IP Address Today

Privacy Policy

Last updated 29 July 2026

This policy explains what we collect, why we collect it, how long we keep it, and the choices you have. It covers the ipaddresstoday.com website and the IP Address Today API.

Who we are

The data controller for the purposes of this policy is:

Parneet Singh (trading as IP Address Today)
ABN 53 661 545 083
103/88 Tram Road, Doncaster VIC 3108, Australia
[email protected]

The short version

  • We do not store the IP addresses you look up. Lookups are answered from a local database and are not written to disk or sent to a third party.
  • We do not use advertising or analytics trackers, and we set no tracking cookies.
  • We never sell personal information.
  • You can delete your account at any time, and we purge it within 30 days.

What we collect

If you only use the public API or website without an account, we process your IP address transiently to apply rate limits and block abuse. It is held as a short-lived counter that expires within minutes and is not written to any permanent record or linked to you.

If you create an account, we collect and store:

  • Your email address.
  • A cryptographic hash of your password (Argon2id). We never store the password itself.
  • Hashes of your API keys. The key is shown once at creation and cannot be recovered by us afterwards.
  • Session records, including an approximate device description taken from your browser's user-agent string, so you can review and revoke active sessions.
  • If you enable two-factor authentication, an encrypted authenticator secret and hashed recovery codes.
  • Daily aggregated counts of API requests per key (totals, errors, and rate-limited requests) so we can show you usage and enforce quotas.
  • Support tickets and messages you send us.
  • A security audit log of account events such as sign-ins, key creation, and password changes.

If you subscribe to a paid plan, payment is handled by Stripe. We store only your Stripe customer identifier and invoice metadata. We never see or store your card number.

If you sign in with Google, we receive your email address and whether Google has verified it. We do not receive your Google password or access any other Google data.

What we deliberately do not collect

  • The IP addresses submitted to the API for lookup. These are processed in memory and discarded.
  • Advertising identifiers, cross-site trackers, or behavioural profiles.
  • Any special category data (health, biometrics, political opinions, and similar).

Why we process it, and our legal basis

  • To provide the service you asked for — performance of a contract.
  • To keep the service available and prevent abuse, including rate limiting and blocking — legitimate interests.
  • To take payment and meet tax obligations — contract and legal obligation.
  • To send service messages such as email verification, sign-in codes, and quota warnings — contract and legitimate interests.

We do not send marketing email. If that ever changes, it will be opt-in and separately consented to.

Cookies and local storage

We set no advertising or analytics cookies. The site stores two things in your browser's local storage: your session tokens (so you stay signed in) and your light/dark theme preference. Both stay on your device and can be cleared at any time through your browser.

Our network provider, Cloudflare, may set a strictly necessary cookie to distinguish humans from bots and protect the service from attack.

Who we share it with

We do not sell personal information. We share it only with the providers needed to run the service:

  • Stripe — payment processing and invoicing (United States, with EU standard contractual clauses).
  • Cloudflare — network protection and content delivery.
  • Our mail server — delivery of account and service email.
  • Google — only if you choose to sign in with Google.

Geolocation data comes from MaxMind's GeoLite2 databases, which we download and query on our own servers. Your lookups are never sent to MaxMind or anyone else.

We may also disclose information where required by Australian law, or to establish or defend a legal claim.

Where your data is held

Our servers are located in Australia. Some providers listed above process data overseas, including in the United States and the European Union. Where that happens we rely on the provider's contractual safeguards, including standard contractual clauses where applicable.

How long we keep it

  • Aggregated API usage records: 12 months.
  • Support tickets and related email: 24 months.
  • Account data after you delete your account: purged within 30 days, except records we must keep for tax and accounting purposes (invoices are retained for five years as required by Australian law).
  • Rate-limiting counters: minutes.

How we protect it

  • All traffic is encrypted in transit with HTTPS.
  • Passwords are hashed with Argon2id; API keys are stored only as HMAC-SHA256 hashes with a server-side secret.
  • Two-factor authentication secrets are encrypted at rest.
  • Optional two-factor authentication is available on every account, and we recommend enabling it.

No system is perfectly secure. If a breach occurs that is likely to cause serious harm, we will notify affected users and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

Your rights

Under the Australian Privacy Principles you may ask for access to the personal information we hold about you, and ask us to correct it. If you are in the European Union or United Kingdom, the GDPR also gives you rights to erasure, restriction, objection, and data portability.

Most of this is self-service: your dashboard shows your account data, active sessions, API keys, and usage, and lets you change or delete them. For anything else, email [email protected] and we will respond within 30 days.

If you are unhappy with our response you can complain to the Office of the Australian Information Commissioner, or to your local supervisory authority in the EU or UK.

Children

The service is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child has created an account, contact us and we will remove it.

Language

This policy is published in English. Parts of our website are available in other languages; if we publish a translation of this policy and it differs from the English text, the English version is the authoritative one.

If anything here is unclear in your language, email [email protected] and we will explain it — you are entitled to understand what we do with your data, and we would rather answer the question than have you guess.

Changes to this policy

We may update this policy as the service changes. The date at the top reflects the current version, and material changes will be announced in the dashboard or by email before they take effect.

Questions? See our contact page.