TTailScope

How TailScope handles information

Effective date: September 8, 2026. This Privacy Policy explains how TailScope handles information when you use the app or contact the publisher.

Scope and publisher

TailScope is an independently developed, unofficial administration client for the Tailscale Admin API. It is not affiliated with, sponsored by, or endorsed by Tailscale Inc. TailScope is not a VPN client and does not establish or carry network traffic through a Tailscale tunnel. In this policy, “TailScope,” “we,” “us,” and “our” refer to the developer and publisher, Shanghai Fengcong Technology Co., Ltd.

Information stored on your device

TailScope does not require or create a TailScope cloud account. On iOS and iPadOS, secret credentials are stored in the device-only Keychain. On Android, API access tokens and OAuth client secrets are encrypted using an Android Keystore key and stored in app-private files excluded from backup. Account names, Tailnet identifiers, selected account, language, appearance, app-lock preferences, and other interface settings may be stored in the local app container. Live Tailnet responses are processed in memory for the requested operation; the current version does not maintain a persistent offline cache of Tailnet business data.

Information sent to Tailscale

When you connect a live Tailnet, requests are sent directly from your device to Tailscale’s official API over encrypted system networking. Depending on the features you use and the permissions of your credentials, requests and responses may include Tailnet settings, device and user information, DNS settings, HuJSON Policy, credential metadata, Services, webhooks, and audit or network-flow log metadata. Tailscale processes that information under its own agreements and privacy policy.

Information not collected by the publisher

The current version does not automatically send Tailscale credentials, Tailnet configuration, API responses, usage events, advertising identifiers, location data, or developer-operated diagnostic logs to the publisher. TailScope contains no advertising SDK, third-party analytics SDK, cross-app tracking, behavioral profiling, or developer-operated telemetry service. The local demo uses fictional data generated on the device and does not contact Tailscale.

Optional Android diagnostics

Android diagnostics are disabled by default. When enabled, the app keeps up to 200 request records per account locally, containing endpoint templates, status, timing, error category, request ID and app version. It excludes credentials and request or response bodies. Records older than seven days are filtered out when read and removed when the file is next rewritten; you can clear them manually. Diagnostics are excluded from backup and are not uploaded automatically. If you export or share them, only the recipients you choose receive that information.

Support communications

If you contact the publisher, we receive the information you choose to provide, such as your email address, message, and attachments. We use it only to respond, investigate the issue, protect the app and its users, and meet legal obligations. Support communications are retained only as long as reasonably necessary to resolve the request, maintain appropriate support records, prevent abuse, or comply with law. Do not send API tokens, client secrets, auth keys, unredacted Tailnet logs, or confidential screenshots.

Purchases and store services

TailScope Pro Lifetime is a one-time in-app purchase. Apple handles purchases on iOS and iPadOS; Google Play handles purchases on Android. The relevant store processes payments, purchase history, refunds, installation and store service data under its own terms and privacy policy. TailScope queries the store for the current purchase entitlement and acknowledges completed purchases. Purchases are not transferred between Apple and Google accounts. TailScope does not receive or store payment-card details and the current version does not send purchase records to a developer-operated server.

Security, app lock, and clipboard

TailScope protects credentials using the device Keychain on iOS and iPadOS or Keystore-backed encryption on Android. App lock uses the platform’s supported biometrics or device credentials. Authentication is performed by the operating system; TailScope does not receive biometric templates. The app accesses the clipboard only when you explicitly copy a value. Treat copied credentials, invitation links, identifiers, and network details as sensitive information.

Retention and deletion

Removing a saved account from TailScope deletes its corresponding local account metadata, stored credentials and, on Android, the account’s local diagnostics. Removing a local account does not delete your Tailscale account or server-side Tailnet data. To change or delete information controlled by Tailscale or your organization, use the applicable Tailscale controls or contact the relevant administrator. TailScope does not create a developer-hosted user account.

Your choices

You may use the local demo without providing credentials, choose which credentials and scopes to use, remove locally saved accounts, enable or disable the app lock, revoke credentials through Tailscale, avoid copying sensitive values, and contact the publisher about a support communication you previously sent. Your organization may control some Tailnet information and may apply its own retention, monitoring, and access policies.

Changes to this policy

This Privacy Policy may be updated when TailScope’s features, data handling, or legal obligations change. The effective or last-updated date will be revised when appropriate, and material changes will be reflected in the app’s privacy disclosures as required.

Privacy contact

For privacy questions or requests concerning TailScope, contact Shanghai Fengcong Technology Co., Ltd. at . Please do not include credentials or unredacted Tailnet data in your message.