App Privacy Policy
Last updated: 2026-09-25
This policy covers the IP Locator mobile app. It says what the app keeps on your device, what leaves it, who else is involved, and what our server does with what reaches it.
1. Who we are and what this policy covers
IP Locator is run by an independent developer under the name LinnetLab, not by a company, based in Ireland. That developer is the data controller for the app and answers at the contact address below.
This policy covers the mobile app for Android and iOS. Both are built from the same code and behave the same way; where a platform genuinely differs, this policy says so by name. The IP Locator website is a separate product with its own privacy policy.
The app has no user accounts. There is nothing to sign up for, and it never asks for your name, your email address or any other contact detail.
2. What the app does
The app shows the public IP address your connection is seen with and what is known about it: country, city, network provider, and whether the address looks like a VPN. Separate proxy and Tor classifications also reach the app from our server, even though the screen does not display them today.
It only ever asks about your own address. There is no field for typing someone else's in, and the app has no way to look one up — unlike the website, which does.
Location data for an IP address is approximate. It describes the network an address belongs to, not the person using it, and it can be inaccurate or out of date.
3. What stays on your device
The app keeps the following on your device and sends none of it to us:
- lookups you chose to save — the full address, the country, city and provider that were found, and the time you saved it
- the note you attached to a saved lookup, if you wrote one — free text, and whatever you put there stays on the device
- your chosen appearance and language
- a count of how many manual refreshes you have used today, so the free daily limit can work
Nothing is saved on its own. A lookup is written only when you press save; refreshing the screen writes nothing.
You delete a saved lookup by swiping it away, with a moment to undo. There is no single button that erases everything: to remove all of it, clear the app's data in system settings or uninstall the app.
4. Backups, and where the two platforms differ
This is the one place where Android and iOS are not the same, so it is worth reading even if the rest was predictable.
On Android, the app's database is left out of Google's automatic backup, and so are your appearance and language settings — they sit in the same kind of storage. Your saved lookups and your notes do not go to Google Drive. What does go there is the small set of preferences written by the purchase SDK, which includes the anonymous purchase identifier described below.
On iOS, the app's database is part of the device backup. If you back your iPhone or iPad up to iCloud or to a computer, your saved lookups — full addresses and your notes — are in that backup. Your appearance and language settings are not. You can exclude the app from backups in system settings.
5. Purchases
The app offers one optional purchase that unlocks the paid features for good. There is no subscription and nothing recurring. Payment is handled by Google Play on Android and by Apple on iOS; we never see your card or your payment details, because they never reach the app.
To know whether you have bought it, the app uses RevenueCat. RevenueCat gives your installation a random identifier that is tied to nothing about you — not a name, not an email address, not an account — and we never send it anything that identifies you. It receives your purchase history from the store, along with what the store tells it about the device and country. On iOS it also records whether you have granted permission to track you across other apps; that is the answer only, never an advertising identifier, and the app never asks the question.
Purchases can be restored on a new device from the store you bought them in. That restores the entitlement, not your saved lookups: those live only on the device they were saved on.
6. What the app does not do
- It contains no analytics, no crash reporting and no tracking library of any kind, and it keeps no diagnostic log of its own.
- It shows no advertising. There is no advertising identifier and no advertising SDK in it.
- It has no accounts, no registration and no sign-in.
- It does not ask for permission to track you across other apps and websites, and collects no advertising identifier.
7. What the app asks the system for
The app asks for no permission at run time — no location, no camera, no contacts, no files, no notifications. Nothing ever interrupts you with a request, because it needs nothing that would require one.
Its installation package still declares the technical permissions that it and its libraries are built with: internet access, reading the network state so the local address can be shown, vibration, the purchase permission used by the store, and a few that come with the frameworks and are not used. Both stores publish that list on the app's page, so you can compare it with this paragraph rather than take our word for it.
8. What our server sees and keeps
When the app looks up your address, it asks our own server. That server necessarily sees the public IP address the request arrives from: seeing it is how it can tell you what your address is.
We record every lookup in our service journal, and the record does not contain your address in readable form. What we store is a keyed cryptographic digest of it together with a masked version. A copy of the journal on its own reveals no addresses, because the key is not kept with it; we will not claim more than that, since whoever holds the key could work back from a digest, and that is us. Journal records are deleted automatically 90 days after the lookup.
Our web server also keeps ordinary technical logs of the requests it handles, which can contain the IP address a request came from, the time and what was requested. They are used to run and protect the service, not to profile anyone, and are discarded when the service is next deployed.
We also keep a knowledge base of what an outside data provider told us about networks. It is no longer added to — lookups are answered from datasets held on our own server — and its entries are deleted as they expire. Nothing the app does ever wrote to it: it holds only addresses that someone typed in on the website, and the app cannot type one in.
9. Third-party services
The address the app looks up is not sent to any outside party. What is known about it comes from datasets MaxMind publishes, which we keep on our own server, so MaxMind never learns which addresses are looked up. This product includes GeoLite2 data created by MaxMind.
Three outside parties are involved:
- RevenueCat, as described under purchases, tells the app whether you have bought the paid features.
- Google Play or the App Store, depending on where you got the app, handle the purchase itself and the delivery of updates.
- our hosting provider, which operates the machines the API runs on.
10. Legal bases for processing
Where the GDPR applies, we rely on two bases:
- Performing a service you asked for, Article 6(1)(b). We process the address of a lookup you requested so that we can answer it, and purchase data so that you get what you paid for.
- Our legitimate interests, Article 6(1)(f). We keep the service journal and technical logs so the service stays available, request limits work and abuse can be investigated. The knowledge base about networks is no longer added to and is emptying as its entries expire. We have weighed this against your interests: the journal keeps no recoverable address, and the logs are not used to profile anyone.
11. How long things are kept
- Service journal: 90 days from the lookup, then deleted automatically.
- Technical logs: no longer than running and protecting the service requires, and discarded when the service is next deployed.
- Everything on your device: until you delete it, clear the app's data or uninstall the app. We cannot delete it for you, because we cannot see it.
- Backup copies of the database, kept only for restoring it, can hold journal and knowledge-base entries for longer than the periods above.
12. International transfers
RevenueCat is based in the United States, so the purchase data described above reaches it outside the European Economic Area. That transfer is governed by RevenueCat's own terms and safeguards, set out in the privacy policy linked in this document. The address you look up is transferred nowhere: it is matched against data held on our own server.
13. Your rights
If the GDPR applies to you, you have the right to:
- ask what personal data we hold about you
- have inaccurate data corrected
- have your data erased
- have our processing of it restricted
- receive your data in a portable form
- object to processing we base on legitimate interests
- complain to the data protection supervisory authority of the country you live in
In practice the app holds almost nothing about you that we can reach. What is on the device is yours alone: we have no copy of it and no way to see it, which is why you remove it yourself. Our journal we can search if you tell us the address — we compute the same digest and find the records for it — but we cannot go the other way and work out from a record who someone is.
For anything held by RevenueCat or by the store you bought the app from, their own policies and controls apply. To exercise any right against us, write to the address below.
14. Applicable law and supervision
Because the developer is established in Ireland, this service falls under Irish law and under the GDPR directly — not only when you happen to be reading from the European Union, but as a matter of where it is run from.
The supervisory authority for the developer is the Irish Data Protection Commission. You can complain to it, and you can equally complain to the data protection authority of the country you live in. Choosing one does not cost you the other.
15. Children
The app is not directed at children, and we do not knowingly collect personal data from children.
16. Security
Traffic between the app and our servers is encrypted in transit. Addresses in our journal are protected by a keyed digest, and the key is kept apart from the journal. No method of storage or transmission is ever completely secure, which is why the app keeps what it keeps on your device rather than on ours, and why the amount of recoverable personal data on our side is as small as we can make it.
17. Contact
For any question about this policy, or to exercise the rights set out above, write to us:
18. Changes to this policy
We may update this policy. When we do, the date at the top of this page changes with it, and a change that matters will be described here rather than made quietly.