SmartDeckPRIVACY

SmartDeck keeps product data local by default.

Desktop app storage

Your layouts, actions, settings, saved weather locations, and integration settings are stored in SmartDeck's Electron user-data folder on your PC, normally under %APPDATA%\SmartDeck in a packaged Windows installation. Spotify and Discord secrets and tokens are encrypted with Electron safeStorage before they are written to local configuration files; client IDs and other non-secret metadata remain plaintext. Up to ten local configuration backups may retain older encrypted credentials. Configuration exports omit integration secrets. Uninstalling SmartDeck does not automatically delete the user-data folder. SmartDeck does not include advertising tracking.

LRCLIB lyrics

Online lyrics are off by default. When you enable them, a Lyrics tile is visible, and no valid local result is available, SmartDeck sends the current track title, artist, album, and rounded duration to LRCLIB over HTTPS; its search request sends the title and artist. Successful lyrics are stored in lyrics-cache.json on your PC. The cache holds at most 200 successful entries and expires them after 90 days; unsuccessful lookups remain only in memory for 10 minutes. LRCLIB may receive network data normally included with a request, and its terms govern server-side handling.

Spotify integration

Spotify connection uses OAuth Authorization Code with PKCE in your system browser and requests the playlist-read-private and playlist-read-collaborative scopes. SmartDeck sends the OAuth client ID and authorization or refresh values to Spotify; it does not request or store a Spotify client secret. It retrieves the account display name and up to eight playlist summaries, which are held in memory rather than saved to a SmartDeck data file; artwork loads from the image host supplied by Spotify. The client ID and token-expiry timestamp are stored plaintext, while access and refresh tokens are encrypted with Electron safeStorage. Disconnecting clears SmartDeck's local tokens but does not call a Spotify revocation endpoint. Encrypted older token copies may remain in local backups until removed or rotated out.

Discord integration

Discord voice controls require a developer client ID and client secret, which SmartDeck sends with authorization or refresh values to Discord's OAuth token service. SmartDeck also communicates with the installed Discord desktop client through local IPC for voice status and controls. It receives the username, mute and deafen state, channel name, server-presence status, and participant names. Current voice data is held in memory. The client ID and any configured channel or invite link are stored plaintext; the client secret and OAuth tokens are encrypted with Electron safeStorage and may remain in encrypted local backups. Disconnecting closes the local Discord connection but does not clear or remotely revoke credentials. Clear saved credentials removes the local secret and tokens but leaves the client ID.

Dodo Payments licensing

In packaged builds, activation sends the license key and an instance name formed as “SmartDeck on” followed by the Windows computer hostname to Dodo Payments. Validation and deactivation send the license key and Dodo Payments instance ID. Dodo Payments may return license status, product details, instance information, customer email, and expiry information. SmartDeck stores the license in a separate license.json file: the license key is encrypted with Electron safeStorage, while the instance ID and name, customer email, expiry date, and last successful validation time are plaintext. The app validates a stored license at startup and when you request verification. Successful deactivation removes the local license file; uninstalling alone does not. Dodo Payments' terms govern its server-side purchase, license, instance, and validation records.

Payments and delivery

When commerce is live, Dodo Payments processes checkout, tax, receipts, refunds, secure order downloads, and license issuance as the merchant of record. Its privacy terms apply to information entered during checkout and the Customer Portal.

Desktop diagnostics

SmartDeck keeps a rotating local diagnostic log on your PC. If you choose Export diagnostics, the app writes a text file to the location you select containing the app version, packaged status, Windows version and processor architecture, Electron and Chromium versions, and recent local log entries after known email addresses, Windows paths, and credential-like values are scrubbed. The export is not uploaded automatically. If you separately enable remote diagnostics, sanitized error reports may be sent to Sentry; default personal information, screenshots, breadcrumbs, user data, request data, and performance traces are not sent by the desktop app.

Weather location queries

When you search for a place for weather features, the location text you enter is sent to Open-Meteo's geocoding service. After you select a result, its latitude and longitude are sent to Open-Meteo's forecast service to retrieve weather data. Open-Meteo receives the network information normally included with an internet request, such as your IP address. SmartDeck does not use browser or Windows precise-location permission for this lookup.

Website analytics

The production website uses Vercel Web Analytics for page views and a small set of product interactions, such as checkout-button placement, workspace selection, screenshot opening, FAQ use, section visibility, regional checkout routing, and an active homepage experiment variant. Query strings and URL fragments are removed from analytics URLs and referrers before submission. We do not intentionally send names, email addresses, order details, license keys, or other user-entered content through these events.

Website diagnostics

When configured, the website uses Sentry for sanitized client, server, and edge error monitoring and a 10% sample of performance traces in production. Session replay is disabled. Before an error event is sent, SmartDeck removes breadcrumbs, contexts, extra fields, request data, and user data, and Sentry is configured not to collect default personal information.

Experiment cookie

When a homepage copy experiment is active, SmartDeck may set a first-party, HTTP-only cookie containing only the assigned control or challenger variant. It exists to keep the experience consistent, is not an advertising identifier, and expires after 30 days.

Website and support

The public website does not intentionally set advertising cookies. If you contact support, we use the information you send only to handle your request and maintain necessary business records.

Your choices

You can leave online lyrics and remote desktop diagnostics disabled, disconnect Spotify, clear saved Discord credentials, choose whether to export diagnostics, remove saved weather locations, and deactivate SmartDeck from License settings before moving the license to another PC. You may contact us about privacy, analytics, diagnostics, or purchase records using the email below.

Questions? Email support@smartdeck.site.