Information we collect
CloneTap does not collect usage analytics, advertising identifiers, location, contacts, audio, video, messages, passwords, interface text, or another app's internal data. An account is not required. If you choose Google sign-in, Firebase Authentication processes your Google account identifier and basic account details such as email address, display name, and profile image URL to identify your private backup. CloneTap does not copy those identity fields into profile documents.
If you are signed in, Cloud Firestore stores your Firebase user ID and profile JSON: profile name, target app package name, screen size/orientation, user-positioned control geometry, interface settings, and normalized coordinates and timing for Action Sequences you explicitly record. This data is used only for private backup and restore. It is encrypted in transit and access is restricted by per-user Firestore Security Rules. Firebase App Check with Play Integrity processes app/device integrity signals to reduce unauthorized backend access.
Local app data
Layout profiles, target app package names, interface settings, action sequences, and visual masks you explicitly create are stored in CloneTap's private storage on your device. Profile JSON is also copied to your private Firebase backup only while you are signed in. When you activate Mask and press Save, CloneTap takes one screen capture, retains only the cropped region under your configured Patch, and discards the full-screen bitmap from memory. Protected Android security windows cannot be captured. An action sequence contains normalized screen coordinates and timing only; it does not contain screenshots, interface text, passwords, messages, audio, or video. Mask crops are excluded from cloud JSON; a restored profile requires you to capture its mask again explicitly.
Google Play services
CloneTap uses the Google Play In-App Updates library to check whether a newer release is available. Google Play may process limited device metadata, app version, and installed module information for that check. Google Play, Firebase Authentication, Cloud Firestore, and App Check are Google services governed by Google's terms and privacy practices. CloneTap does not use Firebase Analytics, Crashlytics, advertising, or marketing profiling.
Profile sharing
A signed-in user can explicitly create a link to share one profile. Before the link is created, a protected Cloud Function validates and rebuilds the profile from an allowlist, removes all recorded Action Sequences, disables visual masks, and applies rate limits. The resulting layout geometry, profile name, and target package name can be read by anyone who has the unguessable link. Links expire after 30 days and Firestore TTL removes expired share documents. The receiving app shows a preview and requires confirmation; it never applies or runs a shared profile automatically. Deleting the cloud account also requests deletion of its active share links.
Android permissions
- Display over other apps: used only to show the controls and layouts that you explicitly start and create above other applications.
- Accessibility control service: after you touch a Clone on Android 13 or newer, the service uses Android's public touch-interaction API to transfer the held DOWN/MOVE/UP interaction to the Patch position you configured in the same active app. CloneTap keeps Android's direct physical stream instead of replacing it with a synthetic pointer, preserving native multi-touch. Experimental Gesture finish geometry from an older internal build may remain in a migrated local profile, but it creates no runtime input window or gesture. On older Android versions, live control uses only an accessible target's screen bounds, control type, numeric range, and supported actions. If you separately create an Action Sequence and press Record actions, the service records only the screen coordinates and timing of the taps, holds, and swipes you perform after the visible countdown; a Volume button stops recording. The saved sequence can be replayed only from its user-created trigger and remains in the local profile. If you activate a visual Mask and press Save, the service takes one screenshot after hiding CloneTap's own windows, stores the complete cropped image beneath your Patch in app-private local storage, and discards the full screenshot. Screenshot capture is blocked on Android security, permission, installer, Settings, System UI, and Google Play surfaces. The service has touch-interaction, window-content, gesture, key-filtering, and screenshot capabilities only for these user-started functions. It does not transmit interface images or access interface text, passwords, messages, or another app's internal data. It also receives the active package name so controls are blocked outside the app linked to the profile.
- Foreground service: keeps an active overlay session available after you start it. Android shows a persistent notification while the service is running, and you can stop it at any time.
- Notifications: used for the visible foreground-service notification on supported Android versions.
Data retention and deletion
Local profiles and visual-mask crops remain until you delete them in CloneTap, clear app data, or uninstall the app. Private Firebase profiles remain until you delete the profile or your cloud account. A profile deletion may leave a minimal tombstone containing only the random profile ID and deletion time so deletion synchronizes across devices; deleting the cloud account removes its profile documents and tombstones. Use Delete cloud account inside CloneTap, or follow the public account deletion instructions. Google may retain limited service logs according to its documented legal and security retention requirements. Firebase states that deleted Authentication information is removed from its live and backup systems within 180 days.
Security and third parties
CloneTap does not sell personal data or share it for advertising. Firebase access is scoped to the signed-in Firebase user ID, protected by Security Rules, TLS, and App Check. Client writes to the public sharing collection are denied; only an exact, unexpired link can read a sanitized share. Accessibility target matching, control actions, gesture execution, screen-mask cropping, and active-package matching remain local on the device.
Children
CloneTap is not directed to children under 13. The early testing release is intended for adults aged 18 and over.
Changes to this policy
If CloneTap's data practices change, this policy and the Google Play Data safety declaration will be updated before the relevant app version is released.
Developer and contact
Developer: VETKA
App: CloneTap (com.momohvet.clonetap)
Privacy and support contact: dmdm75006@gmail.com
Effective date: July 20, 2026