How We Treat Your Data (Privacy Policy)
At IPOK, privacy is not a marketing tagline — it is a foundational baseline of our system architecture. Here are our core commitments to you.
Updated September 7, 2026 · ipok.io
🛡️ Limited Operational Retention, No Account Profiles
IPOK requires no account and does not attach lookups to a name, email, or account, but the service is not “data not collected.” Cloudflare Workers invocation logs may contain the requester IP, full request URL (including a target IP for custom lookups), status, timestamp, and performance metadata. Cloudflare documents Workers Logs retention of 3 days on Free plans and 7 days on Paid plans; the actual period follows the plan in effect. IPOK also keeps an instance-local one-minute requester-IP burst bucket (IPv6 grouped to /64), a requester-IP/UTC-day quota bucket, and shared result caches keyed by target. Expired minute buckets are pruned during later traffic and capped at 10,000 keys per instance; daily buckets older than 3 days are deleted lazily; risk-source entries are normally used for 72 hours with stale fallback up to 7 days, then become ineligible and are physically deleted lazily; auxiliary BGP, WHOIS, CIDR, and segment responses are publicly cached for no more than one hour (empty reverse-IP results for five minutes; badges for at most five minutes). These records are not joined into an account profile, but they can be linked by source IP. A separate daily referrer table counts one hit only when a page navigation carries an external Referer; it stores the UTC date, the Referer hostname, and a count, with no path, query string, source IP, user agent, or timestamp. Writes are capped at 2,000 per UTC day, and rows are kept for about 400 days, then physically deleted lazily on later writes.
📱 Saved iOS Results and Comparisons
From iOS app 1.7, a result is saved only after you tap Save and explicitly confirm. Up to 20 results can be saved, including the full IP address, ASN, country code, risk score and risk-signal flag, total and successful source counts, measurement and save times, and stale-result and own-IP/custom-lookup markers. History stays on this device: it is not automatically recorded, uploaded, or synced across devices, and its directory is excluded from system backups. In Saved results, you can delete individual records or clear all records; both require confirmation. Comparison summaries remove the IP address, ASN, and country. Only when you choose to share is the summary passed to your selected sharing service, whose privacy policy applies. Local history does not change the checks' network requests or the server and third-party data handling described on this page.
📶 Speed-Test Sessions and Request Bodies
The website and iOS app obtain a random same-origin speed-test session bound to the requester IP (IPv6 grouped to /64). D1 stores the requester key, token, logical expiry, request count, and byte count. A session is logically valid for 10 minutes; expired rows are physically deleted lazily during later traffic. Upload bodies are read only for the transfer test and then discarded. Download/upload speed and latency are calculated in the browser or on the device and are not stored by IPOK. Request metadata still follows the Cloudflare log period above.
🧩 Interface-Triggered WebRTC and DNS Checks
On the website, a WebRTC test runs only after you tap its control. In the iOS app, opening the Leak tab automatically starts one test, and leaving cancels work that is still waiting. The website contacts Google and Cloudflare public STUN services; the iOS app uses Google STUN and asks the system resolver for six one-time bash.ws DNS subdomains. Those services receive the source-network information needed to perform the checks. The observed STUN address is compared only in the browser or on the device and is not sent to IPOK. Separately, after the website's main IP check succeeds, the browser automatically contacts IPOK's other-stack endpoint to display that exit IP, but does not automatically call the batch-lookup API. IPOK does not create or persist an application-level v4/v6 pairing record.
🔍 Fully Traceable Multi-Source Logic
We display the source rows and signals returned for a lookup side-by-side, then document IPOK's weights and score floors. This makes IPOK's aggregation reproducible; it does not make the third-party providers' proprietary collection or scoring algorithms transparent.
🍪 No Session Replay or Tracking Cookies
Microsoft Clarity has been removed. IPOK loads no third-party ad or ad-tracking scripts. The website and app may show clearly labeled affiliate recommendations; the app selects an offer on-device from the current risk or speed result, but loads no merchant tracking script and sends no separate click beacon before a click. Cloudflare processes invocation logs, security metadata, and cookieless aggregate metrics as described above. The Subnet Sprint leaderboard publicly stores a chosen name, score, correct count, duration, and submission time and serves only the latest 40 UTC dates; older D1 rows are removed lazily on the next leaderboard submission, so no-submission periods defer cleanup, while legacy KV boards expire under their original 40-day TTL. Leaderboard submissions and reads use separate 20/120-per-UTC-day counters derived from the requester IP or IPv6 /64. The other three game APIs return only the latest 14 days of aggregate runs, shares, returning-play counts, and numeric summaries; rows from the 121st UTC day and earlier are likewise removed on the next statistics access. Game events contain no IPOK account or application-level source IP and are not linked to lookup records; the chosen name, interface preferences, local game progress and records, first-play dates, and the current day's Subnet result remain in localStorage. Since 2026-09-06, the website runs a silent Cloudflare Turnstile check (no visible challenge) before its first /api/ip call; on success IPOK sets two functional cookies: ipok_s (HttpOnly, 1 hour, bound to your IP /64, sent only to /api) and ipok_pv (a marker, 1 hour). They are not used for cross-site tracking or profiling. The verification script and challenge are handled by Cloudflare at challenges.cloudflare.com under the Cloudflare Turnstile Privacy Addendum (see the third-party list below). A failed or unloaded verification never rejects a lookup; it only makes the commercial risk sources read from cache.
Third-Party Services and Data Flows
IP-risk lookups, interactive network tests, and some tools contact the services below. Depending on the feature, they receive a target IP, domain, or request-source information. Review their respective privacy policies:
- •ip-api & ipapi.is — Geolocation routing and autonomous system (ASN) retrieval
- •IPinfo — Fallback geolocation/ASN lookup (used only when ip-api is unavailable)
- •proxycheck.io — Proxy, VPN and blocklist detection flags, subject to the shared-cache and stale-fallback policy
- •StopForumSpam — Forum and signup spam address database
- •AbuseIPDB — Community-reported global spam and threat records, subject to the shared-cache and stale-fallback policy
- •Scamalytics — Fraud scoring and commercial hosting ASN classification
- •RIPEstat & RDAP — every main check sends the target IP to rdap.org for registration data (without a shared cache) and to RIPEstat for routing history; the BGP card also requests a snapshot, and only a snapshot cache miss sends target IP/ASN again. The standalone ASN tool connects directly, exposing the input and source-network information
- •HackerTarget — each report requests a reverse lookup; only a shared-cache miss makes the Worker send the target IP to HackerTarget
- •bash.ws — a manual website DNS test has the Worker obtain/read a one-time ID and the browser request eight HTTPS image subdomains; opening the iOS Leak tab obtains a one-time ID and asks the system resolver for six DNS subdomains. bash.ws receives the test ID, source network, and standard request metadata; website requests send no page Referrer
- •Google / Cloudflare public STUN — the website contacts Google and Cloudflare after you manually start WebRTC testing; the iOS app contacts Google STUN when you open the Leak tab
- •Cloudflare DoH — each IPv4 report makes the Worker send five DNSBL queries derived from the target IP; standalone DNS, PTR, mail-record, and DNSBL tools connect directly from the browser
- •M-Lab — receives bandwidth tests only after you start a speed test and records IP and speed in its public research dataset
- •Regional AWS endpoints — receive browser latency probes only after you start a speed test
- •OpenStreetMap — the map asks the browser for lazy loading, but the browser decides when to load it; a direct load exposes visitor exit IP and target coordinates, with no page Referrer
- •Affiliate merchants — contacted directly only after you click a clearly labeled recommendation; the merchant receives an affiliate identifier and standard request metadata, while IPOK loads no merchant ad-tracking script before the click
- •Cloudflare — CDN, Workers, security, and Turnstile human verification (runs silently before the website calls /api/ip, governed by the Cloudflare Turnstile Privacy Addendum at https://www.cloudflare.com/turnstile-privacy-policy/); invocation logs may record source IP, full request URL, status, timestamp, and performance metadata for 3 or 7 days depending on plan
Privacy Choices and Requests
Stop using the site or uninstall the app to stop future user-initiated requests. IPOK has no account system, so it cannot search by a name or account; short-lived operational logs and caches that cannot be reliably isolated expire under the periods above. To ask a question or request deletion of data IPOK can identify and control, email us with the approximate time and feature involved. Do not send identity documents or other sensitive information unless we specifically need it to handle the request.
Email a privacy request: hello@ipok.io