Privacy Policy
Last updated 29 July 2026
This policy explains what we collect, why we collect it, how long we keep it, and the choices you have. It covers the ipaddresstoday.com website and the IP Address Today API.
Who we are
The data controller for the purposes of this policy is:
Parneet Singh (trading as IP Address Today)ABN 53 661 545 083
103/88 Tram Road, Doncaster VIC 3108, Australia
[email protected]
The short version
- We do not store the IP addresses you look up. Lookups are answered from a local database and are not written to disk or sent to a third party.
- We use no advertising trackers and set no advertising cookies. Analytics is off unless you accept it, and you can change that at any time from the foot of any page.
- We never sell personal information.
- You can delete your account at any time, and we purge it within 30 days.
What we collect
If you only use the public API or website without an account, we process your IP address transiently to apply rate limits and block abuse. It is held as a short-lived counter that expires within minutes and is not written to any permanent record or linked to you.
If you create an account, we collect and store:
- Your email address.
- A cryptographic hash of your password (Argon2id). We never store the password itself.
- Hashes of your API keys. The key is shown once at creation and cannot be recovered by us afterwards.
- Session records, including an approximate device description taken from your browser's user-agent string, so you can review and revoke active sessions.
- If you enable two-factor authentication, an encrypted authenticator secret and hashed recovery codes.
- Daily aggregated counts of API requests per key (totals, errors, and rate-limited requests) so we can show you usage and enforce quotas.
- Support tickets and messages you send us.
- A security audit log of account events such as sign-ins, key creation, and password changes.
If you subscribe to a paid plan, payment is handled by Stripe. We store only your Stripe customer identifier and invoice metadata. We never see or store your card number.
If you sign in with Google, we receive your email address and whether Google has verified it. We do not receive your Google password or access any other Google data.
What we deliberately do not collect
- The IP addresses submitted to the API for lookup. These are processed in memory and discarded.
- Advertising identifiers, cross-site trackers, or behavioural profiles.
- Any special category data (health, biometrics, political opinions, and similar).
Why we process it, and our legal basis
- To provide the service you asked for — performance of a contract.
- To keep the service available and prevent abuse, including rate limiting and blocking — legitimate interests.
- To take payment and meet tax obligations — contract and legal obligation.
- To send service messages such as email verification, sign-in codes, and quota warnings — contract and legitimate interests.
We do not send marketing email. If that ever changes, it will be opt-in and separately consented to.
Cookies and local storage
We set no advertising cookies, and we never sell or share your data with advertisers. The site stores three things in your browser's local storage: your session tokens (so you stay signed in), your light/dark theme preference, and your answer to the analytics question below. All three stay on your device and can be cleared at any time through your browser.
Our network provider, Cloudflare, may set a strictly necessary cookie to distinguish humans from bots and protect the service from attack.
Analytics, and your choice about it
We use Google Analytics to understand which pages people find useful. It is switched off until you agree to it. If you have not answered the banner, or you declined, no analytics script is loaded, no request is made to Google, and no analytics cookie is set — we do not load it and then hold the data back, we simply do not load it.
If you accept, Google Analytics sets cookies on your device and receives your truncated IP address, the pages you view, and general information about your browser and device. Google acts as our processor for this and may transfer data outside Australia, including to the United States. We do not use it for advertising, and we have not enabled ad personalisation or data sharing with Google's advertising products.
You can change your mind at any time using Cookie settings at the foot of any page. Withdrawing consent is exactly as easy as giving it, and takes effect immediately for anything loaded afterwards. To remove cookies already set, clear them through your browser.
Who we share it with
We do not sell personal information. We share it only with the providers needed to run the service:
- Stripe — payment processing and invoicing (United States, with EU standard contractual clauses).
- Cloudflare — network protection and content delivery.
- Our mail server — delivery of account and service email.
- Google — if you choose to sign in with Google, and for Google Analytics if you accept analytics cookies. Neither happens without your action.
Geolocation data comes from MaxMind's GeoLite2 databases, which we download and query on our own servers. Your lookups are never sent to MaxMind or anyone else.
We may also disclose information where required by Australian law, or to establish or defend a legal claim.
Where your data is held
Our servers are located in Australia. Some providers listed above process data overseas, including in the United States and the European Union. Where that happens we rely on the provider's contractual safeguards, including standard contractual clauses where applicable.
How long we keep it
- Aggregated API usage records: 12 months.
- Support tickets and related email: 24 months.
- Account data after you delete your account: purged within 30 days, except records we must keep for tax and accounting purposes (invoices are retained for five years as required by Australian law).
- Rate-limiting counters: minutes.
How we protect it
- All traffic is encrypted in transit with HTTPS.
- Passwords are hashed with Argon2id; API keys are stored only as HMAC-SHA256 hashes with a server-side secret.
- Two-factor authentication secrets are encrypted at rest.
- Optional two-factor authentication is available on every account, and we recommend enabling it.
No system is perfectly secure. If a breach occurs that is likely to cause serious harm, we will notify affected users and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Your rights
Under the Australian Privacy Principles you may ask for access to the personal information we hold about you, and ask us to correct it. If you are in the European Union or United Kingdom, the GDPR also gives you rights to erasure, restriction, objection, and data portability.
Most of this is self-service: your dashboard shows your account data, active sessions, API keys, and usage, and lets you change or delete them. For anything else, email [email protected] and we will respond within 30 days.
If you are unhappy with our response you can complain to the Office of the Australian Information Commissioner, or to your local supervisory authority in the EU or UK.
Children
The service is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child has created an account, contact us and we will remove it.
Language
This policy is published in English. Parts of our website are available in other languages; if we publish a translation of this policy and it differs from the English text, the English version is the authoritative one.
If anything here is unclear in your language, email [email protected] and we will explain it — you are entitled to understand what we do with your data, and we would rather answer the question than have you guess.
Changes to this policy
We may update this policy as the service changes. The date at the top reflects the current version, and material changes will be announced in the dashboard or by email before they take effect.
Questions? See our contact page.