Privacy Policy

How IPRapid handles IP addresses, API and diagnostic requests, browser signals, access logs and expiring share links.

1. Scope and controller

This policy explains how the operator of IPRapid processes information when you use iprapid.com, its public API, command-line responses and network diagnostics. The Service operator is the controller for this processing. The current privacy contact appears below.

2. Information processed

  • Connection data: the source IP address is necessarily received to establish a connection and report the address visible to the Service.
  • Lookup and API input: a target IP, locale and response options that you submit.
  • Browser diagnostics: first-party IPv4/IPv6 probe results and timing, browser timezone and language, WebRTC/STUN addresses, DNS challenge identifiers and observed resolver exits. Tests run only when the relevant browser feature is used.
  • Diagnostic shares: five coarse status values—WebRTC, DNS, IPv6, timezone and language—plus issue and expiry times. Share tokens do not contain an IP address, coordinates or resolver address.
  • Request metadata: timestamp, host, method, requested URI and query, protocol, ordinary headers, response status and timing in protected web-server logs.
  • Security counters: a one-way source-IP hash with a short-lived counter for rate limiting.
  • Administration and communications: staff account security data and information deliberately supplied in a support or privacy request. There are no public visitor accounts.

3. Purposes and legal bases

We process connection, lookup and diagnostic data to provide the requested Service; request logs and short-lived counters to secure, troubleshoot and operate it; minimized daily aggregates to understand reliability and capacity; and communications to respond to you. Depending on applicable law, the bases are performance of the requested service, legitimate interests in secure operation, legal obligations, or consent for optional non-essential technology.

4. Storage and retention

Lookup and API results are generated for the response and are not stored in the application database as a visitor history. Signed diagnostic shares are self-contained, expire after 24 hours and are not stored as share records; creation and verification requests remain subject to ordinary access logs and rate limits. DNS challenge identifiers and observed resolver addresses are normally removed about one hour after challenge expiry. Rate-limit hashes expire after the configured short window.

Raw web access logs can contain source IP and requested URI; they are access-controlled, rotated and configured for approximately 30 days of retention. PostgreSQL usage reporting stores only day, normalized endpoint, country code and counts—not raw IP, full URI, query or headers. Support and security records are kept only as long as reasonably required for their purpose or by law.

5. Sources and recipients

Data comes from your connection, values you submit, browser APIs, first-party probe hosts, DNS observations and locally installed IP datasets. Infrastructure, hosting and email providers may process data as service providers under appropriate safeguards. A normal lookup does not send the queried IP to the geolocation dataset publisher. We may disclose information when required by law, to protect rights and systems, or in a protected business reorganization.

6. Optional analytics and advertising

The core website, API and diagnostic tools are designed to work without a public visitor session cookie. Content pages can support separately configured analytics or advertising providers. If enabled, those providers receive network metadata inherent in a browser connection and may use cookies or similar identifiers under their own terms. Where consent is required, non-essential technology is subject to the consent choice presented for the active configuration. See the Cookie Policy.

7. International transfers

Service providers may operate in other countries. Where transfer rules apply, we use a recognized legal mechanism and supplementary safeguards as required.

8. Your rights

Depending on where you live, you may request access, correction, deletion, restriction or portability, object to processing, or withdraw consent without affecting earlier lawful processing. Because the Service intentionally has no visitor account or application-level lookup history, we may be unable to associate minimized or expired information with you. You may also complain to a competent data-protection authority. We verify and answer requests as required by applicable law.

9. Security and automated decisions

We use encryption in transit, access controls, restricted administration, data minimization, limited retention and operational monitoring. No method is completely secure. Service output is not used by us to make solely automated decisions producing legal or similarly significant effects about visitors.

10. Changes

We may update this policy when features, providers, retention or legal requirements change. The last-updated date identifies the active version.