Privacy Policy
PainTopia AutoClicker
This Privacy Policy explains what data the PainTopia AutoClicker collects, how it is used, and what permissions it requires. The AutoClicker is a companion app to PainTopia that automates tap gestures so the app can follow painting guides hands-free.
1. Overview
PainTopia AutoClicker is a foreground-only automation tool for Android. It works exclusively alongside the PainTopia app to dispatch tap and gesture actions at screen coordinates defined by PainTopia painting guides. The app requires a user account and verified access before it can be used.
PainTopia AutoClicker does not read, record, or transmit the content of your screen. It only dispatches taps at coordinates supplied by PainTopia — nothing more.
2. Account and Authentication
Google Sign-In (Firebase Authentication)
The app requires you to sign in with a Google account through Firebase Authentication. Firebase receives your Google account's name, email address, and profile photo URL in order to create and identify your account. This information is stored securely by Firebase and is not sold or shared with any other third party by us.
You can sign out at any time from within the app. Signing out removes your active session from the device.
Access control
Access to the AutoClicker is granted on a per-account basis. Your Firebase user ID (UID)
is stored in a Firestore access_control collection alongside an access status
flag. This record is used solely to determine whether your account is permitted to use
the app. It is not shared with third parties.
Voucher redemption
If you redeem a voucher code, the code and your UID are sent to a Firebase Cloud Function to validate and record the redemption. No additional personal data is collected during this process. Voucher records are stored in Firestore and are not shared externally.
3. Accessibility Service
PainTopia AutoClicker uses Android's Accessibility Service API solely to dispatch tap and gesture actions on your screen. This is the only supported Android mechanism for performing programmatic touch input without requiring system-level root access.
The Accessibility Service is enabled only when you explicitly activate it in Android Settings. It performs taps only while you have an active guide playing in PainTopia and have pressed Play in the floating overlay.
What the Accessibility Service does
- Dispatches tap and swipe gestures at screen coordinates provided by PainTopia.
- Operates only while the floating overlay is actively running and you have pressed Play.
What the Accessibility Service does NOT do
- Does NOT read, collect, or transmit any text, content, or UI elements on your screen.
- Does NOT operate in the background without your explicit action.
- Does NOT access passwords, messages, notifications, or personal data.
- Does NOT interact with any app other than PainTopia.
- Does NOT record or monitor your activity.
- Does NOT capture screenshots or screen content.
How to revoke
You can disable the Accessibility Service at any time:
Settings → Accessibility → PainTopia AutoClicker → Toggle off.
4. Permissions Used
Draw over other apps (SYSTEM_ALERT_WINDOW)
The floating overlay control panel is displayed over other apps using the SYSTEM_ALERT_WINDOW permission. This overlay shows playback controls and step progress. It does not capture or read the content of the apps beneath it. You must explicitly grant this permission from Android Settings and can revoke it at any time.
Foreground Service
The overlay runs as a foreground service so that Android does not terminate it while it is actively guiding a painting session. A persistent notification is shown while the service is running, in accordance with Android requirements.
Post Notifications
On Android 13 and above, the app requests notification permission to display the foreground service notification described above. No marketing or promotional notifications are sent.
Internet
Internet access is used for Firebase Authentication (sign-in), Firestore access control checks, and voucher validation via Firebase Cloud Functions. No other network requests are made by the app.
No storage, camera, or microphone permission
PainTopia AutoClicker does not request access to your storage, camera, microphone, contacts, location, or any other sensor or personal data store.
5. Data Storage and Retention
The following data is stored on Firebase (Google Cloud) on your behalf:
- Firebase Authentication profile (name, email, photo URL from Google Sign-In).
- Firestore
access_controldocument containing your UID and access status. - Voucher redemption records, if applicable.
Locally on your device, the app stores only SharedPreferences data: your tap delay setting, overlay width preference, auto-advance timer setting, and whether you have read the Accessibility Service disclosure. No images, audio, or personal files are stored by the app locally.
If you would like your account data removed from Firebase, contact us at the address
below and we will delete your access_control document and de-provision
your account.
6. Data Sharing
PainTopia AutoClicker does not sell your data. The only third-party services that receive data are Firebase services (Firebase Authentication, Cloud Firestore, and Cloud Functions), all operated by Google. Their handling of data is governed by the Firebase Privacy and Security documentation and Google's Privacy Policy.
No advertising SDKs are included in PainTopia AutoClicker. No data is shared with advertising networks.
7. Security
Access to the app is restricted to approved accounts. The Firestore
access_control collection is protected by Firebase Security Rules that allow
each user to read only their own document. Voucher validation is handled server-side
by a Cloud Function and includes rate limiting to prevent abuse.
The app build includes signing certificate verification in release mode. The app will refuse to launch if it detects it has been re-signed by an unauthorized party, protecting users from tampered APKs distributed outside official channels.
8. Children's Privacy
PainTopia AutoClicker is not designed for children under the age of 13 and does not knowingly collect personal information from children. If you are a parent or guardian and believe a child has registered an account, contact us at the address below and we will remove the account.
9. Your Choices
- You can sign out at any time from within the app to end your session.
- You can revoke the Accessibility Service permission at any time in Android Settings.
- You can revoke the Draw over other apps permission at any time in Android Settings.
- You can uninstall the app to remove all local data from your device.
- You can request deletion of your Firebase account data by contacting us.
10. Changes to This Policy
This Privacy Policy may be updated when new features are added. Any material changes will be reflected in an updated effective date at the top of this page. We encourage you to review this page periodically.
11. Contact
If you have questions about this Privacy Policy or about PainTopia AutoClicker, contact: