Privacy Policy
How IPRapid handles IP addresses, diagnostic requests, access logs and privacy choices.
1. Scope and controller
This policy explains how the operator of IPRapid processes information when you use iprapid.com, its public endpoints and network diagnostic features. The Service operator acts as controller for this processing. The current privacy contact is shown below.
2. Information processed
- Connection data: your source IP address is necessarily received to establish a network connection and to show the address visible to the Service.
- Lookup and diagnostic input: an IP address you enter, selected language, test identifiers, and the DNS resolver or network addresses observed during an optional leak test.
- Request metadata: timestamp, host, method, requested URI and query, protocol, ordinary request headers such as user agent or referrer, response status and operational timing in protected web-server logs.
- Security counters: a one-way hash of the source IP with a short-lived counter is used for rate limiting.
- Support communications: the address, message and attachments you choose to send when contacting support.
- Administration data: authorized staff accounts use username, email, password hash and two-factor security material. There are no public visitor accounts.
3. Why we process it
We process connection and lookup data to deliver the Service you request; request logs and short-lived counters to secure, troubleshoot and operate it; minimized daily aggregates to understand reliability and capacity; and communications to answer you. Depending on applicable law, these activities rely on performing the requested service, legitimate interests in secure operation, legal obligations, or consent for any optional non-essential analytics or advertising technology.
4. Storage and retention
Per-request diagnostic results are generated for the response and are not written to the application database as a visitor history. Raw web access logs can contain source IP and requested URI; they are access-controlled, rotated, and configured for approximately 30 days of retention. Rate-limit hashes expire after the short configured limit window. DNS challenge identifiers and observed resolver addresses are normally removed about one hour after challenge expiry. PostgreSQL usage reporting stores only day, normalized endpoint, country code and counts—not raw IP, full URI, query or headers. Support and security records are kept only as long as reasonably needed for their purpose or a legal requirement.
5. Sources and recipients
Network data comes from your connection, the values you submit, DNS observations and local IP datasets. Infrastructure, hosting and email providers may process data as service providers under appropriate safeguards. The active geolocation lookup uses locally installed datasets, so the queried IP is not sent to the dataset publisher for each lookup. We may disclose information when required by law, to protect rights and systems, or in a business reorganization subject to appropriate protections.
6. Optional analytics and advertising
The core public Service is designed to work without a visitor session cookie. Content pages can support separately configured analytics or advertising providers. If activated, those providers receive at least the network metadata inherent in a browser connection and may use cookies or similar identifiers under their own terms. Where required, non-essential technology should be activated only after an appropriate consent choice. See the Cookie Policy for the current categories.
7. International transfers
Providers may operate in other countries. Where transfer rules apply, we use a recognized legal mechanism and supplementary safeguards as required. Contact us for information relevant to a particular transfer.
8. Your rights
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Because the Service intentionally does not keep a visitor account or lookup history, we may be unable to link minimized or expired information to you. You may also complain to your local data-protection authority. We will verify and answer requests as required by applicable law.
9. Security and automated decisions
We use access controls, encryption in transit, limited retention, data minimization and operational monitoring. No method is completely secure. Service output is not used by us to make a solely automated decision producing legal or similarly significant effects about visitors.
10. Changes
We may update this policy when the Service, providers or legal requirements change. The last-updated date identifies the active version.