Privacy
Privacy policy
Last updated: 19 July 2026
This is a neutral, privacy-first connection and privacy checkup. It records network-level facts about connections — not people. This page states exactly what is recorded, why, how long it is kept, and the rights you have. Nothing here is collected covertly: the checkup runs automatically when you open the page, and every field it records is disclosed below.
Where a signal cannot be measured honestly in the browser (for example a DNS resolver), we report it as unavailable rather than record a guess.
What runs, and when
Detection runs client-side in your browser and starts automatically when you open the checkup page. We do not run hidden or covert probes beyond this disclosed checkup, and everything it does is described on this page. The server sees your request the way any website does, and reads the exit facts from the edge of our network.
What we record
For each checkup you run, we store a single network-level observation containing only these fields:
- A coarse timestamp, truncated to the hour — not a precise time.
- Your public IP address (a network-level address, treated as personal data under the GDPR).
- The ASN (network operator number) and the country the IP is registered to.
- The IP type: residential, datacenter or mobile.
- Proxy, VPN and Tor flags derived from IP intelligence.
- Leak booleans for WebRTC, DNS and IPv6 (true / false / unknown only — never the leaked addresses themselves).
- Timezone-mismatch and language-mismatch booleans.
- A coarse connection-speed bucket (for example fast, medium or slow).
- A salted hash of your browser fingerprint — never the raw fingerprint.
- A coarse platform label (for example “windows” or “android”) — never your raw user-agent string.
- The computed exposure score.
What we never record
We do not store your raw browser fingerprint, your raw user-agent, the IP addresses surfaced by a WebRTC or IPv6 leak, your browsing history, or any name, email or account identifier. Leak checks send only a true/false flag; the addresses they find stay in your browser.
Aggregates we derive (the crowd dataset)
From these observations we maintain network-level counters that are the tool’s crowdsourced intelligence and power the public /ip, /asn and /country pages:
- Per-IP: number of checks, first/last seen, VPN ratio, a count of distinct fingerprint hashes seen in the last 7 days, and a risk score.
- Per-ASN: checks, distinct IPs, proxy and VPN ratios, and speed distributions.
- Per-country: checks, distinct IPs, proxy and VPN ratios.
How long we keep it
Raw observations are short-lived: each carries a time-to-live of 30 days from its (hour-coarse) timestamp, after which it is evicted. Per-IP aggregates also carry a retention window so stale IPs are evicted over time. Per-ASN and per-country counters are network-level rollups (a few hundred to ~110k rows) and are kept while they remain useful. We rely on the aggregates, not the raw events, for durable insight.
Analytics
We may emit a sampled analytics event per checkup containing only network-level fields — country, ASN, IP type, the proxy/VPN/Tor flags and the exposure score. It contains no IP address and no fingerprint, is sampled rather than exact, and is used only for aggregate trends, never as a system of record.
IP addresses and the GDPR
Under the GDPR a public IP address can identify an individual, so we treat it as personal data. We store it strictly at the network level, minimise what we keep, hash the one sensitive signal (your fingerprint) with a salt, keep raw records for only 30 days, and never link an IP to your identity or build a personal profile from it.
Lawful basis
We process this network-level data under the lawful basis of legitimate interest (Article 6(1)(f)): operating and securing the tool and building network-level IP/ASN intelligence that is the point of the service. We have balanced that interest against your rights, and consider it proportionate because the data is network-level and minimised, the sensitive fingerprint is only ever a salted hash, raw records are short-lived, and we do no profiling or cross-site tracking.
What we never do
No personal profiling. No cross-site or cross-session tracking. No covert collection — the checkup runs automatically when you open the checkup page and is fully disclosed here. We do not sell your data. Fingerprints exist only as salted hashes used to estimate uniqueness, and cannot be reversed into your original browser traits.
Your rights
You have the right to access, rectification, erasure, restriction of processing, and objection to processing under the GDPR. Because we store data only at the network level and cannot link it to your identity, exercising some rights requires you to identify the specific IP address and approximate time so we can locate the relevant records. Note that raw observations are in any case automatically deleted within 30 days.
Changes and contact
We may update this policy as the tool evolves; the “last updated” date above reflects the current version. For any privacy question or to exercise your rights, contact privacy@ip00.cc.