Privacy Policy
Last updated: 2026-09-20
This policy describes what IP Locator does with data: what our server sees, what it keeps, what stays in your browser, and what we do not do at all.
1. Who we are and what this policy covers
IP Locator is run by an independent developer under the name LinnetLab, not by a company. That developer is the data controller for this website and answers at the contact address below; this policy explains what happens to data when you use the site.
It covers this website only. The IP Locator mobile apps are separate products and carry their own privacy policies.
We run no user accounts. There is nothing to sign up for, and we never ask for your name, your email address or any other contact detail.
2. What the service does
IP Locator shows you the public IP address your connection is seen with, and what is known about it: country, region, city, network provider, and whether the address looks like a VPN. Proxy and Tor classifications are also determined for the address and reach your browser, even though this page does not display them today.
You can also type in a different address and look that one up instead of your own.
Location data for an IP address is approximate. It describes the network an address belongs to, not the person using it, and it can be inaccurate or out of date.
3. We run our own server
When you look up an address, your browser sends the request to our own server. That server necessarily sees the public IP address the request arrives from: seeing it is how it can tell you what your address is.
We say this plainly because it is the one thing you cannot check from the outside. The lookup does not travel from your browser straight to some third party. It comes to us first.
4. What we record about a lookup
We record every lookup, successful or not, in our service journal. The record does not contain your address in readable form.
What we store instead is a keyed cryptographic digest of the address together with a masked version for display. A copy of the journal on its own reveals no addresses: the digest cannot be reversed without the key, and the key is not kept with the journal. We will not claim more than that. A keyed digest is pseudonymous, not anonymous — whoever holds the key can work back from it, and that is us.
A record holds the time of the lookup, the masked address, what was found, and whether the lookup succeeded. It holds no name, no email address and no account, because we hold none of those anywhere.
Journal records are deleted automatically 90 days after the lookup.
5. Technical logs
Like any service on the web, our web server keeps technical logs of the requests it handles. A log line can contain the IP address a request came from, the time, the path requested, the page that referred you and your browser's user-agent string.
We use these logs only to run the service: to keep it available, to enforce request limits and to investigate abuse. We do not profile you with them, and we do not combine them with anything else.
The application's own event log is deliberately kept free of addresses. It records the shape of the request path rather than the address that was looked up.
Technical logs are kept no longer than those purposes require, and are discarded when the service is next deployed.
6. What stays in your browser
Some things are stored by your browser, on your own device. They are never sent to us:
- your recent lookups, up to fifty of them, each with the full address and what was found out about it
- the theme you chose, light or dark
- the language you chose
- how densely you asked for the list of lookups to be shown
We deliberately do not offer you a history kept on the server. The journal described above belongs to the caller that made the request, and as far as our API is concerned every visitor to this website is one and the same caller, so showing you that history would mean showing you other people's lookups.
You can delete everything above at any time by clearing this site's data in your browser settings. Nothing about the service stops working if you do.
7. What we do not do
- We set no cookies.
- We use no analytics, no tracking pixels and no third-party script that follows you around the web.
- We show no advertising. There is no advertising identifier and no advertising SDK anywhere in this website.
- We sell nothing here and process no payments. We never see payment details, because we never ask for any.
- We do not sell personal data, and we do not share it for advertising.
8. Third-party services
Two outside parties are involved in running this website:
- IPinfo supplies what is known about an address: country, region, city, network provider, and the VPN, proxy and Tor classification. IPinfo sits behind our API rather than in front of it. Your browser never contacts IPinfo; our server does, and it passes on the address being looked up.
- our hosting provider, which operates the machines the website and the API run on.
9. Legal bases for processing
Where the GDPR applies, we rely on two bases:
- Performing a service you asked for, Article 6(1)(b). We process the address of a lookup you requested so that we can answer it.
- Our legitimate interests, Article 6(1)(f). We keep technical logs and the service journal so the service stays available, request limits work and abuse can be investigated. We have weighed this against your interests: the journal keeps no recoverable address, and the logs are not used to profile anyone.
10. How long we keep things
- Service journal: 90 days from the lookup, then deleted automatically.
- Technical logs: no longer than running and protecting the service requires, and discarded when the service is next deployed.
- Data in your browser: until you clear it. We cannot delete it for you, because we cannot see it.
11. International transfers
IPinfo is based in the United States. When our server asks it about an address, that address leaves the European Economic Area. The transfer is governed by IPinfo's own terms and safeguards, set out in the privacy policy linked above.
12. Your rights
If the GDPR applies to you, you have the right to:
- ask what personal data we hold about you
- have inaccurate data corrected
- have your data erased
- have our processing of it restricted
- receive your data in a portable form
- object to processing we base on legitimate interests
- complain to the data protection supervisory authority of the country you live in
Two notes on what this means in practice. The data in your browser is yours alone: we hold no copy of it and have no way to reach it, which is why you remove it yourself, as described above. Our own journal we can search if you tell us the address — we compute the same digest and find the records for it. What we cannot do is the reverse: work out from a record who someone is.
To exercise any of these rights, write to us at the address below.
13. Children
This website is not directed at children, and we do not knowingly collect personal data from children.
14. Security
Traffic between your browser and our servers is encrypted in transit. Addresses in our journal are protected by a keyed digest, and the key is kept apart from the journal, so a copy of the journal on its own would not reveal them. No method of storage or transmission is ever completely secure, which is why the design keeps the amount of recoverable personal data as small as we can make it.
15. Contact
For any question about this policy, or to exercise the rights set out above, write to us:
16. Changes to this policy
We may update this policy. When we do, the date at the top of this page changes with it. A change that matters will be described here rather than made quietly.