Privacy policy

Short version: your IP address is displayed in your browser and is not stored by IPVitals.

What we process

When you open this site, your browser requests the trace endpoint on our domain, which Cloudflare answers directly at its edge. The response is a small piece of text with the address and network information your connection presents, and it is rendered on the page for you to read. It is not written to a database, a file or a queue, and it is not linked to any identifier. To check IPv4 and IPv6 separately, the page also requests the same trace endpoints from 1.1.1.1 and one.one.one.one, which are Cloudflare addresses too.

The approximate location shown on the home page and on the ISP page is requested from our own origin as /api/geo. It is calculated per request, on the fly, from headers that Cloudflare adds at its edge, and the result is returned to your browser only. Our origin server does not keep a copy of the values and does not write access logs for these requests.

The lookup page does its work in your browser. The address you type is parsed locally. To show the network, the page downloads only the small static ASN shard that covers that address range, so our server can see which broad range is being queried, but not the full address, and those requests are not written to the access log. The reverse DNS query goes from your browser straight to Cloudflare's DNS-over-HTTPS resolver and carries the reverse name of the address. If the page puts the address in the URL fragment after the hash symbol, that fragment stays in your browser, can be shared or bookmarked, and is never sent to our server.

  • No account and no sign-in.
  • Our own server page counter sets no cookies and does not store your raw IP in the browser; the separate Google Analytics, when active under the regional policy, may set its analytics cookies.
  • No third-party advertising trackers. Optional Google Analytics follows regional privacy controls: prior consent in the EEA/UK/CH and conservative or unknown regions; default-on with footer opt-out elsewhere. When storage is blocked it does not default on; an explicit Allow can run for that page from memory only.
  • No advertising and no affiliate links; no third-party scripts other than optional Google Analytics running under the regional policy.
  • No fingerprinting: the browser details on this page are computed locally and shown to you only.

Cloudflare's role

IPVitals is delivered through Cloudflare, which provides DNS, the content delivery network and protection against abuse. As part of that role, Cloudflare processes technical data about each request, including the connecting IP address, under its own privacy policy: https://www.cloudflare.com/privacypolicy/

Three features use Cloudflare endpoints directly from your browser. The trace endpoint reports which address and which data center your connection is using, and it is requested from our own domain and from 1.1.1.1 and one.one.one.one. A STUN server is used during the WebRTC leak test to discover candidate addresses. Cloudflare's DNS-over-HTTPS resolver answers the reverse DNS query, receiving the reverse name of the address you look up. These requests go to Cloudflare, not through our origin server, and are subject to the same Cloudflare policy.

Other than the optional Google Analytics described below, no other external service is contacted. The page loads no remote fonts, no advertising scripts, and no third-party images. Optional Google Analytics runs under the regional policy: prior consent in conservative or unknown regions, default-on with footer opt-out in other recognized regions.

Hosting, page-view counts and logs

The site runs on a server that we control. The /api/geo endpoint and the ASN data requests are not logged at all, and the web server's ordinary access log is switched off. Only error and warning level messages are kept, for troubleshooting; they can include the requested path, the time and technical details of the failing request, and they are rotated daily and kept for about two weeks at most. They are used only to keep the site running, never to build profiles, and they are not sold or shared.

Page views are counted, and we want to be exact about how. The web server sends page requests to our own first-party counting service over a local socket on the same machine, so nothing goes to a third party. Only page requests that return HTTP 200 or 304 are counted: no API or ASN requests, no images, scripts or stylesheets, no error pages. Each stored event holds only: the date and time; the page address and its language; the country reported by Cloudflare; whether the request came from a regular browser, a named crawler or another automated client; for a regular browser, the type of device (such as phone, tablet or computer) and the names of its operating system and browser, read from the user-agent string without version numbers; the host name of the referring website (no path or query, and the site's own host names are dropped); and, for a regular browser, a one-way 16-character hash of three inputs: a random salt that is replaced every day at midnight Beijing time, the visitor's IP address and the browser's user agent string. The IP address, the full user agent and the full referrer are never stored. The service sets no cookies and does not use browser storage. Raw events are deleted after 14 days and only the daily totals remain, kept for 90 days. What is left is an aggregate count: we cannot look up who visited, and we do not share the numbers with anyone.

This site may offer optional Google Analytics 4 to understand general traffic trends. Google Analytics operates under regional privacy policies: in regions requiring prior consent (such as the EEA, UK, Switzerland, and conservative jurisdictions) or where visitor region is unknown, measurement only activates if you explicitly choose Allow in the footer settings. In other recognized regions, measurement is enabled by default with opt-out available at any time via the footer settings. When storage is blocked, measurement does not default on; if you explicitly choose Allow, it can run for that page from memory only. If your browser sends a Global Privacy Control (GPC) or Do Not Track (DNT) signal, or you refuse or withdraw consent, Google Analytics remains completely inactive and that choice overrides the regional default. Choosing not to allow it, opting out, or withdrawing consent at any time never restricts access to any tool. When active, Google Analytics uses pseudonymous cookies (such as _ga, expiring in up to 180 days) to distinguish unique visits, and your choice is remembered in localStorage for up to 180 days (or temporary memory if storage is unavailable). Google receives standard connection metadata, including your IP address, browser type, device details, referring domain, and clean page addresses and a fixed page title, without tool queries, IP inputs, or fragments. Advertising features, Google Signals, and ad personalization are disabled with no cross-site identification; network requests transmit your IP address to Google to facilitate the connection, and data may be processed on servers outside your country by Google and its affiliates. For this site, the Google Analytics administration settings are already configured to limit user-level and event-level data retention to 2 months with reset on new activity disabled; standard aggregate reports may remain longer. Cookie consent choice and pseudonymous cookies expire in up to 180 days, while first-party server telemetry retains raw events for up to 14 days and daily aggregate counts for up to 90 days. You can opt out or withdraw consent at any time via the footer settings; doing so immediately stops data collection and clears cookies without removing your local preferences or tool data. Learn how Google uses information from sites at policies.google.com/technologies/partner-sites and see Google's privacy policy at policies.google.com/privacy .

Contact

Questions about this policy, a correction, or a request related to data can be sent to contact@ipvitals.com. Email routing is provided by Cloudflare, so a message to that address is handled under the same Cloudflare policy described above.

Changes to this policy

If the way the site handles data changes, this page will be updated and the change will be described here. The version of this policy is the one published on this page at the time you read it.