Privacy Policy
Effective date: September 27, 2026
This explains what Telescope collects, why, who handles it, and what you can do about it. It goes with our Terms of Service.
Who we are#
Telescope is run by Little Planet Labs, LLC ("Little Planet Labs", "we", "us"). It's a free service that tracks incidents at third-party providers by watching their public status pages.
This policy covers every part of Telescope:
- The website at telescope.littleplanetlabs.com
- The Telescope apps for iOS and Android
- The public MCP server at
/mcpthat AI agents can connect to (see Connect an agent) - The Telescope account on Bluesky that posts incident updates
The short version#
- There are no accounts. We never ask for your name, email, or phone number.
- We don't sell data, show ads, or track you across other sites or apps.
- The apps store a random device ID, a push token, and the services you watch, so we can send you notifications. You can delete all of it from the app's Settings with Forget this device.
- When an agent uses the MCP diagnosis tool, we send what it describes to an AI provider to find a matching incident. We don't save that text in our database, but we do keep a usage record that includes the caller's IP address.
What we collect#
Website#
- Analytics and performance. We use Vercel Web Analytics and Vercel Speed Insights to see which pages get visited and how fast they load. These tools collect page views and performance measurements along with basic information about the visit, such as the page, referrer, browser, device type, and country. We use them only in aggregate.
- Your service selection. If you pick which services to show on the dashboard, that choice is saved in your browser's local storage. It stays on your device and isn't sent to us.
- Cookies. Telescope doesn't set cookies of its own.
iOS and Android apps#
The apps don't have accounts. The first time you open one, our server creates a random device token and the app stores it (in the keychain on iOS, and in the app's private storage on Android). That token is how the app reads and changes its own settings. For each device we store:
- The device token and an internal device ID
- A push token: an Apple Push Notification service token and its environment on iOS, or a Firebase Cloud Messaging token on Android. Both apps get this token from Apple or Google when they launch and send it to us whether or not you've allowed notifications. The system permission controls whether your device shows notifications, not whether we have a token.
- The platform (iOS or Android)
- Your notification settings: how much detail you want and whether notifications are turned on
- The list of services you watch
- When the device was first registered and when it was last seen
The apps don't include an analytics or advertising SDK, don't read your advertising ID, and don't ask for your location, contacts, or photos. Nothing we store about a device can identify you by name.
MCP server#
The MCP server is public and doesn't need a key. It has two tools.
get_active_incidents returns the list of open incidents. We don't record anything about these calls beyond our hosting provider's standard request logs.
diagnose_suspected_failure takes a description of a problem and, optionally, code snippets, stack traces, or logs. Here's what happens with a call:
- The description and snippets are sent to TypeSafe, an AI provider, together with the list of services we monitor and their open incidents. TypeSafe's model picks the incident and services most likely involved.
- We don't save the description or snippets in our database. They may appear in our hosting or error logs, for example while we're investigating a problem.
- When a diagnosis finishes, we save a usage record with the caller's IP address, the approximate location our host derives from it (city, region, and country), the server region that handled it, the time, how long it took, how much model capacity it used, how many services and incidents were considered, and which incident matched, if any.
- To enforce rate limits, we count calls per IP address in a short-lived counter that expires within 60 seconds.
Don't send secrets
Anything you or your agent sends to diagnose_suspected_failure goes to a third-party AI provider. Strip out API keys, passwords, tokens, customer data, and other personal information first.
Bluesky#
Our Bluesky account posts public information about incidents. We don't collect anything about the people who read or interact with those posts. Your use of Bluesky itself is covered by Bluesky's own policies.
Email#
If you email us, we'll have your email address and whatever you write, and we'll use it to reply.
Hosting logs#
Like most websites, our hosting provider keeps request logs for every part of Telescope. These can include your IP address, browser or app details, the address requested, and the time. When something goes wrong, our error logs can also include details of the request, including a diagnosis request and the caller's IP address. We use these logs to keep the service running and to investigate problems and abuse.
Where status data comes from#
The incidents Telescope shows come from the public status pages of the providers we monitor, through their RSS feeds and webhooks. That data is about the providers' services, not about you.
How we use it#
- To run Telescope: show status, send the notifications you asked for, and answer MCP requests
- To enforce rate limits and protect the service from abuse
- To understand usage and cost, and to fix bugs and improve performance
- To reply when you contact us
- To meet legal obligations
What we don't do#
- We don't sell or rent your information.
- We don't show ads or share data with advertisers.
- We don't track you across other companies' websites or apps.
- We don't build profiles about you.
Who processes it#
We use a small set of service providers to run Telescope. Each one handles data only to provide its service to us.
- Vercel hosts the website, API, and MCP server, keeps request logs, provides Web Analytics and Speed Insights, and derives approximate location from IP addresses.
- PlanetScale hosts our Postgres database, which holds device records, watchlists, and MCP usage records.
- Upstash hosts the Redis store we use for rate limiting.
- TypeSafe runs the AI model that evaluates
diagnose_suspected_failurerequests. TypeSafe's handling of request content, including how long it's kept, is covered by its own privacy policy. - Apple delivers notifications to iOS devices through the Apple Push Notification service.
- Google delivers notifications to Android devices through Firebase Cloud Messaging. On Android, the Firebase Cloud Messaging SDK in the app also talks to Google directly and sends it a Firebase installation ID and delivery metadata.
- Bluesky hosts our public incident posts. We don't send it any information about our users.
Notifications contain the provider name and incident details, and pass through Apple or Google to reach your device.
We may also disclose information if the law requires it, to protect the rights or safety of our users or others, or as part of a merger, sale, or transfer of Telescope, in which case this policy would still apply to the information we hold.
How long we keep it#
We keep data as long as it's needed to operate the service. Here's how each kind of data can be removed.
- Device records and watchlists are kept as long as they're needed to operate the service. Forget this device in the app's Settings deletes them from our server. If the app can't reach us when you do that, a leftover record may stay on our server. It's no longer linked to the app or to you, and once the app re-registers, its push token is moved to the new record or cleared, so no notifications reach you through it. To be sure, try Forget this device again while you're online. Deleting the app doesn't remove the server record: on iOS the device token stays in the keychain and a reinstall picks it back up, and on Android the record stays on our server after the app is gone. Use Forget this device before deleting the app.
- Push tokens are cleared when Apple or Google tells us a token is no longer valid in response to a notification we try to send. That usually happens after the app is uninstalled, and only once a notification is actually attempted. Turning off notifications in your device's system settings doesn't clear the token.
- MCP usage records, including IP addresses and approximate location, are kept as long as they're needed to operate the service. You can ask us to delete records tied to your IP address.
- Rate-limit counters expire within 60 seconds.
- Diagnosis descriptions and snippets aren't saved in our database, though they may appear in our logs (see Hosting logs). TypeSafe's handling is covered by its own privacy policy, linked under Who processes it.
- Hosting logs and analytics are kept for the periods Vercel sets for our plan.
- Emails are kept as long as needed to deal with what you wrote to us about.
Your choices#
- Stop notifications with the notifications switch in the app's Settings. That's what stops us sending them, and it keeps your watchlist. If you only turn notifications off in your device's system settings, we still send notifications with incident details through Apple or Google, and your device just doesn't show them.
- Delete your app data with Forget this device in the app's Settings. It deletes your device record, push token, watchlist, and notification settings from our server, and the app starts fresh with a new, empty device record. If the app can't reach us at that moment, a leftover record may stay on our server. It's no longer linked to the app or to you, and once the app re-registers it no longer carries a working push token. To be sure, try Forget this device again while you're online.
- Ask us to delete MCP usage records by emailing telescope@littleplanetlabs.com with the IP address you used and roughly when. We can't link those records to you any other way.
- Block analytics with your browser's privacy settings or a content blocker. The site still works.
- Ask about your information. Depending on where you live, you may have the right to access, correct, delete, or object to how we handle your personal information. Email us and we'll help. Because there are no accounts, we may need details like an IP address to find anything.
Security#
Telescope is served over HTTPS, and the connection to our database is encrypted. Device tokens are random secrets generated on our server. No system is perfectly secure, though, so we can't promise that information will never be accessed without permission.
Children#
Telescope is a tool for people who build and run software. It isn't directed at children under 13, and we don't knowingly collect personal information from them. If you think a child has sent us personal information, email us and we'll delete it.
International users#
Telescope is run from the United States, and our service providers may process data in the United States and other countries. If you use Telescope from outside the United States, your information may be processed somewhere with different data protection laws than where you live.
Changes to this policy#
If we change this policy, we'll update it here and change the effective date at the top. If a change meaningfully affects how we handle your information, we'll make it more visible, for example with a notice on the site.
Contact#
Questions or requests about privacy go to telescope@littleplanetlabs.com.
See also our Terms of Service.