Acceptable Use Policy
Last updated 29 July 2026
This policy keeps the service fast and lawful for everyone. It forms part of our Terms of Service, and applies to free and paid plans alike.
Do not break the law
You must not use the service in breach of any law that applies to you or to us, including Australian privacy, telecommunications, and criminal law, and equivalent laws in your own jurisdiction.
Do not use it against individuals
IP geolocation describes networks, not people. You must not use the service to:
- Track, stalk, harass, dox, or intimidate a person.
- Identify or infer the home address of an individual.
- Make automated decisions with legal or similarly significant effects on a person without meaningful human review.
- Discriminate against people on the basis of where they appear to be located, in ways prohibited by law.
If you process our results together with personal data, you are the controller of that processing and responsible for having a lawful basis for it.
Do not attack or overload the service
- Do not evade rate limits or quotas — for example by rotating IP addresses, creating multiple accounts, or sharing keys to spread load.
- Do not attempt to gain unauthorised access to the service, other accounts, or the underlying infrastructure.
- Do not scan, probe, or test our security without written permission. See our security page for how to report a vulnerability responsibly.
- Do not use the service as part of a denial-of-service attack against anyone.
Handle 429 responses properly: back off and retry later rather than hammering the endpoint. Persistent hammering is treated as abuse.
Do not resell the raw data
You may use API responses inside your own products and services. You may not systematically extract, bulk-download, cache-and-redistribute, or otherwise rebuild our data into a competing geolocation database or resell it as raw data. Reasonable caching of results your own application has requested is fine and encouraged.
Keys and credentials
- Keep API keys secret. Do not embed a secret key in a public repository, a mobile app binary, or client-side JavaScript.
- Do not share your key with third parties or use one account's keys on behalf of another business.
- Rotate a key immediately if it may have been exposed — the dashboard does this without downtime.
Enforcement
Where we see a breach we will usually contact you first and give you a chance to fix it. For serious breaches — illegal use, attacks, or conduct that puts the service or other customers at risk — we may suspend or terminate access immediately and without notice.
We may also apply technical measures such as blocking specific addresses or networks, and may report unlawful activity to the relevant authorities.
Reporting abuse
If you believe someone is using the service in breach of this policy, email [email protected] with details. To report a security vulnerability, see our security page.