Privacy
Last updated 31 August 2026
This site records the requests made to it, including the IP address the request came from. It runs no third-party analytics and shows no advertising, and it sets a cookie only if you create an account or open a form. This page says exactly what is kept, why, and for how long.
Who is responsible
This site is run by a private individual in the Netherlands. For anything on this page, including any request about your own data, write to [email protected].
Under the GDPR that person is the controller for the data described here. There is no data protection officer, because the scale of this processing does not require one.
What is recorded when you visit
Every request to this site writes one row to a log. That row contains:
- the date and time, the path requested, the HTTP method, the response status and how long the response took
- your IP address
- the
Referer,User-AgentandAccept-Languageheaders your browser sent - the
Sec-Fetch-*headers, which say whether a request was a page you opened or a background request made by the page - your platform (for example "Windows"), where your browser reports it
- the HTTP version, and the
DNTandSec-GPCheaders if you send them - an internal reference to the API key used, if the request used one
- an internal reference to your account, if you were signed in or used a key
Requests for the health check and for static files such as stylesheets and fonts are not logged.
Why
Two purposes. The first is keeping the site working and dealing with abuse: finding what broke, seeing which requests are automated, and investigating attempts to overload or misuse the service. The second is understanding how the site is used, which pages people reach and where they arrive from, so the site can be improved.
The lawful basis is legitimate interests, Article 6(1)(f) GDPR. The interest is running a service that stays available and correct and knowing whether it is useful. Against that: no profiles are built, nothing is combined with data from anywhere else, nothing is sold or shared for marketing, and no attempt is made to identify anyone.
You can object to this processing at any time on grounds relating to your situation. Write to [email protected].
Other things that hold your address briefly
| What | Why | Kept for |
|---|---|---|
| Request log | Security, abuse handling and site analytics | 400 days |
| Rate limit counter | Enforcing the request limits, keyed to your address | About 25 hours |
| Lookup cache | Avoiding recomputing the same answer. Keyed to the address looked up, which is your own address when you use the "what is my IP" feature. | 1 hour |
| Registry lookup cache | Results of optional live registry queries | 7 days |
| Sign-in record | The address and browser a session was created from, so you can see on your account page which browsers are signed in | Until the session expires, then a day |
Each of these is deleted automatically. Nothing here depends on anyone remembering to run a clean-up.
Cookies
Two cookies, both strictly necessary, so there is no consent banner to click. Neither is used for analytics or advertising and neither follows you anywhere else.
| Name | What it does | Kept for |
|---|---|---|
lm_session | Keeps you signed in. Set when you sign in, deleted when you sign out. | 30 days |
lm_form | A random value used to check that a form you submit came from this site. Set when you open the sign-in, sign-up or password pages. | 1 hour |
If you never create an account, neither is set by simply reading the site.
Your browser also stores two values locally, which is not the same thing as a cookie: whether you chose the light or dark theme, and the last few addresses you looked up. Neither is sent to the server and neither is used to recognise you. You can clear both through your browser at any time.
Who else handles your data
The site runs on hardware operated by the site owner in the Netherlands. Traffic reaches it through Cloudflare, which provides the connection and protects against attack. Cloudflare therefore processes your request, including your IP address, on the way through, and acts as a processor under a data processing agreement. Cloudflare is a United States company with EU infrastructure, so some processing may take place outside the EEA under the safeguards in Chapter V GDPR.
If you create an account, the confirmation and password emails are sent through Resend, which processes your email address in order to deliver them. Resend acts as a processor under a data processing agreement.
If you buy a plan, the payment is taken by our payment provider, who is the seller on that purchase and therefore a controller of the payment data in their own right, not our processor. Their privacy notice governs what they do with it. See what we hold about a payment below.
Nobody else receives this data. It is not sold, rented or shared for advertising.
If you create an account
An account exists to raise your request limit and to let you issue and revoke API keys yourself. Creating one stores your email address, a hash of your password, when you confirmed the address, which plan you are on, and the keys you have made. Only a hash of each key is stored, so a key cannot be read back to you or to anyone else.
The lawful basis here is different from the one above: providing the account is performance of a contract, Article 6(1)(b) GDPR. You gave the address in order to be given the service, and it is used for nothing else. There is no newsletter and no marketing mail unless you ask for it: the signup form has a separate, unticked box for occasional email about what changes here, and you can turn it on or off at any time on your account page. That box is consent under Article 6(1)(a) and it is kept apart from accepting the terms, because consent bundled into something else is not consent. Nothing is sent to that list yet.
Six other messages exist and that is all of them: the link that confirms your address, a password reset when you ask for one, a link confirming a new address when you change it, a notice to the old address that a change was asked for, a notice when your password changes, and a confirmation when the account is closed. The last three are sent whether or not you asked, because being told is the point of them.
Nothing is sent when you sign in. Your account page lists the browsers currently signed in, with the address and the time each started, and you can sign the others out from there.
Your email address is kept while the account exists. You can close the account yourself from your account page, and you can download everything held about it from there first.
A record is kept of changes made to the account: when it was created and confirmed, each sign-in and sign-out, when the password or the address changed, when a reset link was sent, when keys were made or revoked, and anything an operator did to it. Each entry holds the time, what changed, whether you or an operator did it, and the address it came from. It is in your download, and it is what lets a question about your account be answered. It never contains a password or a key.
Closing it deletes the password, the keys and the sign-in records outright, and strips the account itself: the address is replaced with one nothing can deliver to, and every entry in the history loses the address it was made from and any address in its detail. What is left is an account number, when it was created, which plan it was on, and which version of the terms was accepted. None of that identifies you, and it is kept so that a question about the account can still be answered after it is gone. Entries in the traffic log that were linked to the account are kept and stripped: the link to you goes, and so does the address, which leaves a record that a request happened with nothing in it saying who made it. Entries that were never linked to an account are held by address alone and are not reachable from your account page, because nothing connects them to it. Write to [email protected] with the address and roughly the dates to have those removed too.
One exception, and it is a legal obligation rather than a choice: where the account ever paid for a plan, the billing record survives closing it, for as long as Dutch tax law requires. Everything in the paragraph above still happens.
You can also ask for any of this by writing to [email protected], which is usually answered the same day.
If you buy a plan
We never see your card. The payment is taken on our payment provider's own page, by them rather than by us, and they act as the seller. Card numbers, bank details and whatever billing address or tax identifier they ask you for are handled by them under their own privacy notice and never reach this application. There is nothing here to leak, because there is nothing here.
What we hold is the smallest set that lets an account be an account: which plan it is on, when that changed, whether the subscription is live, cancelled or unpaid, and the reference their system uses for it. That reference is what lets a question about your payment be traced to the right record in theirs.
The lawful basis is performance of a contract, Article 6(1)(b) GDPR, and for the records a tax authority requires, a legal obligation under Article 6(1)(c).
Billing records outlive the account. Dutch tax law requires business records to be kept for seven years, so where a payment has been made, the record of it survives closing the account and survives a deletion request. That is the one exception to the deletion described above, it is required rather than chosen, and it is limited to what the obligation covers: what was sold, when, for how much, and to which account. It does not keep your password, your keys, or your traffic.
Your rights
You can ask for a copy of the data held about you, ask for it to be corrected or deleted, ask for its use to be restricted, object to it being processed, and ask to receive it in a portable form. Write to [email protected].
One practical limit worth stating honestly: the request log is indexed by time, not by person. To find your entries, the address you used has to be known, and after 400 days nothing remains to find. If you want your entries removed, tell us the address and the approximate dates.
If you are unhappy with how this is handled you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
The addresses in the lookup database
Separately from the logs, this site publishes information about IP addresses and networks generally: which network an address belongs to, the organisation a block is registered to, the country it appears to be in, and whether public lists describe it as VPN, proxy or datacenter space. An IP address can be personal data, so this deserves saying plainly.
That information comes from public and licensed sources: the regional internet registries, published network operator data, commercial and open geolocation datasets, and published lists of VPN, proxy and datacenter address ranges. It describes address blocks and the organisations they are registered to.
The registries remove personal records from the data they publish, and we add nothing of our own. One case deserves spelling out. Where a block is registered to a sole trader, the registered holder is often that person's own name, and it appears here as the registry publishes it. That is the published registration for a block of addresses, not a profile of anyone, and nothing is combined with it. If a page names you and you would rather it did not, write to [email protected] and it will be removed.
No attempt is made to link an address to a person. Geolocation is an estimate for a block of addresses, and never a fix on a device or a household.
The site does not contact the holders of every address it describes, because there are billions of them and no way to reach them. GDPR allows this where notice would require disproportionate effort, and this page is the public notice that takes its place. If you hold an address or a network and want its entry corrected or removed, write to [email protected] and say which block you control.
Scores and automated processing
Lookup results include two computed indicators, one for reported abuse and one for origin concealment. They summarise what public sources say about an address block. They are not decisions about a person, they produce no legal or similarly significant effect, and nothing on this site decides anything about anyone. Whoever reads a result decides what to do with it.
Age
This is a technical reference tool for people who run networks and write software. It is not directed at children and it is not offered to them. Reading it asks for nothing at all.
Creating an account asks you to confirm that you are 16 or older and that you accept the terms. Sixteen is the age the Netherlands sets for a person to agree to a service like this on their own account. Entering a contract is a separate question with a higher age in most countries, which is why the confirmation covers both: the age, and accepting terms written for somebody able to agree to them. We record that you confirmed it, when, and which wording you were shown.
If you believe an account belongs to somebody under that age, write to [email protected] and it will be closed.
When the terms change
The terms of use carry a version. Yours is recorded when you accept them, and if they change in a way that affects what you agreed to, your account page asks you to accept the new version once. A correction to the wording does not ask you anything, because a prompt that appears for every edit is one people click past without reading.
Changes
If what is collected or how long it is kept changes, this page changes with it and the date at the top moves. A change that affects account holders is emailed to them; for everything else, this page is the current position.