PRIVACY POLICY

What is processed, where, and why.

This policy separates the IP address you choose to look up from the public IP your browser necessarily uses to connect to websites.

Last updated: August 16, 2026

Important: IP addresses that you enter into the lookup tools are not saved by IP-Lookup.com in a lookup-history database. They are sent to the third-party service required to return the requested network information. Some tools call a provider directly from your browser; advanced or server-only functions pass the query transiently through IP-Lookup.com's PHP endpoint without intentionally persisting the submitted lookup value.

1. Core IP geolocation

The core IP location and bulk lookup features use FreeIPAPI. The browser normally requests the selected IP information directly from that provider. If a direct browser request fails, the website can use a same-domain fallback endpoint that forwards the IP to the same provider. The fallback request body is not intentionally written to an IP-search database by IP-Lookup.com.

2. Advanced VPN, proxy, Tor and reputation intelligence

When the site operator enables the advanced intelligence feature, the website uses FindIP for additional geolocation, network, VPN, proxy, Tor, hosting, malicious-IP and risk signals. Because FindIP requires its API credential to remain private, your browser submits the IP to IP-Lookup.com's same-domain PHP endpoint, which forwards it to FindIP and returns only the fields needed for the user-facing report. IP-Lookup.com does not intentionally store the submitted IP as lookup history.

3. RDAP / WHOIS and reverse DNS

RDAP and reverse-DNS operations require server-side processing. The requested IP or ASN is submitted in a POST request body. RDAP queries are sent to the RDAP bootstrap service used by the site. Reverse-DNS lookups are performed through the web server's configured DNS resolver. These query values are not intentionally added to a lookup-history database.

4. Your connecting public IP

Like every website, IP-Lookup.com must receive an internet address in order to deliver a response to your browser. Hosting, firewall, CDN or server access logs may record technical connection metadata such as the visitor's public IP, timestamp, requested path, response status and user-agent. Those infrastructure logs are separate from the IP address you manually enter into a lookup form.

5. Browser-only localStorage

The “What Is My IP?” change comparison and VPN before/after baseline can save an IP value and timestamp in your browser's localStorage. That browser-only history is not uploaded to an IP-Lookup.com history database by those features. You can clear it from the relevant tool.

6. WebRTC diagnostic

The WebRTC test asks your browser to gather ICE candidates and currently uses Google's public STUN hostname. Running the test may cause your browser to communicate with Google's infrastructure. Browser privacy features can redact or suppress candidate information.

7. IPv6-path diagnostic

The IPv6-path test uses ipify's public IP service to determine which public address is visible through an IPv4/IPv6-capable endpoint. That request is made from the visitor's browser to the third-party service.

8. DNS leak diagnostic

A genuine DNS leak test requires resolver-observation infrastructure that an ordinary page cannot implement with JavaScript alone. The DNS Leak Test page therefore links to the external diagnostic configured in the website settings, currently bash.ws. That test operates under the third party's own privacy practices and terms, and IP-Lookup.com does not receive its resolver result.

9. Contact messages

If you use the Contact form, the name, email address, subject and message you submit are processed so the website operator can receive and respond to the message. The supplied website sends contact mail through the hosting server's PHP mail configuration and does not intentionally create a contact-message database.

10. Public developer API and rate limiting

The public JSON API and same-domain lookup endpoints use coarse anti-abuse request limits. The supplied implementation derives a one-way SHA-256 hash from the connecting IP address and the site identifier, then stores a bucket name, date and request count in a protected runtime directory. The plaintext IP is not written to that rate-limit file. Normal hosting/CDN logs remain separate and may still contain connection metadata.

11. Hostname, FCrDNS and port tools

Hostname/domain resolution and forward-confirmed reverse DNS are processed transiently by the web server's DNS resolver. The Port Checker attempts one TCP connection to the public target and port submitted by the user; private and reserved destination IPs are blocked. These utilities do not intentionally create a history database of submitted targets.

12. Consent management, Google Analytics 4 and Google AdSense

IP-Lookup.com can use Google's certified Privacy & messaging Consent Management Platform (CMP) to present consent choices where required. For visitors in the EEA, United Kingdom and Switzerland, the website is configured so Google Consent Mode defaults advertising storage, advertising user data, ad personalization and analytics storage to denied until the Google CMP provides the user's choice. The website operator must publish the applicable consent message in the AdSense account for this mechanism to operate.

Google Analytics 4

When enabled by the site operator, Google Analytics 4 (GA4) is used to understand aggregate website usage, such as page visits, navigation and technical performance. Google tags adjust their behavior according to the consent signals supplied through Consent Mode. Where analytics storage is denied, Google may operate in a restricted/cookieless measurement mode rather than setting normal analytics cookies.

Google AdSense

When enabled, Google AdSense is used to display advertising. Google and participating advertising technology providers may process information for ad delivery, measurement, fraud prevention and, where the user has consented, personalization. The European regulations consent message identifies the vendors and purposes made available through the Google CMP.

Your choices

Where the Google consent message applies, you can consent, decline, or manage individual options. You can later reopen the consent controls through the Privacy and cookie settings link in the footer of regular site pages. See the Cookie Policy for a plain-language explanation of the main storage categories.

13. Third-party processing

Third-party services used to provide lookups or diagnostics process requests under their own privacy policies and terms. Those providers can receive the queried IP address and technical request metadata necessary to operate their service.

14. Retention

IP-Lookup.com does not intentionally maintain a database of manual IP-search history. Normal hosting/security logs may have retention periods set by the hosting provider or site operator. Contact correspondence may be retained as reasonably necessary to respond to a request and maintain appropriate records.

15. Your rights and contact

Applicable privacy law may provide rights concerning personal data controlled by the website operator. Use the Contact page for privacy requests.

Operator action required before public launch: add the legal identity, postal address and any other controller/operator information required for your business and jurisdiction. This template is technical drafting, not legal advice.