About
Privacy policy
The short version: octoscope has no account, no telemetry and no analytics. The CLI talks to GitHub, with your own token, and to GitHub's status page. This website sets no cookies of its own.
Last updated: 5 October 2026
Who is responsible
The data controller is Giovambattista Fazioli (Undolog), an independent software developer in Italy, VAT number IT12343751009. Write to hello@undolog.com about anything on this page. See also the Legal notice.
The octoscope CLI
It talks to two hosts, both GitHub's, and to nothing else:
- GitHub's API (
api.github.com). Everything on the dashboard is read from it, with the token octoscope finds in$GITHUB_TOKENor gets fromgh auth token, or with no token at all for a public profile. At launch, then every 60 seconds by default (refresh_interval), and whenever you open something that needs more. It only reads: octoscope never writes to GitHub. What GitHub does with those requests is covered by GitHub's own privacy statement. - The update check. At launch and then hourly, octoscope asks the same API for its own latest release, with the same token when there is one.
check_for_updates = falseturns it off, and--public-onlyskips it. octoscope never updates itself. - GitHub's status page (
www.githubstatus.com). One request without a token at launch, on r and after a failed fetch, and on your refresh cadence while a warning is on screen.check_service_status = falseturns it off, and--public-onlyskips it.
No telemetry, no analytics and no crash reports. A link you open from octoscope — a GitHub page, GitHub Sponsors, a donation through Stripe — opens in your browser, and octoscope sends nothing to it.
What it keeps on your machine
- Your token stays in memory. octoscope never writes it to disk.
- The config file,
~/.config/octoscope/config.toml(or under$XDG_CONFIG_HOME): your settings, and the repositories and issues you pin or watch. It is written only when you change one of them. - The security scan history,
scan-baselines.jsonbeside it: for each repository you scan, when, the verdict, the file paths and hashes it compared and the dependency versions it read. It is kept until you delete it. - The update cache, in your user cache folder: when it last checked and the latest version it saw.
Installing octoscope with Homebrew, go install, the gh extension or the Docker image downloads it from GitHub through those tools, whose own privacy policies apply.
This website
- No cookies of its own, no analytics, no cross-site tracking.
- Hosting. The site is served by GitHub Pages. Like any host, GitHub processes your IP address and the details of each request to deliver the pages and keep them secure. We have no access to those logs; GitHub keeps them under its own privacy statement.
- Release information. The home page and these docs ask GitHub's API for octoscope's latest version, to show its number, and the release notes page reads the notes from there too, so GitHub sees your IP address.
- Pictures from other services. The Product Hunt badge on the home page is loaded from Product Hunt, which sets a security cookie on its own domain for 30 minutes, and the sponsor's picture is loaded from GitHub. Both see your IP address. The fonts are served by the site itself.
- Your browser's local storage remembers, in your browser only, the theme you chose in these docs and that you closed the newsletter prompt on the home page. None of it is sent to us.
- Email. If you write to us, we use your address and message only to answer you, and keep them no longer than the conversation needs.
- Links. The newsletter on Substack, GitHub Sponsors, donations through Stripe and the share buttons lead to services of their own, and nothing is loaded from them until you click. If you use them, their own privacy policies apply.
Why, and your rights
We process the little personal data described here to run and protect the site and to answer you when you write: our legitimate interest, or the service you asked for. GitHub and Product Hunt may process it outside the European Union, including in the United States: they rely on the EU–US Data Privacy Framework or on the European Commission's standard contractual clauses, and we will tell you which on request.
Under the GDPR you can ask to access, correct or delete your personal data, to restrict or object to its processing, and to receive it in a portable format: write to hello@undolog.com. You can also lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali.
Changes
When this page changes, the date at the top changes with it.