Live Sky Privacy Policy
Updated October 10, 2026
Live Sky is an astronomy app for iPhone, iPad, Apple Watch, and Android, operated by Dapperfinch Inc. No Live Sky account is required. Available features vary by platform and app version.
Android age range and local privacy mode
Android’s current Google Play listing targets adults ages 18 and over. The app also applies local privacy restrictions for younger or unknown-age users. Before using the app, choose an age range on a neutral screen. Only that range is saved on your device; we do not request a date of birth or send the range to our services. Unknown-age users and users under 16 use local astronomy and local reminders. For these users, online maps and location-name lookup, weather, cloud summaries, messaging, advertising, analytics, model services, and purchases are disabled. Device location, camera, and notification permissions remain optional and support local features. This restriction cannot be turned off with Survivor Mode or analytics settings.
Your observing information
Locations, coordinates, elevation, time zones, favorites, telescope details, viewpoints, and viewing preferences are saved on your device. With permission, Live Sky uses your device location for astronomical calculations. Camera and motion access support finding objects and recording viewpoint outlines. Camera images are not sent to the summary service. On Apple devices, weather requests use the selected observing location and are processed through Apple Weather. On Android, weather requests send the selected observing coordinates and language directly to Google Maps Platform Weather API, which also receives network information such as your IP address. Weather powers calculated observing cards independently of optional cloud summaries. Android keeps current and hourly weather in memory for at most one hour and disables new weather requests in Survivor Mode. While online, Android's geocoding service may receive coordinates to resolve a location's city or administrative name. See Google's Privacy Policy and Google Maps terms.
Opening Android's online location map requests map tiles from OpenStreetMap, or uses Google Maps where configured. These providers receive network request information, including your IP address, and the viewed map area. This is separate from sharing observing details with the summary service.
Optional summaries
Before enabling summaries, Live Sky asks for your consent to share the selected observing location, including coordinates and its label, weather and sky conditions, viewing preferences, equipment, favorites, and saved viewpoints with a third-party summary service through the Live Sky backend. These details help generate observing advice. Avoid entering sensitive information in location names, equipment notes, or viewpoint names.
You can turn cloud summaries off at any time through Settings on Apple devices or Today's summary options on Android. This stops new summary requests; it does not undo information already processed. Today can still show calculated sky facts. Our generation requests disable provider response storage where supported. The service provider may retain information for security and abuse prevention under its own retention rules. Live Sky may temporarily cache generated summaries to avoid repeated requests.
To diagnose summary failures and improve summary quality, Dapperfinch retains observing context sent to the summary service, generated responses (including outputs rejected by validation), model and prompt information, and request diagnostics for up to 30 days. This can include the selected location and coordinates, favorites, weather, equipment, and viewing conditions. For summaries using Google weather, the backend does not store the observing context, generated text or model outputs; Android keeps that text only in memory until the source weather's one-hour expiry. The 12-hour generation limit still applies. Only request metadata and optional rating are retained for these summaries. These review records are restricted to the service operator and do not contain purchase receipts or authentication tokens. Expired records are removed automatically; transient backup copies may persist under the storage provider's backup retention rules.
If you choose to rate a summary with a thumbs-up or thumbs-down, your current rating and its submission time are stored with that summary and its observing context for the same 30-day review period. Changing your vote replaces your earlier rating. Feedback is optional and does not require sending your location or purchase receipt again.
Message us
On Apple devices, when you send a message, we receive the text plus app version/build, platform, OS version, onboarding completion, owned feature product names/status, favorites, saved-location and viewpoint counts, and telescope aperture/focal length. The selected observing location is rounded to a five-degree region. On all platforms, chat never automatically attaches exact coordinates, saved location/telescope/viewpoint names, purchase receipts or transaction identifiers, screenshots, files, or logs. Avoid including sensitive information in your message.
Android messages include app version/build, platform, OS version, onboarding completion, whether purchases have been checked, and owned product names. Android does not automatically attach observing location, favorites, saved-location or viewpoint counts, or telescope information to a message.
In Android's message options, you may add a reply email or choose to preview and explicitly share your observing setup with a message. Shared setup can include exact selected and saved observing coordinates, saved-location and telescope names, telescope models and specifications, favorites, and viewpoint counts. The preview shows the details before you choose to share them. Optional reply email, setup details, and message context expire after 30 days; message text remains in conversation history until cleared. No automated reply email is sent.
No account is required. Private credentials grant access to your conversation; a reference ID alone does not. On Apple devices, these credentials are stored in Keychain. With iCloud Keychain enabled, a credential can sync between your Apple devices so existing conversations can be joined without losing their history. iCloud availability and synchronization are controlled by Apple. Without it, the conversation remains local to that installation. Android stores conversation credentials and message drafts in private app storage excluded from backup; clearing app data or uninstalling loses access to that installation's conversation. Normal app updates retain access. History stays on the backend until you clear it in the conversation menu; this clears it across linked devices. Message context expires after 30 days. Transient backups follow the storage provider’s retention.
With iOS notification permission, we store a push token to send generic reply notifications and an unread badge. The notification payload does not include message text or observing details. Disable notifications in iOS Settings at any time. Unused device registrations expire after 180 days. Older app versions may still submit optional reply email and explicitly consented observing details; these expire after 30 days. No automated email is sent.
Android currently reads replies when you open the conversation; it does not register a push token for reply notifications.
App Check and temporary network rate limits help prevent abuse. Message text, email, reference IDs, credentials, and context are not sent to GA4. Feedback analytics record only opened, submitted, or failed with bounded topic/outcome; free-form chat uses “other.” Feedback is separate from App Store ratings and does not change review prompts.
Alerts
When remote notification features are enabled, the notification service receives an installation identifier, notification token, selected locations, favorites, viewpoints, alert rules, and notification preferences needed to deliver requested alerts. You can change alert preferences in the app and notification permission in device Settings. Service records are retained as needed to operate requested features, investigate failures, and prevent abuse.
On iOS, favorite tracking is an optional Live Activity feature. Enabling it shares the tracked objects, chosen saved location and coordinates, minimum altitude, viewpoint outlines, and ActivityKit push tokens with the Live Sky backend so activities can start and update while the app is closed. Camera images are not shared. You can turn tracking off in the object's details or disable Live Activities in iOS Settings. Ending an activity stops that visibility window and keeps future tracking enabled. Unused tracking registrations expire after 180 days.
Android observing and event reminders are scheduled locally on your device. Notification permission and, for precise scheduled delivery, Android's alarms and reminders access are optional. Android does not send these local reminder rules to the remote notification service.
Purchases and the free summary allowance
Apple processes Live Sky Plus subscriptions and restores of legacy Apple purchases; Google Play processes Android subscriptions. Dapperfinch does not receive payment-card details. To verify access, the backend verifies signed App Store purchase information or an Android purchase token with Google Play. It uses hashed account or installation identifiers, free-allowance records, and verified subscription status needed to enforce access and handle refunds. Android purchase verification also receives an installation identifier and returns a signed access proof saved privately on your device. These records do not require your name or email address. Existing Apple Remove Ads purchases continue to hide ads in the Apple app.
Advertising
The free app can display Google AdMob banner ads; Apple versions may also show full-screen ads. Google and its partners may process device identifiers, IP address, approximate location, ad interactions, and diagnostic data to provide, measure, and protect advertising. Consent choices are presented where required, and available privacy options can be reopened in Settings. Live Sky Plus and restored Apple Remove Ads purchases disable advertising on their respective platforms. See Google's Privacy Policy.
Analytics and reliability
Live Sky uses Firebase Analytics and Crashlytics to understand feature use and diagnose crashes. This may include installation identifiers, app and device information, purchase status, interactions, performance measurements, and crash diagnostics. App analytics use general feature and setup information, rather than the text of your location names, telescope notes, or summaries. On Android, app analytics and crash collection default off and require your separate in-app analytics choice; you can turn them off in Settings. App Check attestation helps verify requests to the backend independently of that analytics choice. Survivor Mode disables app analytics and network-dependent features. Firebase and Google service retention rules also apply.
Your choices and contact
You can edit or delete saved observing data, disable summaries, change notification and advertising preferences, and manage device permissions. Manage Apple subscription cancellation and purchase records through App Store account settings, or Android subscriptions through Google Play account settings. For questions or requests concerning information held by Dapperfinch, contact anurag@dapperfinch.com. We may need enough information to locate and verify the relevant service records.
We do not sell your observing profiles. Information may be shared with service providers to operate the features described here, to meet legal obligations, or to protect the service. The Apple app is not directed to children under 13. Android supports the age ranges and local privacy restrictions described above. We may update this policy as features and services change.
Website and MCP service
The following disclosures apply to the separate website and MCP astronomy service.
Accountless ChatGPT and MCP astronomy service
The accountless service calculates astronomy from coarse host-provided observer context or a city, region or observing landmark you explicitly supply for the request. Named destinations are supported. The service does not request direct coordinates or street addresses, create an account or save observing profiles, preferences, favorites or telescope profiles. Missing context prompts for a coarse place; ambiguity requires your clarification.
Explicit place queries are sent to Geoapify for approximate coordinates and an IANA time zone. Temporary encrypted references carry that context between tools and expire after 15 minutes; the backend stores no query, location result or reference in a profile, database or cache. Geoapify and OpenStreetMap attribution accompanies place results. Geoapify's privacy policy describes its separate processing and retention; this is not a promise of zero third-party retention. IP addresses, remembered profiles and unrelated conversation text are never used to infer an observing place. Other host identity/session hints are ignored. Optional equipment-name lookup uses a bundled catalog. Native saved information and notifications described above are separate.
Cloudflare processes requests and network metadata to deliver and protect the service. Application logs contain a random request identifier, operation, duration, success, engine version and a bounded integration label from the endpoint URL, not locations, equipment text or identities. These logs are retained in Cloudflare Workers Logs for up to seven days. A keyed value derived from the network address rotates each minute and supports one-minute abuse limits; our database stores aggregate compute and geocoder counters, not that value or personal location. Aggregate compute counters cover the current minute, geocoder counters cover the current UTC day, and the spacing gate records the latest search time; the fixed rows are replaced as new periods are used and may remain while the service is idle. Infrastructure providers have their own operational logging and retention practices.
Your chat host, including OpenAI when you use ChatGPT, may retain conversation and tool data under its policies. Host conversation context is not a saved Live Sky profile. Contact us about privacy questions or operational data; use your host's controls for its conversation history.
AI observing guides
The website automatically loads a cached guide or generates one when the displayed city’s sky loads. MCP guides are generated only when explicitly requested. When a new guide is generated, calculated night facts are sent to OpenAI: dates and time zone, solar timing and darkness intervals, Moon geometry, and planet windows and positions. Hourly forecast values, when available, are included in the AI input. Apple WeatherKit receives coordinates rounded to 0.1°, the requested night interval and time zone to provide forecasts. That coarse forecast request and the calculated night facts travel through a Cloudflare generation queue without city labels, temporary location references, observing profiles or visitor request headers; coordinates are not included in the OpenAI input. Apple Weather logo assets are loaded from Apple. OpenAI is used separately from your chat host. Response storage is disabled, but provider processing and retention policies still apply.
Guide text and its forecast context are cached using a hashed observing-context key for reuse for up to one hour, the forecast’s validity time or the end of the local observing-night interval, whichever comes first. Expired entries are periodically removed; expiry does not mean immediate physical deletion. This cache is separate from temporary location references and does not create a saved observing profile. The database also keeps a shared daily generation-attempt count.
MCP usage counts
Our MCP server sends aggregate call counts, fixed tool names, integration labels and outcomes to Google Analytics. It sends no tool arguments, calculation results, IP addresses, API keys or personal identifiers. A shared synthetic server identifier represents all calls; these counts do not identify users. Clients can opt out with DNT: 1 or Sec-GPC: 1 request headers. Website and MCP analytics details.