The app signs in locally (device-bound key and PIN) and never signs into the cloud; selling and every core function work with no network. The launcher itself has no account and is unaffected by this mode
LNCH-0034○ PlannedLite and ProCoreFree (launcher)Optional online action
The app signs in with cloud credentials so online-network features (Tap to PayCard acceptance on a phone via NFC, through a certified payment-provider SDK. Planned as an adapter; Simca does not read or store card numbers. Glossary, co-op counter, referral validation, board relay) can work; registration is needed only for this mode
Launcher open makes one disclosed update-manifest request
LNCH-0036○ PlannedLite and ProCoreFree (launcher)Optional online action
When opened and connected, the launcher makes one plain GET of the signed static manifest; no account data, no telemetry, no identifiers beyond the request itself; nothing is polled afterwards
The only request the launcher makes by itself is the single disclosed manifest request when opened; no hidden checks, no later polling, no telemetry; applying any update is always the user's action