Privacy Policy
2026-10-05
MINISTRY OF GOOD VIBES LLC (“we”, “us”) operates the Deck Pointer app and the deckpointer.com website. This page explains, in plain terms, what data either one touches, why, and what you can do about it.
Who's responsible
Deck Pointer is made by MINISTRY OF GOOD VIBES LLC, a company registered in Wyoming, United States. For this policy we're the data controller for the website's waitlist, and the customer of the processor named below for app crash reports.
Questions or requests about your data go to hello@deckpointer.com.
The short version
The app's controls work without an internet connection. Your phone talks directly to your PC or Steam Deck over Bluetooth — we never see that input traffic and it never touches our servers.
Published builds send product-usage events to PostHog and crash reports to Sentry. These help us understand setup and fix bugs; Bluetooth input, presets, and Actions are not sent to either provider.
The website stores an email address only if you type it into the iOS waitlist form yourself, and only to send you the iOS test invite or update you asked for.
If you subscribe to free-game emails, the website keeps your email address and your settings in an account you can delete at any time. No ads, ad trackers, or cross-site tracking — on the site or in the app. Product analytics use a random app-installation or browser identifier, never your email address; the data and providers are described below.
What stays on your phone
Deck Pointer keeps everything it needs locally: your theme, scroll settings, control presets, and the list of computers you've paired with (each entry has that computer's Bluetooth address and the name it broadcasts, so the app can reconnect and remember your layout for it).
Recorded Actions — the clicks, waits, and keystrokes you capture for one-tap replay — are stored in a file encrypted with AES-256-GCM, keyed to your device's secure key store — the Android Keystore on Android, the Keychain on iOS. That key never leaves the phone and can't be exported. Actions can include a password you typed, which is exactly why we encrypt them: they never leave your device and we can't read them.
The app doesn't back any of this up to the cloud — Android's own backup and “restore on new device” features are switched off for Deck Pointer, and on iOS the same data is excluded from iCloud and encrypted device backups. Uninstalling the app deletes all of it. There's no account to close, because there's no account.
What goes over Bluetooth
Deck Pointer pairs with your computer as a standard Bluetooth HID device — the same kind of connection a physical mouse or keyboard uses. All it sends are HID input reports: cursor movement, button and scroll state, keyboard scan codes, and gamepad axes and buttons. Typed text is converted into the same keystrokes a physical keyboard would send.
That connection is between your phone and your computer only. It doesn't pass through any server of ours, we can't see it, and we don't log it.
Crash reports
If the app crashes, it sends an error report to Sentry (Functional Software, Inc.), our crash-reporting provider, hosted in the EU. A report can include: the stack trace, app version, device model, Android or iOS version, your phone's language setting, a random installation ID Sentry generates (not tied to your name or account — there isn't one), and a short trail of recent app actions (like “3 devices bonded” or “connect attempt”) with no device names or Bluetooth addresses in them. If the connection keeps dropping or cannot be restored, the app also sends one warning with the same short trail and the kind of computer (never its name), so we can see what happened without a crash.
We don't turn on screenshots, screen-recording, or Sentry's “send default PII” option, so your name, email, or exact location are never part of a crash report.
This exists for one reason: finding and fixing bugs. Our legal basis is legitimate interest in keeping the app working.
If you send a problem report from the app (Settings, the connection panel or the pairing guide), Sentry receives exactly what the form shows: the kind of problem you picked, the Steam Deck model and SteamOS channel you picked, the system version or computer description you typed, your optional note, any photos you attach, the app and phone details above, whether you restarted the phone or the computer, roughly how long the phone has been on (under 10 minutes, under an hour, under a day, or longer), the support code, the kind of computer and its Bluetooth stack version (such as “BlueZ 5.85”), whether the phone was connecting over Bluetooth or Wi-Fi, whether Wi-Fi is set up and how many Bluetooth attempts failed since the last working link, and the recent connection trail (the last few hundred connection steps kept on the phone, without names or addresses). Nothing is sent until you press Send report, and the report carries no email address unless you write one in the note.
Product analytics
Published builds of the app, and this website, send product-usage events to PostHog (PostHog, Inc.), processed in the United States. The app sends lifecycle events; events for connection attempts, successful connections, completed pairings, and connections that fail, drop or keep dropping; events for the first use of the trackpad, Live Typing and the gamepad; events for preset selection, layout saving and Action playback; and events for onboarding steps (started, device chosen, Bluetooth permission granted or denied, skipped or completed). On Android it also sends whether notifications were allowed during onboarding. When a connection ends, the app sends how it ended, how long it lasted and in how many seconds input was sent (never the input itself). It also sends the steps of the connect wizard and of pairing, the search for a Steam Deck over Wi-Fi, the moments when it could ask for a store rating and what you did in the seconds after, and whether you opened the rating link in Settings. Wi-Fi problem events also say whether a VPN was on. The website records page views and selected clicks. We use these to understand use and improve setup. Connection events also carry the kind of computer the app connected to (for example Steam Deck, Windows PC or Mac; never its name or address), and problem events carry a reason code or a rough duration such as “under 2 seconds”. Settings shows the first characters of the random installation ID as a support code; it is sent nowhere unless you paste it into a bug report or email. Debug builds of the app and preview deployments of the site send nothing.
An app event carries the app version, device model, OS version, and a random installation ID PostHog generates. It never carries a device name, a Bluetooth address, anything you type, or the contents of a preset or an Action. Session replay and screen recording are switched off in the app, and no person profile is created, because there is no account to attach one to.
On the website the events include page views and selected clicks, with the page address, the referring page, and browser information. PostHog session replay may run on the website and can capture page interactions and visible page content, including text entered into fields, unless that content is masked by PostHog or client-side configuration. PostHog receives the source IP address with analytics requests from both the app and the website and may use it to infer approximate location. This policy does not state whether raw IP addresses are retained.
If you subscribe to free-game emails, the website also records the steps of subscribing and signing in (for example code sent, signed in, subscribed) and which settings you changed — never your email address or the code. Links in our emails carry tags that tell PostHog which email and which link brought you to the site.
App permissions
Bluetooth (connect, advertise, and — on Android 11 and below — the legacy Bluetooth/Bluetooth Admin permissions): required to pair with and control your computer.
On iOS, Bluetooth is the only permission the app asks for, and the items below are Android names for the same jobs: the background Bluetooth mode keeps the connection alive.
Notifications: shows the “Connected to <device>” status while a session is running; you can deny it and the app still works, just without that notification.
Foreground service: keeps the Bluetooth connection alive while the app is in the background.
Internet: used to send product-usage events to PostHog and crash reports to Sentry, as described above. Bluetooth controls do not pass through our servers.
We do not request location permission, contacts, camera, microphone, or storage/file access, and Bluetooth scanning for nearby devices (BLUETOOTH_SCAN) is not used. PostHog can infer approximate location from the IP address as described above.
The iOS waitlist on the website
If you submit the form on deckpointer.com, we collect the email address, platform (iOS), and site language you provided. A honeypot field and a short-lived, in-memory rate limit on your IP address help keep the form free of bots. The waitlist function itself does not store the IP address; website hosting and PostHog analytics process IP addresses as described above.
We use double opt-in: the confirmation link is a signed token containing your email, platform, and language, valid for 24 hours, with nothing stored server-side until you click it.
Once confirmed, your email and the platform/language you chose are stored as a contact with Resend (our email provider) so we can send you the TestFlight invite or an iOS update, and a notification with the same details goes to our own inbox.
Free-game emails and your account
If you subscribe to free-game emails or sign in on deckpointer.com, we keep your email address, the stores you picked, whether emails are on, the site language you subscribed in and your browser's time zone, so emails show times you can use. You can change all of it on deckpointer.com/account/.
There is no password. To sign in we email you a 6-digit code and a link, valid for 10 minutes and usable once. The account and its settings are stored with Supabase, our database provider; the codes are mailed through our website by Resend.
You can switch the emails off or delete the account at any time on deckpointer.com/account/. Deleting removes your address and settings at once. Every email also has an unsubscribe link.
Who else touches this data
Vercel — hosts the website and its server functions (sign-ups, sign-in emails, the free-games pages), and sees ordinary web-server request logs (IP address, page requested) like any host does.
Supabase — stores the free-game accounts (email address and settings) and checks sign-in codes.
Resend — stores your waitlist contact and delivers our emails.
Sentry — receives app crash reports, as described above, processed in the EU.
PostHog — receives the product-analytics events described above, from published builds of the app and from this website, processed in the United States. Session replay is switched off in the app. Website session replay may run and can capture page interactions and visible page content, including text entered into fields, unless that content is masked by PostHog or client-side configuration. App events carry no device names or Bluetooth addresses.
If you use the in-app feedback button, Deck Pointer opens an external Ducalis feedback board in your browser. Deck Pointer does not transmit feedback data itself; Ducalis may process your browser/device details and IP address, plus content and email/account details you submit for voting or comments, under its own [privacy policy](https://ducalis.io/privacy-policy/).
Nobody else. We don't sell, rent, or share your data with advertisers, data brokers, or anyone outside this list, and none of these providers may use your data for their own purposes.
Cookies and tracking
One: PostHog (see “Product analytics” above) stores an identifier in your browser — a cookie on our own domain, alongside a matching entry in local storage — so that coming back tomorrow isn't counted as a new visitor. It is first-party, it says nothing about you, and clearing your browser data removes it.
Signing in for free-game emails also keeps your sign-in session in your browser's local storage, so you stay signed in. It is needed for the account to work, is not used for tracking, and signing out removes it.
Nothing else. No advertising pixel, no third-party tag, no cross-site tracking, no fingerprinting. The site's fonts are hosted on our own domain specifically so that a font request can't leak your IP address to a third party either.
How long we keep it
Waitlist contacts: until the iOS waitlist ends, or until you ask us to remove you — whichever comes first. (Contacts who joined the earlier Android waitlist are kept on the same terms.)
Free-game account: until you delete it on deckpointer.com/account/ or ask us to. Deleting removes it at once.
Crash reports: kept under Sentry's standard retention window (90 days for error events at the time of writing), then deleted automatically.
Product-analytics events: retained in PostHog according to our plan's retention settings; contact us to exercise your data rights as described below. We do not promise a 90-day deletion period for these events.
On-device data (presets, known hosts, Actions): kept until you delete it in the app or uninstall the app — that's fully under your control, not ours.
Your rights
If you're in the EU/UK/EEA (GDPR): you can ask to access, correct, delete, or export your data, or object to how we use it, by writing to hello@deckpointer.com. You can also complain to your local data protection authority.
If you're in California (CCPA/CPRA) or another US state with similar rights: you can ask to know what we hold, delete it, or opt out of any sale — we don't sell personal data, so there's nothing to opt out of.
Either way, write to hello@deckpointer.com and we'll respond within 30 days.
Children
Deck Pointer isn't directed at children, and we don't knowingly collect data from anyone under 13 (or under 16 in the EU). If you believe a child gave us data, contact us and we'll delete it.
International transfers
We're a US company; Resend runs in the US and Sentry in the EU. If you're in the EEA/UK, your data may be transferred outside it under Standard Contractual Clauses or an equivalent safeguard.
Changes to this policy
We'll update the date above when this changes. If a change is significant, we'll also email anyone on the iOS waitlist.