Privacy
Privacy policy
The ChimpDeck app collects no personal data, shares nothing with anyone, and does not track its users. If you buy the Non Stop Pass, further down you will find exactly what the licensing system stores, and why.
Last updated: 9 September 2026
Who is accountable for this
The data controller is Tecno Eurotrading SL, tax ID ESB82779562, registered at Calle Caravaña 4, Local 1, 28805 Alcalá de Henares, Madrid, Spain.
You may exercise your rights of access, rectification, erasure, objection, restriction and portability at any time by writing to us from the contact form on this website. If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD).
What the app collects
Nothing. The app asks for no account, requires no sign-up, and sends no information to any server of ours. There is no analytics, no crash-reporting SDK and no advertising identifier: the manifest removes it explicitly.
This holds for the whole Android app, whether or not you own a Non Stop Pass. The phone takes no part in licensing: it sends no identifier and does not know what you have bought.
What stays on your device
The app keeps a few settings in your Android device private storage, readable only by the app and removed when you uninstall it:
- The name the server advertises on your network and the port it uses.
- The nicknames you give your controllers, tied to their serial number.
- Your preferences: auto-start, alerts, pairing key, controller-driven navigation.
- A summary of finished sessions (duration, bytes transferred, measured latency), which only you can export.
What travels on your network
When you plug in a controller and use it from the PC, the controller data travels between your Android device and your computer over your local network, using a USB/IP compatible protocol. That traffic never goes through any server of ours and never leaves your network.
The app advertises itself on the local network over mDNS so the client can find it. That announcement carries the name you gave the server and its address on your network.
Permissions and why
- USB device access: this is what the app does — read the controller you plug in.
- Internet and network state: to listen for the client on your local network and advertise on it.
- Foreground service (connected device): to keep the session alive while the PC is using the controller.
- Notifications: for the ongoing server notification and session alerts.
- Start on boot: only if you turn it on, to bring the server back after a restart.
Children
The app is not directed at children under 13, and since it collects no data from anyone, it collects none from children either.
Third parties
The published build ships no third-party library that collects data: no analytics, no advertising, no Google Play Services. We share nothing with anyone because we collect nothing.
The form on this website
Everything above is about the app. This website also has a contact form, and it is worth saying what happens with what you write there: your name, your email and your message are sent by email to our support mailbox and used only to reply to you. They are not stored in any database, they feed no mailing list and they are shared with nobody.
To keep spam out, the server counts how many messages arrive from the same IP address over a few minutes. That count lives in the process memory, with no IP tied to any message, and disappears on its own shortly after. The website carries no analytics, no tracking cookies and no third-party services.
The Non Stop Pass and the Windows client
This part does process data, which is why it is spelled out in full. When you activate the Non Stop Pass, the Windows client talks to our licensing server to check that the licence is yours and that it is used on a single computer. This is what gets stored, and nothing else:
- The cryptographic digest (SHA-256) of your twelve-word phrase. The phrase itself is never stored: if someone stole the database, they would get no usable licence out of it.
- A random installation identifier, generated by your computer and unrelated to you as a person.
- Five cryptographic digests of the machine (motherboard, disk and the like). The original serial numbers never leave your computer: only the digest travels, and it cannot be turned back into them.
- An encryption public key for that installation, the client version, and the dates it was registered and last seen.
- For free-tier play time, only a digest of the machine and the seconds played in the current cycle. It deletes itself when the cycle ends.
- To detect one key being shared with many people, the digest (SHA-256) of the IP address and how many times it was seen that day. The address itself is never stored, and the record deletes itself after 30 days.
What the licensing system does NOT hold
There is no name, no email address and no payment details: none of that reaches the licensing database. Nor is there anything about what you do — what you play, when, or which controllers you use — because controller traffic never passes through any server of ours and still stays on your local network.
The legal basis is performance of the purchase contract, so we can give you what you paid for, plus our legitimate interest in a licence being used on one computer rather than a thousand. Your licence data is kept for as long as the licence exists; everything else deletes itself within the periods above. It is never shared or sold.
Changes to this policy
If a future feature ever needed to process data, this page would be updated before that version is published, stating the date of the change.
For any question about this policy, write to us from the contact form