Privacy Policy
Last updated: September 28, 2026
1. Overview
IPAddress.to ("the Service") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data.
2. Information We Collect
Automatically Collected
- IP Address: Your IP address is collected when you use the Service, as it is essential to the core functionality (showing you your own IP information). It is also used for rate limiting and abuse prevention.
- Request Data: Standard server logs may record request timestamps, URLs accessed, HTTP headers (including User-Agent and Referer), and response codes.
Provided by You (optional)
- Account: If you create an account for API keys, we store your email address, a salted password hash, the IP address used at signup and at each login, and the API keys you generate together with their usage counters. Accounts are optional; every tool and API works without one.
- Contact form: If you contact us, we store the name, email address and message you submit, plus your IP address and browser user agent, for as long as needed to reply and to filter spam.
- Lookups you run: The IP addresses, domains and email addresses you look up are recorded in our request logs (with your IP address) for rate limiting, abuse detection and aggregate usage statistics.
Not Collected
- We do not collect names, phone numbers or payment details, and we do not require an account to use the Service.
- We do not use tracking cookies for advertising purposes and we do not sell or share personal data with advertisers.
3. How We Use Your Information
- Service Delivery: To provide IP lookup, geolocation, DNS, WHOIS, and other network tool results
- Rate Limiting: To enforce fair usage and prevent abuse of the API and web interface
- Security: To detect and prevent malicious activity, DDoS attacks, and unauthorized access
- Analytics: To understand aggregate usage patterns and improve the Service
4. Cookies and Local Storage
The Service uses minimal client-side storage:
- Search History: Recent lookups are stored in your browser's localStorage for convenience. This data never leaves your browser.
- Account session (
ipa_sess,ipa_li): Set only when you log in. The session cookie keeps you logged in for up to 7 days of inactivity; the hint cookie only tells the page header whether to show "Account" or "Log in". - Form protection (
contact_form_t,account_form_t): Short-lived anti-forgery tokens set while you use the contact or account forms.
We do not use third-party tracking cookies or advertising pixels.
5. Third-Party Services
The Service relies on third-party data sources to provide results:
- IP geolocation databases for location data
- Public DNS resolvers (Google, Cloudflare, Quad9, etc.) for DNS propagation checks
- WHOIS registries for domain and IP registration data
When you perform a lookup, your query (IP address, domain name, or hostname) may be sent to these third-party services. Their respective privacy policies apply to that data.
6. Data Retention
Request logs (lookups with your IP address) are retained for a limited period for operational and security purposes and are then aggregated or deleted. Failed-request and API-key usage logs are kept for 30 days. Contact-form submissions are kept until handled and then archived or deleted. Account data is kept for as long as your account exists; you can delete your account and its API keys by contacting us, after which the record is removed within 30 days.
7. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may disclose information only if required by law or to protect the rights, safety, or property of the Service and its users.
8. Security
We implement reasonable technical and organizational measures to protect the data we process. However, no method of transmission over the Internet is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Request access to data we hold about you
- Request deletion of your data
- Object to processing of your data
- Lodge a complaint with a data protection authority
10. Children's Privacy
The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the Service constitutes acceptance of the revised policy.
12. Contact
If you have questions about this Privacy Policy, please contact us at privacy@ipaddress.to.