Local-first architecture

Your checkout operation does not become our database.

This page separates what the Windows app keeps locally from the limited identity, billing, and release data handled by the account service.

Windows desktopMonitors, proxies, profiles, missions
SealedOps accountIdentity, plan, wallet, downloads
Connected providersStripe, Discord, retailer, optional services

SealedOps data flow

What stays on your PC

Product monitors, proxy configurations, checkout profiles, operational history, token references, and instance settings stay in the encrypted desktop vault. The account website cannot read them.

What reaches SealedOps servers

The account service stores your name, email, password hash, revocable sessions, plan and wallet state, device activation state, Discord link ID, referral status, and release entitlement. It does not run your monitor fleet.

Authentication and license checks

Website and desktop sessions are revocable. The desktop sends its device identifier and session credential to confirm account access; Discord can verify an already-linked identity without sharing your Discord password.

Billing and plan value

Stripe handles card billing and the customer portal. SealedOps stores Stripe customer and subscription references plus the entitlement result. Wallet credits are service value, not cash or a bank balance.

Desktop vault behavior

The desktop vault is encrypted at rest and bound to the local app data. Checkout data entered into the desktop remains local; cloud account pages never expose reusable checkout credentials.

Virtual-card providers

When configured, SealedOps stores provider references and requests the payment material needed for a supported checkout. Provider availability, terms, and transaction decisions remain outside SealedOps.

Proxy handling

Proxy endpoints and credentials stay in the encrypted desktop vault. Retailers and your proxy provider can still observe traffic routed through those services; SealedOps does not sell or bundle proxies.

Errors, analytics, and retention

Production error reporting may receive application faults and route names when enabled. Sensitive checkout fields are excluded. Account records and logs are retained only as needed for access, security, support, billing, and legal obligations.

Update delivery

Automatic updates require a signed release and preserve local app data. Separately labeled manual downloads may be unsigned: their file checksum is checked by the download service, but Windows cannot verify the publisher. Manual releases are not added to the automatic-update feed.

Uninstall and deletion

Uninstalling the app does not automatically delete the local vault so an update or reinstall can recover it. Remove local app data separately when you intend permanent device deletion, and contact support for hosted account deletion.