Privacy Note
Control Deck is local-first. Your decks, settings, and credentials are stored on your own device. Secrets (API keys and tokens) are kept in your operating system's credential store, not in plaintext. The Developer does not operate a hosted Control Deck account and does not collect analytics or usage telemetry from the app. Crash reporting is off by default and only runs if you turn it on (see below).
What the Developer receives
- Purchase. When you buy a license, payment is handled by Stripe, Inc. The Developer receives your email address and purchase details from Stripe but never your full card number. Your license key is emailed to you through Resend.
- Activation. To activate and periodically re-validate your license, the Software sends your license key along with a device identifier and device name to the Developer's licensing server (hosted on Supabase) so it can enforce the two-device limit and return a signed entitlement the app can check offline. No decks, prompts, or file contents are sent.
- Crash reports (optional, off by default). If you turn on crash reporting — during first-run setup or in Settings → Advanced → Privacy — the Software sends reports about unexpected crashes and errors to the Developer's error-monitoring provider (Sentry) to help fix problems. These reports include error messages, stack traces, and basic app and environment details. Before any report leaves your machine, license keys, tokens, and API keys are scrubbed, and your decks, prompts, and file contents are not sent. You can turn crash reporting off at any time; turning it off takes effect immediately.
This information is used only to sell and license the Software, provide support, improve reliability, and prevent abuse. It is kept only as long as needed for those purposes and to meet legal and accounting obligations, is never sold, and is not used for advertising. You may request access to or deletion of your data, subject to records the Developer is required to keep, by emailing license@ctrldeck.dev.
Feedback
Feedback is collected only through GitHub Issues, and only when you choose to file one. When you do, do not paste API keys, OAuth tokens, license keys, private prompts, customer data, or full terminal transcripts into a public issue.
Third-party services
The Software connects to third-party AI providers, command-line tools, and update services that you configure or that are needed to deliver updates. Those services have their own privacy policies and receive data according to your use of them.