Zasady ochrony prywatności dodatku launchitall
launchitall Autor: gargoyle
launchitall
Last updated 17 September 2026
launchitall is a browser start page. This policy covers the website at
www.launchitall.com and the browser extension of the same name.
The short version. You can use launchitall without an
account, and then nothing at all leaves your browser. If you create an
account, your bookmarks are encrypted on your device before they are
uploaded. We store the encrypted result and hold no key that can open it,
so we cannot read your bookmarks — and neither can anyone who obtains our
database.
With no account, your bookmarks, notes, tasks and settings are stored only
in your own browser, in localStorage. We receive nothing. There
is no analytics, no tracking pixel and no advertising anywhere in launchitall.
Data | Why |
Email address | To identify your account, confirm it, and let you reset a password. |
An encrypted blob | Your bookmarks, notes, tasks and settings — encrypted before upload. We cannot read it. |
A device label per browser, such as “Firefox on Linux” | To show which devices are signed in and to enforce the one-device limit on free accounts. |
Your plan and subscription status | To know whether syncing is enabled. |
Sign-in timestamps | Ordinary security and abuse prevention. |
Your most-visited sites, encrypted — only if you turn on the Frequent group | So that group can appear on your other devices. Deleted when you turn it off. |
- Your bookmarks in readable form — not titles, not URLs, not even how many you have.
- Your password. A key is derived from it in your browser and never sent. What is sent for sign-in is a separate one-way derivation that cannot be used to decrypt anything.
- Your encryption key or recovery code.
- Your browsing history, with one exception you control, described below.
- Payment card details. Those go directly to Stripe; we never see them.
The extension can show a Frequent group built from your browser's
most-visited list. It is off unless you turn it on.
If you turn it on and you have an account, that list of
sites is encrypted alongside your bookmarks and synced, so the same group can
appear on launchitall.com and on your other devices. This is the only
browsing-derived data that leaves your machine. As with everything else in
the vault, we hold ciphertext and no key that opens it — but it is being
stored and transmitted, which is why it is called out here rather than buried.
The icon shown on each of those tiles comes from your browser's own
store, not from the site and not from anyone else — no request is made to
fetch it. Where it is small enough, it is stored with the site so the same
group looks the same on launchitall.com; it is encrypted exactly as
everything else in the vault is.
Hiding a site from that group records that you hid it, so it stays hidden;
that record sits in the vault with everything else and is capped. Turn the
group off and the stored copy is deleted, that record with it. Use it without an
account and the list never leaves your browser at all.
The extension requests topSites, so that adding a bookmark can
suggest sites you already visit often, and so the optional Frequent group can
exist at all. On Chrome it also requests favicon, which lets it
draw tiles with icons your browser already holds rather than fetching them
from the sites. Both are optional permissions, asked for from the settings
screen when you turn the feature on — the extension installs without a
permission prompt.
That list is read in your browser and used to draw the suggestion menu. It
is not transmitted anywhere unless you turn on the Frequent
group — the exception described above — and then only encrypted, into
your own vault. Leave that group off and it never leaves the machine.
The extension requests no access to your browsing history, your browser
bookmarks, or the content of pages you visit, and runs no content scripts. It
holds no access to any website unless you grant one: if you add a private ESPN
fantasy league, it asks for access to ESPN's fantasy service
(lm-api-reads.fantasy.espn.com) and nothing else, so that your
browser can send ESPN the sign-in it already has. Removing your last ESPN
league gives that access back.
- Supabase hosts the database and authentication. It holds the data in the table above, in encrypted form where stated.
- Stripe processes subscription payments and handles card details directly.
- Open-Meteo provides the forecast. Your chosen coordinates are sent to it to retrieve weather. It requires no account and sets no cookie. Remove the weather widget in Settings and no request is made.
- ESPN provides scores, and only if you add a team. The teams you follow are requested by name, so ESPN can see which ones they are and the address asking. It requires no account and no key. Follow no teams and nothing is ever requested from it; remove the Scores widget and the same is true.
- Sleeper and ESPN Fantasy provide fantasy football scores, and only for leagues you add. Your browser asks them directly: Sleeper by the username you type, ESPN by league ID. For a private ESPN league your browser includes your existing ESPN sign-in, which goes to ESPN and is never readable by the page or by us. Add no leagues and neither is contacted.
- ESPN Pick'em standings, if you add a Pick'em entry. Your browser asks ESPN for that entry by the ID in the link you paste, with no sign-in sent: ESPN serves an entry, its picks and its groups to anyone holding the ID, so treat the link as you would any shareable link. Add no entry and nothing is requested.
- Service status pages — GitHub's, Cloudflare's and any others you choose — are read directly from each service's public status page. They see the request and nothing else. Remove the widget and none is contacted.
- CoinGecko provides crypto prices, and only if you add a coin. Same shape: no account, no key, and no request at all unless you have asked for one.
- MaxFeeder, on Pro, and only if you set it up. Your browser fetches the feed from the address you give it, sending the API key you paste — the request goes straight there and never through us, so we never see the feed or the key. Both the address and the key live in your vault, encrypted like everything else in it. Leave it unconfigured and no request is made.
- Favicons. By default the page asks each bookmarked site for its own icon, and falls back to DuckDuckGo's icon service where that fails. You can restrict this to first-party requests only, or disable icon loading entirely, in Settings → Data. Bookmarks on your own network — a router, a NAS, anything at an address like 192.168.x.x, localhost or a .local name — are never contacted: their icon falls back to a letter, they are left out of the Frequent group, and the link checker skips them. The page does not scan your local network.
Settings → Account → Delete account removes your encrypted
vault, your device records and your login, and cancels any active
subscription. It is immediate and cannot be undone. The local copy in the
browser you are using stays until you clear it or reset from Settings → Data.
You can also export everything as JSON at any time from Settings → Data.
Your data becomes permanently unreadable, including by us. This is a
consequence of holding no key, not an operational limitation, and no support
request can recover it. Keep the recovery code shown when you sign up.
launchitall is not directed at children under 13, and we do not knowingly
create accounts for them.
If this policy changes materially, the date above changes and account
holders are notified by email before the change takes effect.
Questions, deletion requests or privacy concerns:
privacy@launchitall.com.