Legal
Privacy Policy
This Privacy Policy explains how IP Lens ("IP Lens", "we", "us") processes personal data when you use the IP Lens website, lookup pages, documentation, and public IP address intelligence features.
Version: 2026-08-28
1. Controller and contacts
- Privacy contact
- Email: privacy@iplens.io.
- Vulnerability and security contact
- Email: security@iplens.io.
- Supervisory authority
- If you are in Poland, you may contact the President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, UODO). You may also contact the supervisory authority in your European Union member state.
2. Roles and sources of data
IP Lens acts as a data controller when it decides which public IP address, network, routing, reverse DNS, geolocation, ownership, and related metadata to collect, enrich, publish, correct, suppress, or retain as part of the IP Lens dataset. IP Lens also acts as a controller for website operation, service security, support, and correction requests.
Data may come from you when you visit a page, submit a lookup, or contact us. It may also come from public or publicly available sources, including public registration records, BGP routing data, reverse DNS, geolocation datasets, special-purpose address registries, and other public network-intelligence sources.
3. Data categories and retention
IP addresses, hostnames, and network identifiers can be personal data in some contexts. We process them under the General Data Protection Regulation (GDPR) only when we have a legal basis and a defined purpose.
We keep personal data only while it remains necessary for the purpose described below. We delete or irreversibly anonymize it when that need ends, subject to applicable legal requirements and specific legal or security holds.
Providing data
Except where we tell you otherwise for a specific matter, providing personal data is not a statutory or contractual requirement and is not required to enter into a contract with IP Lens. IP Lens has no accounts or paid subscriptions, so you do not need to provide account or billing data. Limited data must nevertheless be processed to provide functions that you choose to request:
- Lookups and pages. We must process the lookup selector, if any, and the technical request metadata needed to receive your request and return the requested result or page. Without that data, we cannot provide the lookup or page.
- Contacting us. Contact information and message content are voluntary. If you do not provide enough information for us to understand, answer, or verify your request, we may be unable to respond or act on it.
3.1 Historical IP and network observations
This includes IP addresses, prefixes, Autonomous System Numbers (ASNs), network names, public registry data, approximate geolocation, reverse DNS hostnames, routing signals, special-purpose address metadata, and related public facts.
Purpose and legal basis: provide IP address intelligence, support longitudinal first-seen/last-seen and infrastructure-change analysis, validate sources, improve data quality, and support defensive-security research (Art. 6(1)(f) GDPR). GDPR Recital 49 recognizes processing necessary and proportionate for network and information security as a legitimate interest.
Retention: observations remain in the historical IP Lens dataset while they continue to support those purposes. We review them at least annually and correct, suppress, aggregate, or delete data that is no longer relevant, accurate, proportionate, or lawful.
3.2 Technical and security logs
The search queries that you submit, together with basic request metadata needed to return the page, secure the Service, and operate logs. Technical and security logs may also include page and access requests, CDN and infrastructure records, collection/import/validation events, network or routine security logs, paths, times, source IP addresses, user agents, referrers, response statuses, errors, rate-limit events, and security events.
Purpose and legal basis: return the requested page, collect and validate the public dataset, troubleshoot errors, maintain security, prevent abuse, and understand operational reliability (Art. 6(1)(f) GDPR and Recital 49).
Retention: we keep these logs only while they remain useful for operating, troubleshooting, auditing, and securing the Service. We regularly review aged records and delete, aggregate, or irreversibly anonymize them when that operational or security need ends.
3.3 Website audience analytics
Our company-controlled, self-hosted Umami service at stats.iplens.io records a pageview with the exact page path, page title, website hostname, referrer domain and path, browser, language, screen size, device information, and approximate country, region, and city when they can be derived from the request IP address.
Umami derives a pseudonymous session identifier from the website property, request IP address, user agent, application secret, and a salt that rotates monthly. Matching inputs can be linked within the current monthly rotation; the next rotation produces a different identifier. Umami does not retain the raw IP address in the analytics record.
The configured tracker removes query strings and URL fragments from the page URL and referrer before transmission, while retaining the referrer domain and path.
Purpose and legal basis: understand which parts of IP Lens are used, measure audience trends, and improve the Service (Art. 6(1)(f) GDPR). We do not use this information for advertising, cross-site tracking, user identification, custom event tracking, browser performance collection, session replay, or automated decisions. The tracker honors your browser's Do Not Track signal.
Retention: we keep analytics records only while they remain necessary to measure audience trends and improve the Service. A recurring process deletes aged records when that need ends. Copies of deleted records are removed through the applicable backup overwrite cycle.
To opt out on this IP Lens origin, store a non-empty value, for example localStorage.setItem("umami.disabled", "1"). The tracker suppresses analytics while localStorage.getItem("umami.disabled") returns a non-empty value. Removing the key re-enables analytics.
3.4 Google Ads conversion measurement
When a page URL contains a non-empty Google Ads click identifier or gtm_debug parameter, IP Lens asks whether you want to allow conversion measurement. The Google tag does not load unless you select Allow conversion measurement. Declining does not limit any IP Lens feature.
If you allow it, Google may receive an ad-click identifier when present, the IP Lens page path, the referring site's origin, the conversion time, and browser, device, request, consent, and network data, including your IP address. IP Lens removes unrelated query parameters, URL fragments, search terms, and referrer paths from the page information configured for the Google tag. The ad-click identifier and an IP address or prefix shown in a result-page path are not removed. IP Lens disables ad personalization signals and does not send enhanced-conversion contact data.
IP Lens reports one conversion if you submit a search or view an IP address or prefix result within 48 hours after the qualifying visit. The conversion and advertising cookie use rely on your consent under Art. 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law. You can withdraw consent at any time through Ad conversion settings in the page footer.
The first-party record becomes ineligible after one conversion, expires after 48 hours, and is removed at expiry or when you withdraw consent. Until then, its converted marker prevents duplicate reports. The consent preference remains in your browser until you change it or clear browser data. The Google tag may set first-party advertising cookies that hold ad-click information. Google controls its copies under the applicable Google Ads terms, account settings, and Google Privacy Policy.
3.5 Cases, correspondence, corrections, and security reports
If you contact us, we process the contact details and message content you provide, along with any IP address, prefix, ASN, page URL, source details, attachments, or case evidence. A vulnerability report may also include the researcher's contact details, affected host, technical evidence, reproduction steps, timestamps, and follow-up correspondence.
Purpose and legal basis: answer and acknowledge support, privacy, and security reports; handle corrections or suppression; triage and reproduce vulnerabilities; coordinate and document remediation; investigate abuse or security matters; prevent harm; preserve necessary evidence; comply with legal obligations; and establish, exercise, or defend claims (Art. 6(1)(f), 6(1)(c), or 6(1)(b) GDPR depending on the matter).
Retention: we keep correspondence and case records while they remain necessary to handle the matter, meet legal or regulatory duties, investigate an incident, or establish, exercise, or defend a claim. We consider the case status, the nature of the record, and applicable legal requirements when reviewing it for deletion. We remove unnecessary secrets, attachments, personal data, and technical evidence as the matter progresses. Vulnerability reports that become security cases follow the applicable security-case retention rule. Minimal correction, suppression, or claim records may remain while necessary to honor the decision or protect a claim.
Send vulnerability reports to security@iplens.io. The production-only testing scope, safe harbor, and three-business-day acknowledgment target are in the Good-faith security research clause. Current machine-readable disclosure contact and policy links are available in security.txt.
3.6 Backups and holds
Data removed from active systems may remain in rolling backups until those copies are overwritten through the applicable backup cycle. Backup copies are not restored for ordinary processing.
If a backup is restored, we reapply applicable deletion, correction, and suppression outcomes. A specific legal or security hold may suspend deletion for selected records; holds are scoped, reviewed regularly, and released when no longer necessary.
Backup persistence is a technical overwrite delay, not a new processing purpose or a guaranteed data-availability period.
4. Public IP intelligence
IP Lens publishes information about IP addresses, networks, and public Internet infrastructure. This information describes network-level context and apparent network endpoints, not a verified identification of a particular person or household. Because IP addresses may be shared, reassigned, translated, or routed through proxies, VPNs, mobile networks, or carrier-grade network address translation, results are approximate and should not be used as the sole basis for identifying a person or determining their precise location.
Because IP data changes frequently, the dataset may contain old, incomplete, or incorrect entries. We review correction and suppression requests when they are specific enough to evaluate and when the requested change is consistent with security, transparency, source-license, and legal obligations.
5. Security, subprocessors, and transfers
We use HTTPS for public web traffic and limit access to operational systems. Main servers that process requests and store service databases are self-hosted. Website audience analytics is handled as described in section 3.3. Consent-based Google Ads conversion measurement is described in section 3.4. Third-party recipients and subprocessors that may process personal data for IP Lens are:
-
Amazon Web Services (AWS) is a
subprocessor for product DNS, static asset delivery, and related access logging.
Amazon Route 53 processes authoritative DNS request metadata needed to answer and
secure requests for IP Lens domains through its global infrastructure. Amazon
CloudFront delivers static assets through its global edge network and may process
viewer IP addresses and ports, request times and paths, response details, referrers,
user agents, protocol and TLS details, cache and timing data, and request identifiers.
Amazon S3 stores public static assets and related object and origin metadata in
European Union AWS Regions, primarily
eu-central-1. Amazon CloudWatch Logs stores CloudFront access logs and delivery metadata inus-east-1. AWS does not host the core IP Lens application databases. - Google Ads receives conversion-measurement data only after the consent described in section 3.4. Google Ireland Limited and relevant Google affiliates process the ad-click, device, request, page, and conversion data through Google's global infrastructure and approved subprocessors, including outside the European Economic Area. For this Google Ads conversion service, Google and IP Lens each act as an independent controller under the applicable Google Ads controller terms.
- Google Workspace is a subprocessor for corporate email, corporate documents, and internal legal, privacy, security, and support communications. It may process names and contact details, message and attachment contents, documents, and collaboration metadata through Google's global infrastructure and approved subprocessors, including outside the European Economic Area. IP Lens does not use Google Workspace for website transactional email.
AWS and Google process the relevant personal data under their applicable service, data protection, and controller terms. Where those arrangements involve a transfer that requires additional safeguards, their contractual terms provide Standard Contractual Clauses as applicable.
Personal data may be transferred outside the European Economic Area when a subprocessor or network path requires it. Where legally required, we rely on an adequacy decision, Standard Contractual Clauses, or another lawful basis under GDPR Chapter V.
Where required, we document a transfer impact assessment to evaluate whether the selected transfer basis provides effective protection in the circumstances and whether supplementary measures are needed. A transfer impact assessment and supplementary measures do not independently authorize a transfer.
6. Government and law-enforcement requests
We review government and law-enforcement requests before responding. We disclose personal data only when we believe disclosure is legally required or necessary to protect the Service, users, or others from abuse or security threats.
7. Your privacy rights
Subject to the conditions and exceptions under applicable law, you may have rights to access personal data about you and receive a copy, rectify or erase it, or restrict its processing. You may also have the right to data portability as described below and to complain to a supervisory authority.
Where we process personal data based on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary to establish, exercise, or defend legal claims.
Where processing is carried out by automated means and is based on your consent or on a contract, you have the right to receive personal data that you provided to us in a structured, commonly used, machine-readable format and to transmit it to another controller. Where technically feasible, you may ask us to transmit that data directly to the other controller.
To exercise rights, contact privacy@iplens.io. Please identify the IP address, prefix, ASN, page URL, or message at issue and explain your relationship to the data so we can evaluate the request. We may need to verify your identity or authority before making a change.
We provide information on action taken without undue delay and in any event within one month after receiving your request. Where necessary, taking into account the complexity and number of requests, we may extend that period by up to two further months. We will tell you about the extension and explain the reasons for it within one month after receiving your request.
9. Children
IP Lens is a general-audience service and is not directed to children. We do not knowingly solicit personal data from children through privacy, correction, support, security, or other direct-contact channels. A parent or guardian who believes that a child has provided personal data directly to IP Lens may contact privacy@iplens.io. We will assess the request under applicable law and may request information reasonably necessary to verify identity and authority.
10. Changes and contact
We update this Privacy Policy when the Service, law, infrastructure, suppliers, or processing changes so that it remains accurate. An update to this notice does not create a new legal basis, reduce data-protection rights, or change contractual Terms. Before using personal data for a materially different purpose, we will provide information before that processing and obtain consent where applicable law requires it. The version above identifies the current notice.
Questions about privacy, correction requests, subprocessors, or data protection rights should be sent to privacy@iplens.io.