The plugin shows which programs are registered to start with Windows, switches one of them off or on when you press its key, and tells you when a new one has been registered. To do that it reads the startup entries of your PC from the Windows registry and from the two Startup folders (listed below), and it writes one small on/off mark in the registry when you press a Startup Toggle key. Everything stays on your PC: the plugin sends nothing to us or to anyone else, and it makes no network requests of its own.
While a key of the plugin is on the visible Stream Deck page (about once a second), and when a settings page asks for the list, the plugin reads:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run.%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) and in the one for all users (%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup), and the contents of those files (files up to 1 MB), only to work out a short fingerprint that tells the plugin when a file was replaced. The contents are not kept and not shown....\Explorer\StartupApproved keys (Run, Run32 and StartupFolder, under HKEY_CURRENT_USER and HKEY_LOCAL_MACHINE). This is where Windows keeps "enabled" and "disabled" for its Startup apps list.The plugin does not read the startup tasks of Store apps, services or scheduled tasks. It does not read which programs are running, your documents, what you type, or anything outside the places above. It takes no screenshots and injects nothing into other programs.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run (or ...\StartupFolder for a file in your Startup folder). This is the same value the Startup page of Windows Settings writes. When that entry had no mark before the plugin wrote one, the next press removes the plugin's mark again.HKEY_LOCAL_MACHINE. It does not ask for administrator rights.ms-settings:startupapps). The plugin writes nothing there. When that page opens, Windows itself may mark entries whose program file does not exist as off (see the Support page).| Data | Where it is processed | Stored by the plugin? |
|---|---|---|
| Names of startup entries, the names Windows shows for their programs, on or off, how many there are | Read from Windows on your PC; drawn on the keys and written into the Status line and the list of the settings page. These are shown by the Stream Deck app on your PC. | No, except what the next three rows say. |
| Command lines of startup entries, contents of Startup folder files | Read on your PC to find the program file and to work out a fingerprint (a hash). Kept in memory until the next reading. | No. A command line is never saved, shown or logged. |
| Key settings of a Startup Toggle key: the entry you chose (its name and place) and a fingerprint (a 16-character hash) of what it started when you chose it | Saved by the Stream Deck app on your PC, like the settings of any other key. The fingerprint lets the plugin notice when the same name starts something else. | Only in your Stream Deck profile on your PC. A profile you export or share contains the entry's name. |
| The list of entries New Startup App has shown as seen: for each one its name, its place and a fingerprint (a 16-character hash) of what it started then; no command lines | Saved by the Stream Deck app on your PC as this plugin's own settings. It is what makes "new since last time" possible. | On your PC only. |
| For each entry a Startup Toggle key switched: the on/off mark it had before and the mark the plugin wrote (12 bytes each) | Saved the same way, so that the next press can put back exactly what was there. | On your PC only. |
| Technical log | The Stream Deck plugin framework writes a small log file (mainly connection errors) in the plugin's folder on your PC. The plugin writes no entry name, no command line and no path into it. | On your PC only. It is not sent anywhere. |
| Anything sent to GRAMSHIFT servers | — | Nothing. The plugin has no server of its own and makes no network requests of its own. |
The plugin talks only to the Stream Deck app on the same PC, through a local connection (127.0.0.1) that the Stream Deck app provides to every plugin.
The plugin is sold on the Elgato Marketplace. Purchases, payments and licenses are handled by Elgato (Corsair) and its payment provider under Elgato's own terms and privacy policy. GRAMSHIFT never receives card details. If Elgato provides us with sales records (for example the date, country and amount of a sale), we use them only for accounting and tax.
If you contact us, we receive what you choose to send (for example your email address, your message and any screenshots; a photo of a key or a screenshot of the settings page can show the names of programs that start with your Windows). We use it only to answer you. Email to contact@gramshift.com is forwarded by our email forwarding provider (ImprovMX) to a mailbox hosted by Google (Gmail), so those providers process support emails on our behalf.
The plugin works only as a tool on your own computer: GRAMSHIFT does not receive or process anything from it. For sales records and support emails, GRAMSHIFT is the controller. We rely on our legitimate interest in answering requests and on legal obligations (for example tax records). GRAMSHIFT is based in Japan, so this information is processed in Japan and by the providers named above.
You can ask us to access, correct or delete personal information we hold about you, or object to its use, by emailing contact@gramshift.com. If you are in the EEA or the UK, you can also complain to your local data protection authority.
The plugin keeps nothing of its own except its key settings, its own settings (the list of seen entries and the remembered on/off marks) and its log file, on your PC. The log file is in the plugin's own folder. Key settings and the plugin's own settings are held by the Stream Deck app on your PC. Support emails are kept only as long as needed to handle the request and meet legal obligations; you can ask us to delete them. Sales records are kept for up to 7 years for accounting and tax.
If the plugin ever starts to send or store other data, this policy will be updated before that change is released, and the date above will change.
GRAMSHIFT · contact@gramshift.com · 1-10-8 Dogenzaka, Shibuya Dogenzaka Tokyu Bldg 2F-C, Shibuya-ku, Tokyo 150-0043, Japan