Legal

Privacy Policy

This Privacy Policy explains how IP Lens ("IP Lens", "we", "us") processes personal data when you use the IP Lens website, lookup pages, documentation, and public IP address intelligence features.

Version: 2026-08-28

1. Controller and contacts

Privacy contact
Email: privacy@iplens.io.
Vulnerability and security contact
Email: security@iplens.io.
Supervisory authority
If you are in Poland, you may contact the President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, UODO). You may also contact the supervisory authority in your European Union member state.

2. Roles and sources of data

IP Lens acts as a data controller when it decides which public IP address, network, routing, reverse DNS, geolocation, ownership, and related metadata to collect, enrich, publish, correct, suppress, or retain as part of the IP Lens dataset. IP Lens also acts as a controller for website operation, service security, support, and correction requests.

Data may come from you when you visit a page, submit a lookup, or contact us. It may also come from public or publicly available sources, including public registration records, BGP routing data, reverse DNS, geolocation datasets, special-purpose address registries, and other public network-intelligence sources.

3. Data categories and retention

IP addresses, hostnames, and network identifiers can be personal data in some contexts. We process them under the General Data Protection Regulation (GDPR) only when we have a legal basis and a defined purpose.

We keep personal data only while it remains necessary for the purpose described below. We delete or irreversibly anonymize it when that need ends, subject to applicable legal requirements and specific legal or security holds.

Providing data

Except where we tell you otherwise for a specific matter, providing personal data is not a statutory or contractual requirement and is not required to enter into a contract with IP Lens. IP Lens has no accounts or paid subscriptions, so you do not need to provide account or billing data. Limited data must nevertheless be processed to provide functions that you choose to request:

  • Lookups and pages. We must process the lookup selector, if any, and the technical request metadata needed to receive your request and return the requested result or page. Without that data, we cannot provide the lookup or page.
  • Contacting us. Contact information and message content are voluntary. If you do not provide enough information for us to understand, answer, or verify your request, we may be unable to respond or act on it.

3.1 Historical IP and network observations

This includes IP addresses, prefixes, Autonomous System Numbers (ASNs), network names, public registry data, approximate geolocation, reverse DNS hostnames, routing signals, special-purpose address metadata, and related public facts.

Purpose and legal basis: provide IP address intelligence, support longitudinal first-seen/last-seen and infrastructure-change analysis, validate sources, improve data quality, and support defensive-security research (Art. 6(1)(f) GDPR). GDPR Recital 49 recognizes processing necessary and proportionate for network and information security as a legitimate interest.

Retention: observations remain in the historical IP Lens dataset while they continue to support those purposes. We review them at least annually and correct, suppress, aggregate, or delete data that is no longer relevant, accurate, proportionate, or lawful.

3.2 Technical and security logs

The search queries that you submit, together with basic request metadata needed to return the page, secure the Service, and operate logs. Technical and security logs may also include page and access requests, CDN and infrastructure records, collection/import/validation events, network or routine security logs, paths, times, source IP addresses, user agents, referrers, response statuses, errors, rate-limit events, and security events.

Purpose and legal basis: return the requested page, collect and validate the public dataset, troubleshoot errors, maintain security, prevent abuse, and understand operational reliability (Art. 6(1)(f) GDPR and Recital 49).

Retention: we keep these logs only while they remain useful for operating, troubleshooting, auditing, and securing the Service. We regularly review aged records and delete, aggregate, or irreversibly anonymize them when that operational or security need ends.

3.3 Website audience analytics

Our company-controlled, self-hosted Umami service at stats.iplens.io records a pageview with the exact page path, page title, website hostname, referrer domain and path, browser, language, screen size, device information, and approximate country, region, and city when they can be derived from the request IP address.

Umami derives a pseudonymous session identifier from the website property, request IP address, user agent, application secret, and a salt that rotates monthly. Matching inputs can be linked within the current monthly rotation; the next rotation produces a different identifier. Umami does not retain the raw IP address in the analytics record.

The configured tracker removes query strings and URL fragments from the page URL and referrer before transmission, while retaining the referrer domain and path.

Purpose and legal basis: understand which parts of IP Lens are used, measure audience trends, and improve the Service (Art. 6(1)(f) GDPR). We do not use this information for advertising, cross-site tracking, user identification, custom event tracking, browser performance collection, session replay, or automated decisions. The tracker honors your browser's Do Not Track signal.

Retention: we keep analytics records only while they remain necessary to measure audience trends and improve the Service. A recurring process deletes aged records when that need ends. Copies of deleted records are removed through the applicable backup overwrite cycle.

To opt out on this IP Lens origin, store a non-empty value, for example localStorage.setItem("umami.disabled", "1"). The tracker suppresses analytics while localStorage.getItem("umami.disabled") returns a non-empty value. Removing the key re-enables analytics.

3.5 Cases, correspondence, corrections, and security reports

If you contact us, we process the contact details and message content you provide, along with any IP address, prefix, ASN, page URL, source details, attachments, or case evidence. A vulnerability report may also include the researcher's contact details, affected host, technical evidence, reproduction steps, timestamps, and follow-up correspondence.

Purpose and legal basis: answer and acknowledge support, privacy, and security reports; handle corrections or suppression; triage and reproduce vulnerabilities; coordinate and document remediation; investigate abuse or security matters; prevent harm; preserve necessary evidence; comply with legal obligations; and establish, exercise, or defend claims (Art. 6(1)(f), 6(1)(c), or 6(1)(b) GDPR depending on the matter).

Retention: we keep correspondence and case records while they remain necessary to handle the matter, meet legal or regulatory duties, investigate an incident, or establish, exercise, or defend a claim. We consider the case status, the nature of the record, and applicable legal requirements when reviewing it for deletion. We remove unnecessary secrets, attachments, personal data, and technical evidence as the matter progresses. Vulnerability reports that become security cases follow the applicable security-case retention rule. Minimal correction, suppression, or claim records may remain while necessary to honor the decision or protect a claim.

Send vulnerability reports to security@iplens.io. The production-only testing scope, safe harbor, and three-business-day acknowledgment target are in the Good-faith security research clause. Current machine-readable disclosure contact and policy links are available in security.txt.

3.6 Backups and holds

Data removed from active systems may remain in rolling backups until those copies are overwritten through the applicable backup cycle. Backup copies are not restored for ordinary processing.

If a backup is restored, we reapply applicable deletion, correction, and suppression outcomes. A specific legal or security hold may suspend deletion for selected records; holds are scoped, reviewed regularly, and released when no longer necessary.

Backup persistence is a technical overwrite delay, not a new processing purpose or a guaranteed data-availability period.

4. Public IP intelligence

IP Lens publishes information about IP addresses, networks, and public Internet infrastructure. This information describes network-level context and apparent network endpoints, not a verified identification of a particular person or household. Because IP addresses may be shared, reassigned, translated, or routed through proxies, VPNs, mobile networks, or carrier-grade network address translation, results are approximate and should not be used as the sole basis for identifying a person or determining their precise location.

Because IP data changes frequently, the dataset may contain old, incomplete, or incorrect entries. We review correction and suppression requests when they are specific enough to evaluate and when the requested change is consistent with security, transparency, source-license, and legal obligations.

5. Security, subprocessors, and transfers

We use HTTPS for public web traffic and limit access to operational systems. Main servers that process requests and store service databases are self-hosted. Website audience analytics is handled as described in section 3.3. Consent-based Google Ads conversion measurement is described in section 3.4. Third-party recipients and subprocessors that may process personal data for IP Lens are:

  • Amazon Web Services (AWS) is a subprocessor for product DNS, static asset delivery, and related access logging. Amazon Route 53 processes authoritative DNS request metadata needed to answer and secure requests for IP Lens domains through its global infrastructure. Amazon CloudFront delivers static assets through its global edge network and may process viewer IP addresses and ports, request times and paths, response details, referrers, user agents, protocol and TLS details, cache and timing data, and request identifiers. Amazon S3 stores public static assets and related object and origin metadata in European Union AWS Regions, primarily eu-central-1. Amazon CloudWatch Logs stores CloudFront access logs and delivery metadata in us-east-1. AWS does not host the core IP Lens application databases.
  • Google Ads receives conversion-measurement data only after the consent described in section 3.4. Google Ireland Limited and relevant Google affiliates process the ad-click, device, request, page, and conversion data through Google's global infrastructure and approved subprocessors, including outside the European Economic Area. For this Google Ads conversion service, Google and IP Lens each act as an independent controller under the applicable Google Ads controller terms.
  • Google Workspace is a subprocessor for corporate email, corporate documents, and internal legal, privacy, security, and support communications. It may process names and contact details, message and attachment contents, documents, and collaboration metadata through Google's global infrastructure and approved subprocessors, including outside the European Economic Area. IP Lens does not use Google Workspace for website transactional email.

AWS and Google process the relevant personal data under their applicable service, data protection, and controller terms. Where those arrangements involve a transfer that requires additional safeguards, their contractual terms provide Standard Contractual Clauses as applicable.

Personal data may be transferred outside the European Economic Area when a subprocessor or network path requires it. Where legally required, we rely on an adequacy decision, Standard Contractual Clauses, or another lawful basis under GDPR Chapter V.

Where required, we document a transfer impact assessment to evaluate whether the selected transfer basis provides effective protection in the circumstances and whether supplementary measures are needed. A transfer impact assessment and supplementary measures do not independently authorize a transfer.

7. Your privacy rights

Subject to the conditions and exceptions under applicable law, you may have rights to access personal data about you and receive a copy, rectify or erase it, or restrict its processing. You may also have the right to data portability as described below and to complain to a supervisory authority.

Where we process personal data based on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary to establish, exercise, or defend legal claims.

Where processing is carried out by automated means and is based on your consent or on a contract, you have the right to receive personal data that you provided to us in a structured, commonly used, machine-readable format and to transmit it to another controller. Where technically feasible, you may ask us to transmit that data directly to the other controller.

To exercise rights, contact privacy@iplens.io. Please identify the IP address, prefix, ASN, page URL, or message at issue and explain your relationship to the data so we can evaluate the request. We may need to verify your identity or authority before making a change.

We provide information on action taken without undue delay and in any event within one month after receiving your request. Where necessary, taking into account the complexity and number of requests, we may extend that period by up to two further months. We will tell you about the extension and explain the reasons for it within one month after receiving your request.

8. Cookies and similar technologies

IP Lens does not use analytics cookies. The self-hosted audience analytics described in section 3.3 is cookie-free. The Google tag and advertising cookies described in section 3.4 remain blocked unless a visitor with a qualifying URL parameter selects Allow conversion measurement.

IP Lens stores the first-party iplens.google-ads-consent preference so it can honor your choice. After consent on a qualifying visit, the first-party iplens.google-ads-attribution record stores only the start and expiry times and whether the visit qualified and a conversion is pending or complete. It does not store the Google click identifier. Use Ad conversion settings in the page footer to change or withdraw your choice.

If you explicitly select the Light or Dark color theme, IP Lens stores that choice in the first-party lens_theme cookie for up to one year. It is used only to provide the requested display preference and is not used for analytics or tracking. Selecting System removes the cookie. You can also remove it by deleting browser data.

9. Children

IP Lens is a general-audience service and is not directed to children. We do not knowingly solicit personal data from children through privacy, correction, support, security, or other direct-contact channels. A parent or guardian who believes that a child has provided personal data directly to IP Lens may contact privacy@iplens.io. We will assess the request under applicable law and may request information reasonably necessary to verify identity and authority.

10. Changes and contact

We update this Privacy Policy when the Service, law, infrastructure, suppliers, or processing changes so that it remains accurate. An update to this notice does not create a new legal basis, reduce data-protection rights, or change contractual Terms. Before using personal data for a materially different purpose, we will provide information before that processing and obtain consent where applicable law requires it. The version above identifies the current notice.

Questions about privacy, correction requests, subprocessors, or data protection rights should be sent to privacy@iplens.io.