch or, if you choose Run via phone, from the phone. The request goes to the endpoint you configured. The FlickDeck developer does not receive it unless you deliberately configure an endpoint controlled by the developer.
Public webhook URLs must use HTTPS. Plain HTTP is intentionally limited to validated local-network/homelab targets. FlickDeck revalidates destinations and redirects, refuses public HTTP/unsupported schemes/HTTPS-to-HTTP downgrade/cross-origin redirects, bypasses system proxies for permitted cleartext local traffic, and does not automatically retry or redirect-replay mutating requests.
Plain HTTP does not provide transport confidentiality even when its destination is permitted. Prefer HTTPS for confidential request content.
## Help and support
FlickDeck exposes an explicit **Report a bug** action. The Android companion opens the FlickDeck support page in a browser. The Wear OS app opens that same support page on the paired phone so a report never requires watch typing. The support URL contains only the flow type, source platform, and a bounded app version when available.
The Android companion can also copy a locally generated, allowlisted technical summary after the user taps **Copy technical details**. That summary contains only app/version, Android release/API, and device manufacturer/model. It cannot contain profiles, action names or configuration, gesture mappings, webhook/Home Assistant endpoints, headers, bodies, secrets, relay request/session IDs, purchase data, logs, or arbitrary user content. Nothing is automatically attached or uploaded by FlickDeck; information entered into the external support form is submitted only by the user's explicit action.
## Data collection by the developer
FlickDeck does not automatically collect FlickDeck app data on developer-owned servers.
FlickDeck does not use developer cloud sync, analytics SDKs, advertising SDKs, tracking SDKs, crash-reporting SDKs, telemetry backends, or remote-configuration services.
## Data sharing
FlickDeck does not sell or rent your personal data.
User-triggered webhook requests are sent to endpoints you choose as part of the app function you requested. Those endpoints may be controlled by you or third-party services such as Home Assistant, n8n, or a custom API; their privacy practices are governed by their own policies.
Google Play processes FlickDeck Pro purchases directly under Google's terms. FlickDeck does not provide payment credentials to the developer or to user-configured webhook endpoints.
## Backups and exports
Android backup is disabled for both FlickDeck phone and watch applications.
Where local setup export is available, exports are designed to exclude secrets by default. You are responsible for where you store/export files.
## Data deletion
The phone app provides **Delete local setup**. This clears canonical phone configuration and queues an empty persistent configuration for the paired watch.
If you need immediate removal on a disconnected watch, clear FlickDeck app data or uninstall FlickDeck from that watch. You can clear all other local FlickDeck data—including local calibration, entitlement cache, and the phone execution ledger—by clearing app data/uninstalling on the relevant device.
FlickDeck does not hold developer-server account data, so there is no developer-server account deletion request. Google Play purchase records are managed through your Google Play account and Google's policies.
## Children
FlickDeck is not directed to children and does not knowingly collect personal data from children on developer-owned infrastructure.
## Security
FlickDeck is designed to reduce accidental execution/data exposure through user-armed sessions, conservative gesture classification, non-executing practice/calibration, explicit confirmation for risky actions, cooldowns, metadata-only phone relay commands, phone-authoritative action revalidation, at-most-once relay admission, destination/redirect validation, redaction, and the absence of developer cloud collection.
No app can guarantee absolute security or guaranteed gesture recognition. FlickDeck should not be used for emergency, medical, or other safety-critical actions.
## Third-party services
FlickDeck may interact with Google Play and services you configure, such as Home Assistant, n8n, custom webhooks, or other automation systems. FlickDeck is not affiliated with or endorsed by those services unless explicitly stated.
## Changes to this policy
This policy may be updated as FlickDeck evolves. The date at the top will be updated when substantive behavior/disclosures change.
## Contact
Use the developer contact email shown on FlickDeck's Google Play listing.
Do not send API tokens, webhook URLs, request bodies, purchase tokens, order IDs, relay request IDs, or other secrets in support emails.
General Privacy Terms
These terms apply across all our applications.
Questions or privacy requests? Contact us at Quazmoz@vivaldi.net