Privacy policy
Last updated 2026-10-03.
Who we are
This policy explains what personal data IP-FD.net ("we") collects when you use the website and the API, why we collect it and what your rights are. Questions can be sent through the contact page.
Data we collect
- Account data: username, email address and a bcrypt hash of your password. If you sign in with GitHub or Discord we receive your account ID, username and avatar from that service.
- Security data: the IP address and browser user agent of each session and sign-in attempt, used to show your active sessions and to detect abuse.
- API usage: for requests made with your API key we store the endpoint, the address you looked up, its country and the time. This powers your usage statistics and daily quota.
- Request logs: every API request is logged with its endpoint, time and source IP address for rate limiting and abuse prevention.
- Support data: messages you send through tickets, the contact form, location reports and geofeed submissions.
- Monitors: the targets, settings and check history of uptime monitors you create. Passwords for monitored URLs are stored encrypted.
Cookies
We set a session cookie when you sign in, a cookie that protects forms against cross-site request forgery and, during two-factor sign in, a short-lived cookie that expires after five minutes. These are necessary for the site to work. If web analytics is enabled on the site, Google Analytics sets its own cookies with IP anonymisation turned on. Your theme choice is stored in your browser's local storage, not in a cookie.
Why we use it
- To provide the lookups, API, monitors and account features you use.
- To keep accounts secure and stop abuse of the service.
- To answer support requests and review location reports.
- To send emails you need, such as password resets, monitor alerts and ticket replies.
Third parties
We do not sell personal data. Some features rely on outside services:
- RIPE NCC: addresses you look up may be sent to RIPE IPmap and the RIPE Database to locate them.
- AbuseIPDB and Spamhaus: the address on an IP page is checked against their reputation data.
- OpenStreetMap: map tiles on lookup pages are loaded from its servers.
- Google Fonts and unpkg: fonts, flags and the map library are loaded from these CDNs.
- icanhazip.com: the What is my IP page asks it for your IPv4 and IPv6 address, directly from your browser.
- GitHub and Discord: only if you choose to sign in with them.
- Our email provider: for messages we send to you.
How long we keep it
- Account data: until you delete your account.
- API request logs: 90 days. API usage per key: 180 days.
- Sign-in history: 180 days.
- Sessions: 30 days after you last signed in.
- Monitor check history: 30 days.
- Support messages: until the ticket is deleted or your account is removed.
Your rights
You can see and change your account details, export your data and delete your account at any time from the dashboard. Deleting your account removes your API keys, usage history, saved items, monitors and tickets. For any other request about your data, including access, correction or objection, contact us. If you are in the EU or UK you can also complain to your data protection authority.
Registry data
IP-FD.net shows data published by the regional internet registries. Organisation names, abuse contacts and addresses come from their public databases. If you want registry data about you changed, contact the registry or your network provider. We update our copy every day.
Changes
When we change this policy we update the date at the top. Important changes are announced on the site or by email.