Security boundary
Your credentials stay in your browser.
The backend coordinates campaigns without becoming a shared vault for directory passwords and active sessions.
Find the valid route. Leave a receipt.
Local secrets, synchronized state
Stays with you
- Directory passwords and authenticated browser sessions
- Email inbox access and verification messages
- CAPTCHA, payment, legal, identity, and social-auth decisions
- Payment instruments and directory billing details
Minimum synchronized state
- Project facts you confirm for submission use
- Eligibility decisions and campaign policy
- Attempt status, timestamps, and redacted evidence
- Secret-free human-action instructions and resume state
Controls built into the workflow
Scoped access
API keys identify the licensed operator and can be revoked without exposing browser accounts.
Dedicated inbox
A separate project email limits exposure and keeps verification work auditable.
Protected decisions
One project authorization covers standard non-exclusive listing terms. The agent still pauses for broader legal commitments, security challenges, purchases, or identity requirements.
Deletion controls
Project and scan data need clear deletion paths that match the published retention policy.
Prompt-injection resistance
Directory text is untrusted input. It cannot silently change campaign policy or secret boundaries.
Redacted evidence
Screenshots and logs should omit credentials, codes, and unrelated personal information before sync.
Report a security concern
Send a concise report to kenkenysy@gmail.com. Do not include passwords, active session cookies, verification codes, or personal data in the first message.
Start with fit, not a promise.
Scan a public product page to separate fully supported zero-touch routes from assisted candidates and product fit.