Privacy Policy
Last updated: 2026-05-25
This policy describes what data IPconf (ipconf.me, ipconf.cn, api.ipconf.me) collects, why we collect it, how long we keep it, and what we don't do. It is written to be readable. If anything here is unclear, that's a bug — please report it.
1. What we collect
1.1 Your IP address
Every HTTP request to our servers carries an IP address. That's how TCP/IP works — we couldn't return you a response without it. We display it back to you on the homepage, log it in our server access logs, and use it as input to the geolocation lookup you asked for.
1.2 Standard request metadata
Along with each request we receive:
- Browser User-Agent string (browser and OS family)
Accept-Languageheader (used to choose UI language)- The URL path you visited
- The HTTP method and response status code
- Timestamp
We do not fingerprint your browser beyond standard server logging. We do not load any JavaScript that probes for fonts, plugins, canvas hashes, or other passive identifiers.
1.3 Cookies and local storage
We use the smallest set of cookies/local storage we can:
-
theme(localStorage) — your light/dark preference. Set on your device only, never sent to our servers. - Analytics cookies set by Google Analytics or Baidu Analytics (see §3). You can block these by blocking the analytics domain in your browser or with an extension.
We do not use cookies to track you across sessions or sites for our own purposes. There is no advertising cookie set by us directly.
2. How we use the data
- To answer your request: when you open a tool page, we use your IP to display your geolocation; when you call the API, we return the response. This is the immediate, contractual use.
- To prevent abuse: rate limits and basic anomaly detection use IP and request patterns.
- To generate aggregate statistics: number of requests per day, popular endpoints, error rates. These are anonymized counts, not per-user records.
- To improve geolocation accuracy: when a user submits a correction via the Report button, we re-check the data and may update our database for that IP range.
3. Third-party services
- Cloudflare — sits in front of all our domains for CDN, TLS termination, and DDoS protection. Cloudflare necessarily sees every request. Their handling is described in their privacy policy.
- Google Analytics — loaded for visitors outside mainland China; uses cookies; subject to Google's privacy policy.
- Baidu Analytics — loaded for visitors inside mainland China; uses cookies; subject to Baidu's privacy policy.
- Adsterra — currently in use to serve banner and native ads. Adsterra may set its own cookies. We do not enable push, popunder, or social-bar ad formats.
- MaxMind GeoLite2 — a static database we download and query locally. MaxMind does not see your IP from us.
- ip-api.com — used as a fallback for ISP and region naming, primarily for Chinese-network IPs.
4. Retention
- Server access logs (including IP): up to 30 days, then permanently deleted
- Aggregated daily counts (no IP, no PII): retained indefinitely for trend analysis
- IP correction reports: kept as long as the IP is in our database (we need them to justify the correction)
- Cache of geolocation lookups: refreshed at least every 30 days
5. What we don't do
- We don't sell or share your data with data brokers.
- We don't build a per-user profile across sessions for our own purposes.
- We don't run cross-site tracking pixels or fingerprinting scripts.
- We don't require accounts, emails, or any identifying information to use the service.
6. Your rights
Because we don't link IPs to accounts and we delete server logs within 30 days, we have very little data tied to "you" in the first place. That said:
- You can ask us to delete any logs containing a specific IP. Send the IP and a brief note via the channels in §8; we'll process it within a few business days.
- You can ask for a correction of any geolocation entry for a specific IP, with or without using the in-page Report button.
- EU/UK residents have rights under GDPR / UK GDPR. We act as controller for the data we collect; if you wish to file a complaint with a supervisory authority, you can do so directly.
7. Children
IPconf is not directed at children under 13. We don't knowingly collect personal data from children. If you believe we have, please contact us and we'll delete it.
8. Contact
For any privacy-related question, correction request, or deletion request, use the Report button on any IP page (for IP-specific issues), or contact us via the channels listed on the About page.
9. Changes
We will update this page when our practices change. The "Last updated" date at the top reflects the most recent change. Major changes will also be noted in our changelog.