Last updated: October 8, 2026
This policy explains what happens to information about you when you use IPFerret — the website at ipferret.com and its JSON API. IPFerret is run by Liquid Monks, which is responsible for the data described here. Questions go to privacy@ipferret.com.
The short version
- There are no accounts, sign-ups or logins.
- We don't keep a database of visitors' IP addresses.
- Our own code sets no cookies. Google's advertising, analytics and consent tools do; they are listed below.
- We don't fingerprint your browser or device, and we don't sell or share your data with data brokers.
- Most tools send the address or name you type to a public service (a DNS resolver, a registry, a blocklist) from our server, so that service sees our server, not you. The speed test and the WebRTC leak test are the exceptions: they run in your browser and contact Cloudflare and Google directly.
When you load a page
Your browser sends our server your IP address and the usual request headers (browser, language and so on), as with any website. We use them to answer the request: several pages exist to show you exactly that information.
- Location and network of your IP. On the pages that show your own IP (the home page and What is my IP?) and when you look up an IP address, our server asks ipinfo.io for its approximate location and network. Only the IP address is sent. See ipinfo's privacy policy.
- Pageview counter. For our own visit statistics we record, for each page view: the time, the page address without anything after a
?, a visitor code made from your IP address and a secret value that changes every day (the IP itself is not stored, and the code can't be matched to you across days), your browser, operating system and device type in broad terms, the website that linked you here (its name only), and your country when it is known. These records stay on our server and are never shared. - Server logs. Our web server and app keep technical logs, which can include IP addresses and the addresses checked with a tool, for security and to fix errors. They are kept only as long as needed for that and are not shared.
- Rate limiting. To stop abuse, our server counts recent requests per IP address. The counts are kept only in memory, are never written to disk, and are cleared when the app restarts or needs the space.
When you use a tool
The address, domain or text you enter is processed as described below and is not stored by us. Lookups are made by our server unless the tool says otherwise.
- DNS lookup, email authentication check, bulk reverse DNS, what's hosting this site, blocklist checker. The name or address you enter is resolved through Cloudflare's public DNS resolver (
1.1.1.1, DNS over HTTPS); see Cloudflare's resolver privacy notice. The blocklist checker looks the IP up in public DNS blocklists (Spamhaus, Barracuda, SORBS, SpamCop, CBL, PSBL, UCEPROTECT, GBUdb, Mailspike and s5h.net), so those operators' name servers receive the IP you check. - WHOIS / RDAP, domain age, ASN and country pages. The IP address, domain or network number is sent to the registry that holds it: the Regional Internet Registries (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC) through their RDAP service, the domain's registry through rdap.org, and RIPE NCC's RIPEstat for network and country details.
- Domain history. The domain is looked up in the public certificate transparency log search crt.sh and the Internet Archive's Wayback Machine.
- MAC vendor lookup. Only the first half of the MAC address (the manufacturer prefix) is sent to macvendors.com.
- SSL/TLS checker, Open Graph checker, port checker. Our server connects to the host you enter (public addresses only) to read its certificate, page tags or port status.
- Visual traceroute. Only the host name and port you enter are sent to our server (usernames, passwords and the rest of a pasted link are removed in your browser first). The destination is not put into the page address, so it does not reach analytics or ad requests; a link made with “Copy a link to this check” keeps it after a
#, which browsers never send to any server. Our server resolves that host through Cloudflare's DNS resolver, opens one TCP connection to the port, and sends traceroute probes to it. Text you paste from your own traceroute stays in your browser. To name the networks on the path, the public router addresses (from our trace, or found in your pasted text) and your own IP address are looked up in Team Cymru's IP-to-ASN service and by a reverse-DNS query for each address, both sent through Cloudflare's DNS resolver; reverse-DNS answers come from the name servers of whoever runs each network. Those answers are kept in our server's memory for up to an hour so repeat lookups are fast, and are never written to disk. We don't store the destinations you test or the results. - Speed test (in your browser). When you start it, your browser downloads and uploads test data directly with Cloudflare's speed-test servers (
speed.cloudflare.com), so Cloudflare sees your IP address. Results are shown to you and not sent to us. - WebRTC leak test (in your browser). Your browser asks Google's public STUN server (
stun.l.google.com) which address it appears to come from, so Google sees your IP address. The addresses found are shown to you and not sent to us. - Tools that run entirely in your browser — email header analyzer, IP extractor, CIDR calculator and aggregator, IP converters — send nothing anywhere.
Advertising, consent and analytics (Google)
- Google AdSense pays for the site. Its script loads on every page and, with Google's ad-fraud checks, uses cookies and similar technologies to choose and measure ads, as described in how Google uses information from sites that use its services and its cookie policy. You can turn off personalised ads at adssettings.google.com.
- Google's consent tool. Visitors in the European Economic Area, the UK and Switzerland are asked first, with the choices Consent, Do not consent and Manage options. Until you choose, and if you decline, Google's tags run without advertising or analytics cookies.
- Google Analytics 4 measures overall traffic: which pages are popular, how visitors arrive, broad device and browser numbers. It follows the same consent settings as AdSense (Google Consent Mode): where consent is needed and not given, it sends only cookieless signals. See how Google Analytics safeguards data.
- Where consent is assumed. In the United States and a list of other countries where the law allows it (Canada, Mexico, Australia, New Zealand, Japan, South Korea, Singapore, Hong Kong, India, Brazil, Argentina, Chile, South Africa, the United Arab Emirates, Israel and Turkey), advertising and analytics cookies are on by default. Everywhere else not mentioned here, Google's tags start without those cookies.
- ads.txt. We publish /ads.txt, a public list of who may sell ad space on this site. It collects nothing.
Cookies and browser storage
- Set by our own code: none. Your light/dark theme choice is kept in your browser's
localStorageand never leaves your device. - Google's consent tool keeps your choice in cookies on this site (such as
FCCDCFandFCNEC) so it doesn't ask on every page. - Google AdSense sets cookies on Google domains such as
doubleclick.netfor choosing ads, limiting repeats and counting clicks; see Google's list of ad cookies. - Google Analytics 4, where consent is given or assumed, sets
_gaand_ga_*cookies to tell visits apart in its totals.
Your rights
Depending on where you live (for example under the GDPR in the EU/EEA, the UK GDPR, the Swiss FADP, or California's CCPA/CPRA), you can ask to see, correct, delete or receive a copy of personal data we hold about you, object to its use, or withdraw consent. Because there are no accounts and no IP database, what we hold about any one visitor is limited to the pageview records and short-lived logs described above, which we cannot link to you by name. Email privacy@ipferret.com and we will reply within 30 days. For data held by Google, use your Google account settings or Google's own processes. We do not sell personal information.
Children
IPFerret is not directed at children under 13 (or the equivalent age where you live). We do not knowingly collect data from children. If you believe we have, contact privacy@ipferret.com and we will delete it.
Changes to this policy
When this policy changes, the “Last updated” date at the top changes with it.
Contact
Liquid Monks, for IPFerret: privacy@ipferret.com.
