Your email address, password hash, account dates and email-verification status. IPGetter never stores your plaintext password.
Privacy without the mystery.
This notice explains what IPGetter processes when you use the website, create an account, use the browser terminal or call the developer API.
Last updated: 19 September 2026Who is responsible for your data
IPGetter.com is the service responsible for the personal data described in this notice. Privacy questions and data-rights requests can be sent to privacy@ipgetter.com.
What IPGetter collects
One-way hashes derived from session identifiers, IP addresses and user agents are used for login protection, session security and abuse controls.
API-key names, key identifiers, one-way key hashes, request counts and last-used times. Full API secrets are shown once and are not recoverable by IPGetter.
When signed in, IPGetter stores your recent terminal commands so history can follow your account between devices. Guest command history is page-local; lightweight analytics may retain only the command category (for example, dns or ssl), not the full guest command or target.
Page, device/browser family, approximate country, referrer, engagement signals and a pseudonymous visitor identifier that rotates monthly. IPGetter analytics do not store raw visitor IP addresses.
Targets such as IP addresses, domains, URLs and ports are processed to perform the network check you request. Depending on the tool, IPGetter may query DNS, RDAP or the destination service itself.
If you use the support form, IPGetter stores your reply email, category, subject, message, account link when signed in, and one-way client hashes used for abuse prevention and support security.
Why it is used
IPGetter processes data to provide requested tools and account features, authenticate users, secure accounts and API keys, enforce fair-use limits, prevent abuse, troubleshoot problems and understand whether the service is useful. Depending on the activity, this processing is generally necessary to provide the service you request or supports IPGetter's legitimate interests in operating, securing and improving the service.
Analytics and privacy controls
IPGetter uses lightweight first-party analytics rather than a third-party analytics platform. The service records limited technical and engagement information to understand which pages and tools are useful, detect automated traffic and improve the site.
You can object to this first-party analytics collection at any time from the Cookies and privacy controls page. The opt-out itself is stored as a small preference cookie so IPGetter can remember your choice.
How long data is kept
- First-party analytics event files are automatically removed after 90 days.
- Failed/successful authentication security events are routinely removed after 30 days.
- Signed-in terminal history is limited to the most recent 250 commands per account and is deleted with the account.
- Account, API-key metadata and account usage remain while the account is active and are deleted when the account is deleted, except where a limited record must be retained for security or legal reasons.
- Password-reset links expire after 60 minutes. Email-verification links expire after 24 hours.
- Support requests are normally retained for up to 12 months after resolution so follow-up questions and recurring issues can be understood, unless a longer period is reasonably needed for security or legal purposes.
Like most websites, the hosting platform may also maintain standard server/access logs for operational and security purposes under the hosting environment's retention settings.
Who data is shared with
IPGetter uses hosting and email-delivery infrastructure to run the service. Network tools may communicate with public DNS resolvers, authoritative RDAP services or the host/domain you ask IPGetter to inspect. Core IP geolocation and ASN enrichment is performed from local databases on the IPGetter server rather than sending every visitor IP to a live geolocation API.
IPGetter does not sell personal data to advertisers.
Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or object to processing of your personal data, and to receive certain data in a portable format. You can delete your IPGetter account from the account page. For other requests, contact privacy@ipgetter.com.
You can also raise a concern with the UK Information Commissioner's Office if you are unhappy with how personal data has been handled.
Security
Passwords are stored using PHP's password hashing functions. API secrets are stored only as one-way hashes. Signed-in sessions use secure HttpOnly cookies, CSRF protection and server-side session records. Authentication and API endpoints are rate limited.
Changes to this notice
This notice will be updated when IPGetter materially changes how personal data is used. The date at the top shows the latest revision.