StemDeck Remote for iOS and Android
The short version:
This policy covers the StemDeck Remote apps for iOS and Android — the source is public at github.com/udeysri/StemDeckRemote, so anyone can verify what's described here against the actual code. StemDeck Remote is a companion to StemDeck, a separate desktop application; this policy covers the mobile apps only.
StemDeck Remote has no sign-up, no login, and no backend service operated by us. The app connects directly, over your local Wi-Fi network, to a StemDeck desktop instance that you pair it with — typically running on a computer in your own home. We never see your library, your songs, or anything else that passes between the app and your StemDeck instance, because that connection never touches a server we operate. There isn't one.
The following is stored locally on your device only, and never sent anywhere by the app:
| Data | Why |
|---|---|
| Your StemDeck's address and a fingerprint of its security certificate | So the app can reconnect and recognize your paired StemDeck without asking you to pair again, and to warn you if that certificate ever unexpectedly changes. |
| Downloaded stem audio files and library metadata | So songs already downloaded play back without needing StemDeck to be reachable every time. |
| Folders you create and songs you assign to them | Organizing your library on your phone is a feature of the app, not of StemDeck — folders exist only on your device and are never sent to StemDeck. |
| Songs you remove from the app (Trash) | Deleting a song from the app only hides it locally and remembers that choice, so it isn't re-downloaded next time you sync — it never deletes anything from StemDeck itself. |
Uninstalling the app deletes all of it, the same as any other app's local data.
The camera is used for exactly one thing: scanning the QR code StemDeck's desktop app displays when you pair. The camera feed is processed entirely on-device to read the code and is never recorded, stored, or uploaded — by us or by the on-device QR scanning library the app uses. If you pair by typing your StemDeck's address instead, the app never requests camera access at all.
Android's notification permission is used only for the standard media playback notification (the one with your song's title and transport controls) while a song is playing — not for anything sent from a server, because there isn't one.
There are none. No analytics SDK, no crash reporting service, no advertising, and no third party the app shares data with — none is included in either app. The open-source libraries StemDeck Remote is built on (Jetpack Compose, Media3, CameraX and ML Kit's on-device barcode scanner on Android; SwiftUI and AVFoundation on iOS) run entirely on your device and don't transmit anything on the app's behalf.
Because StemDeck Remote doesn't collect any personal data from anyone, it doesn't knowingly collect personal data from children either.
If this ever changes, the update will be made here and reflected in the app's store listings. Given this app's whole design is "no server, no account," we don't expect much to change.
Questions about this policy or the app's data handling are welcome — open an issue on GitHub.