Privacy Policy
Last updated: July 23, 2026
IP Lookup ("the Service") respects and protects the privacy of every user. This policy explains how data is collected, used, and safeguarded when you use the website and API. The Service follows a data-minimization principle: we collect only what is necessary to serve an instant lookup, build no user profiles, and perform no behavioral tracking.
Information We Collect
- IP address: Your public IP address is used only during the request to display the lookup result instantly. It is never written to a persistent database and is discarded once the request completes.
- GeoIP location (optional, off by default): When GeoIP is enabled server-side, your IP is resolved to city, country, and ISP in memory and returned with the JSON API. The result is not logged, stored, or shared.
- No personally identifiable information (PII): We do not collect names, emails, device identifiers, or any PII. No registration or login is required to use any feature.
Logs & Data Retention
- IP masking: Every IP address in operational logs is masked (IPv4 keeps the first three octets, IPv6 keeps the first four groups). Full IPs never appear in logs.
- Retention: Logs are used solely for security monitoring and troubleshooting, auto-rotate, and are retained for at most 30 days.
- No query content: Logs do not record your query behavior or the specific results returned.
Cookies & Tracking
The Service uses no cookies, no localStorage (except the ad-dismissal preference), no web beacons, no fingerprinting, and no client-side tracking. We use Cloudflare Web Analytics, a privacy-first, cookieless analytics solution that collects no PII. We do not use Google Analytics or any cookie-based analytics, so no cookie-consent banner is required.
Advertising
A single text ad may appear at the top of the page. It is shown statically, is not behaviorally targeted, and does not track your browsing. After you dismiss it, the preference is kept only for the current session (sessionStorage) and is cleared when the browser closes.
Third-Party Services
- Cloudflare: Serves as CDN and DNS provider and processes requests at its edge. Cloudflare's own privacy policy governs its edge processing; we do not control what Cloudflare collects at the edge.
- MaxMind GeoIP: When GeoIP is enabled, a local MaxMind database maps IPs to locations. The lookup happens locally on the server; your IP is never sent to MaxMind.
Data Sharing & Sale
We do not sell, trade, or share your data with any third party. API responses are returned directly to your browser, never cached, forwarded, or recorded.
Your Rights (GDPR / PIPL)
Whether you are in the European Economic Area (EEA) or mainland China, under GDPR or the Personal Information Protection Law (PIPL) you have the following rights:
- Access: access your data (we hold none).
- Erasure: request deletion of your data (nothing to delete).
- Objection: object to processing (no ongoing processing occurs).
- Withdrawal: no consent to withdraw, since we never ask for it.
Because we collect no information that identifies you, these rights have no actionable target; should you still have concerns, contact us via the email below.
Security Measures
- All connections are forced over HTTPS.
- The service runs as a dedicated least-privilege user on a read-only filesystem.
- Content-Security-Policy restricts external resources; by default no third-party origin is contacted.
- A real-IP trust chain and rate limiting prevent spoofing and abuse.
Children's Privacy
The Service is a general-purpose network utility, not directed at children under 13, and we do not knowingly collect information from children.
Policy Changes
This policy may be updated periodically. Updates will be reflected on this page with a revised "Last updated" date. Material changes will be announced via a page notice.
Contact
For any privacy-related questions or data requests, email contact@iohow.com.