TubeNow is an independent desktop application around the official YouTube website. This document covers the data a user can encounter and the channel for security-sensitive reports.
| Version | Status |
|---|---|
1.0.x |
Current release line |
| Older versions | Upgrade before reporting a release-specific issue |
- Keeps the signed-in YouTube session in a local TubeNow application profile.
- Provides local Shields that reduce ads and tracking requests before they reach the player.
- Keeps YouTube navigation in TubeNow and sends unrelated links to the computer's default browser.
- Runs optional
yt-dlpdownloads locally when the user requests one and accepts the installation prompt when needed. - Does not operate a TubeNow account database, advertising SDK, or TubeNow analytics service.
YouTube traffic still goes to YouTube. Services used for protection updates remain external upstream services. TubeNow does not promise that every advertisement, tracker, or YouTube experiment behaves the same on every account and platform.
Treat these as private:
- the application profile and signed-in session;
- cookies, downloaded media, copied watch URLs, and screenshots containing account information;
- installer logs and diagnostic exports that include local paths;
- credentials, tokens, and private repository material.
Do not attach this data to a public issue. Redact account names, URLs, cookies, and personal paths before sharing a reproduction.
The public repository contains documentation, artwork, release notes, checksums, and installers. Implementation source and private engineering material stay in a separate private repository. See the public repository policy for the boundary.
Use the private contact channel listed on the GitHub profile rather than opening a public issue when a report includes an exploit, account data, credentials, or a security-sensitive reproduction.
Include:
- the affected TubeNow version, shell, operating system, and architecture;
- a minimal reproduction or proof of concept;
- the impact and any required account or network conditions;
- whether the issue affects a released installer or only a local build.
Allow reasonable time for investigation before public disclosure.
Release artifacts are built from the private source repository. The public release contains only the intended installers, package files, release notes, and checksums. A successful local build or installer download does not prove that every current YouTube account, video, or advertisement path behaves identically.