Back to Privacy Hub
PressDeck: Button Remapper Privacy Policy
Last Updated: September 25, 2026
Quick Summary
PressDeck is a local-first Android physical-button shortcut utility. It uses a narrowly scoped, non-accessibility-tool AccessibilityService for supported raw hardware-key routes, supports a separate Motorola MyKey app-shortcut route on compatible devices, can ask Android to perform a system screenshot action without receiving screenshot pixels, stores configuration locally, and uses Google Play Billing for an optional one-time Pro entitlement.
App-Specific Details
Specific data handling practices for PressDeck: Button Remapper.
- AccessibilityService is limited to supported physical Volume Up/Down and explicitly tested Assist, Voice Assist, Macro, or legacy Bixby key routes; it does not retrieve window content, read screen/typed text, perform accessibility gestures, or use accessibility overlays.
- On supported Motorola Signature-family phones, MyKey can launch a private PressDeck app-shortcut target after the user selects PressDeck AI Key; this is separate from raw AccessibilityService key handling.
- A user-configured Take screenshot shortcut asks Android to perform the system screenshot action. PressDeck receives only whether Android accepted the request and does not receive, inspect, store, or transmit screenshot pixels.
- Stores shortcut mappings/parameters, pause/settings state, compatibility evidence, bounded local activity/service-health state, and a cached verified Pro entitlement in app-private storage.
- Google Play Billing processes the optional one-time pressdeck_pro_lifetime entitlement. Purchase tokens and signed purchase payloads are processed in memory and are not persisted by PressDeck.
- PressDeck has no PressDeck account, first-party cloud backend, advertising SDK, analytics SDK, attribution SDK, or crash-reporting SDK.
- The source manifest does not request INTERNET, but the merged app includes network permissions contributed by Google Play Billing for Google's billing/platform path; PressDeck does not operate a first-party upload endpoint.
- Clearing app storage or uninstalling removes PressDeck local data. Google Play purchase history remains governed by the user's Google account and can be restored.
Detailed Official Policy
Full technical and legal disclosure for PressDeck: Button Remapper.
# PressDeck: Button Remapper Privacy Policy
Last updated: September 25, 2026
## Summary
PressDeck is designed as a local-first utility. It has no PressDeck account, no first-party cloud
backend, no advertising SDK, and no analytics or crash-reporting SDK in the current source.
Shortcut configuration, compatibility results and the local activity log stay on the device.
PressDeck uses Android AccessibilityService only to receive supported physical volume-button key
events and explicitly tested raw Android Assist, Voice Assist, Macro, or legacy Bixby button events,
then run deterministic shortcuts configured by the user. PressDeck is explicitly declared as a
**non-accessibility-tool** service (`isAccessibilityTool=false`). Accepted raw button events are
processed on the device and are not sent or shared by PressDeck. AccessibilityService is not used
to read screen text, typed text, passwords, messages or app content, and PressDeck does not perform
accessibility gestures.
On supported Motorola Signature-family phones, the intended AI Key route is separate and local:
after the user selects **PressDeck AI Key** in Motorola MyKey settings, MyKey can launch a private
PressDeck app-shortcut target. Android may also expose that dynamic shortcut through other supported
shortcut surfaces, so PressDeck does not treat a shortcut invocation as proof of caller identity.
PressDeck does not receive the Motorola AI Key as a raw AccessibilityService event. Shortcut
invocations are processed on-device and are not sent or shared by PressDeck.
If the user assigns **Take screenshot**, PressDeck asks Android to run its system screenshot action.
PressDeck receives only whether Android accepted that request; it does not receive, store, inspect,
or transmit screenshot pixels and does not request screenshot-content capture capability.
If the user buys PressDeck Pro, the purchase is processed by **Google Play**. PressDeck receives
the purchase state, product identifier, purchase token and signed purchase payload from Google
Play so it can verify the Pro entitlement and acknowledge the purchase. PressDeck does not collect
or process payment-card or bank details.
## Data PressDeck handles locally
PressDeck can store the following in app-private local storage:
- shortcut mappings and parameters, such as the package name of an app the user chose to launch;
- whether shortcuts are paused and other app settings;
- device/build compatibility observations produced by compatibility tests or the verified Motorola
MyKey app-shortcut route, including which local delivery source supplied the evidence;
- a short in-memory activity history containing shortcut outcomes and service health;
- a Boolean cached Pro entitlement after a completed Google Play purchase is verified.
The implementation does **not** persist the Google Play purchase token, signed purchase JSON or
purchase signature. Those values are processed in memory during billing verification.
## AccessibilityService data
The accessibility service is configured for physical key-event filtering only. It:
- declares `isAccessibilityTool=false`;
- does not retrieve window content;
- does not inspect screen text or typed text;
- does not perform accessibility gestures;
- does not subscribe to accessibility event types;
- does not use accessibility overlays or the accessibility button.
- may invoke Android's system screenshot action only for a user-configured shortcut, without
receiving the screenshot content.
Release builds do not retain the rolling raw accepted-button diagnostic trace and do not emit that
trace to Logcat. Debug builds may keep a bounded in-memory trace for engineering diagnostics; it
is not persisted or transmitted. Only Volume Up, Volume Down, Android Assist/Voice Assist/Macro
1/2, and the legacy Samsung Bixby code can reach raw-key gesture processing. Every other key is
rejected immediately. A raw optional device-button code remains inactive until the exact
device/build passes the visible complete-stream check. Motorola MyKey shortcut invocations are a
separate app-shortcut route and never count as raw AccessibilityService evidence.
Because PressDeck is not an accessibility tool, onboarding shows a separate prominent disclosure
before opening Android Accessibility settings and requires an affirmative user action. Choosing
**Not now** does not request or enable the service.
## Google Play Billing
Google Play Billing is used only for the one-time `pressdeck_pro_lifetime` digital entitlement.
Google Play is responsible for the purchase sheet and payment processing. PressDeck queries
Google Play for current ownership when the app returns to the foreground or when the user taps
Restore purchase.
A pending purchase does not unlock Pro. A completed purchase must pass verification before the
local entitlement is granted. Transient Play/network failures do not revoke a previously verified
offline entitlement. Revocation occurs only after a successful authoritative ownership query no
longer contains a completed Pro purchase.
Google's own handling of data through Google Play and the Google Play Billing SDK is governed by
Google's policies and the user's Google account relationship with Google.
## Network and sharing
PressDeck application code has no first-party server, upload endpoint, analytics transport, or
advertising transport. Its source manifest does not request Android `INTERNET`.
The **merged packaged app does include `INTERNET` and `ACCESS_NETWORK_STATE`** because the pinned
Google Play Billing 9.1.0 dependency graph contributes those normal Android permissions through
Google-owned transport components. Those permissions support the Google billing/platform path and
do not create a PressDeck-operated backend. PressDeck's release gate pins the expected Billing
version and exact merged permission set so a future SDK change cannot silently broaden this
contract.
PressDeck does not sell user data.
The support action opens the user's own mail application with a pre-filled local diagnostic
summary. Nothing is sent until the user reviews and sends that email through their chosen mail
provider.
## Permissions and special access
PressDeck uses AccessibilityService for the purpose described above and `MODIFY_AUDIO_SETTINGS`
for volume-behavior reproduction when PressDeck legitimately owns a compound gesture stream. It
does not request Notification Policy Access; while DND is active or unreadable, PressDeck yields
the stream to Android rather than risking a volume replay that Android may reject.
Google Play Billing 9.1.0 contributes `com.android.vending.BILLING`, `INTERNET`, and
`ACCESS_NETWORK_STATE` to the merged package. The final permission inventory must be regenerated
from the exact merged release manifest before publication. `tools/release/verify-release.py`
automates the release-manifest, service-metadata, signing and R8 contract checks after the release
artifacts are built.
## Data deletion
PressDeck has no user account or server-side profile. Users can remove local PressDeck data by
clearing app storage or uninstalling the app. Because a Google Play purchase belongs to the user's
Play account, clearing PressDeck's local data does not delete the Play transaction; Restore
purchase can re-establish a verified entitlement from Google Play.
## Children, sensitive data and advertising
PressDeck is not designed to collect children's personal information. The current source contains
no advertising SDK and does not use accessibility access for advertising, profiling or analytics.
## Changes
If a future version adds analytics, crash reporting, a PressDeck backend/account, ads, or any new
SDK that processes user data, update this policy, the in-app Privacy & data screen,
`docs/data-safety.md`, the Play Console Data Safety declaration and actual product behavior
together before shipping that version.
If AccessibilityService usage changes, update the prominent disclosure, reviewer video/declaration,
and obtain any newly required user consent before release.
## Contact
For privacy questions, contact Quazmoz@vivaldi.net.
General Privacy Terms
These terms apply across all our applications.
Questions or privacy requests? Contact us at Quazmoz@vivaldi.net