No access-control bypass
CAPTCHA, 2FA, Passkeys, and identity verification always require a person.
Security boundaries
Vibe Launch Master runs directory submissions through a dedicated Chrome profile, keeps directory passwords in Chrome Password Manager, keeps AI keys in the operating system credential store, limits browser actions to audited targets, and stops for CAPTCHA, 2FA, Passkeys, payment, identity verification, or unknown high-risk terms.
Automatic browser execution
Submissions run through a dedicated Chrome profile controlled by the local app. Directory passwords remain in Chrome Password Manager.
Status: Controlled workflow ready
CAPTCHA, 2FA, Passkeys, and identity verification always require a person.
Card entry, paid placement, renewal, and paid-only submission remain blocked.
Ownership transfer, exclusive licensing, or unclear commitments stop for review.
The app records an unknown outcome and does not assume that the first action failed.
Credential and data location
The design avoids treating every piece of campaign data as one cloud record or one privileged application secret.
Storage boundary
Explicit exclusion
Trust boundary
Security is described through observable architecture and explicit exclusions rather than unsupported certification language.
Directory websites run in a dedicated Chrome profile on the user’s computer rather than a privileged app WebView or disguised cloud session.
Inspection, navigation, click, fill, select, upload, download, and final submit are limited to approved campaign hosts and operations.
The website does not claim zero telemetry, end-to-end encryption, SOC 2, ISO 27001, or another certification without independent verification.
Directory websites run in a dedicated Chrome profile on the user’s computer. The desktop app coordinates the workflow through the approved browser bridge and does not load arbitrary third-party directories inside a privileged application WebView.
Local data can include working documents, source snapshots, Launch Master versions, temporary asset variants, browser artifacts, detailed activity events, campaign checkpoints, and local credentials. Sensitive browser evidence must be masked before any optional synchronization.
Cloud data can include identity and organization metadata, minimal project metadata, signed capability records, registry-release metadata, release information, minimal campaign summaries, and receipt indexes. The exact released implementation remains authoritative for retention and telemetry fields.
The app records an unknown-outcome state and does not click final submit again. The user can inspect the real browser and the app can revalidate the destination state, but it cannot assume failure and create a duplicate listing or account action.
Users can disconnect the launch inbox, AI provider, dedicated browser profile, or account session. Revocation stops future capability use; durable receipts may remain when required to explain completed actions, subject to the published privacy and retention policy.