Skip to content
IPOK

Trust & Security Statement

Trust & Safety Narrative: Why IPOK is Trustworthy?

In geofencing auditing and network anonymity checks, trust depends on precise disclosure. IPOK builds no account profile and documents the operational logs, quotas, sessions, and caches it actually retains.

Updated September 7, 2026 · ipok.io

🔒 Limited Operational Logs, No Account Profiles

IPOK requires no account and does not attach lookups to a name, email, or account. Cloudflare Workers invocation logs may contain source IP, full request URL, status, timestamp, and performance metadata for 3 or 7 days depending on plan. The application also uses an instance-local one-minute requester-IP burst bucket, a requester-IP daily counter, a 10-minute speed-test session, and shared target caches. Risk-source entries use 72-hour freshness with up to seven-day fallback; auxiliary responses are publicly cached for no more than one hour. Expired D1 rows are physically deleted lazily. A separate daily referrer table counts external referrers by UTC date and Referer hostname only when a page navigation carries one, storing no path, source IP, or user agent, and is retained for about 400 days. See the privacy policy for the complete retention disclosure.

🧩 On-Demand WebRTC Leak Audits

The WebRTC test runs only when you trigger it. Your browser then contacts Google and Cloudflare public STUN services, which receive the source network information required for that request; ICE candidates stay in the browser and are never sent to IPOK. The main IP check separately auto-fetches the other-stack IP but does not automatically call the batch-lookup API. IPOK does not create or persist an application-level v4/v6 pairing record.

🍪 No Session Replay or Tracking Cookies

Microsoft Clarity has been removed. IPOK loads no third-party ad or ad-tracking scripts; the site may show clearly labeled affiliate recommendations. Cloudflare may process security logs and cookieless aggregate operational metrics. The Subnet Sprint leaderboard publicly stores a chosen name, score, correct count, duration, and submission time and serves only the latest 40 UTC dates; older D1 rows are removed lazily on the next leaderboard submission, while legacy KV boards expire under their original 40-day TTL. Leaderboard submissions and reads use separate 20/120-per-UTC-day counters derived from the requester IP or IPv6 /64. The other three games query only the latest 14 days of daily aggregates, and rows from the 121st UTC day and earlier are likewise cleaned on the next statistics access. Game events contain no IPOK account or application-level source IP.

🌐 Fully Traceable Anti-Fraud Signals

IPOK shows the source scores and risk flags returned for this lookup side-by-side and publishes its own weights and score floors, so IPOK's aggregation can be audited. Providers such as AbuseIPDB and Scamalytics still use proprietary collection and scoring methods, and this report cannot prove why a separate payment or login platform blocked an address.

IPOK builds no account profile and does not sell or rent query data. Limited operational logs, quotas, speed-test sessions, and caches are disclosed in the privacy policy. Affiliate recommendations do not affect detection scores.