1. Overview
Lookip operates https://lookip.io, the dashboard, the public lookup tools, and the IP intelligence API at api.lookip.io (collectively, the “Service”). This Privacy Policy supplements our Terms of Service and uses the same defined terms.
We try to keep this policy plain and complete. If anything is unclear, write to [email protected] and we will explain.
2. Our role
Under the EU General Data Protection Regulation, the UK GDPR, and equivalent laws, we act in two roles:
- Controller — for the data we collect about you directly: your account, billing, sessions, support correspondence, and the way you use the Service.
- Processor — for data you put into the Service about other people, such as the optional context payload you attach to a lookup, contacts you save, or end-user IPs you query on behalf of your own application. You remain the controller of that data and decide its purposes and means; we process it on your instructions.
California and other U.S. state laws use different terms (“business” vs “service provider”) — the substantive distinction is the same.
3. Data we collect
The table below describes what we collect and where it comes from.
| Category | What it contains | Where it comes from |
|---|---|---|
| Account data | Name, email address, hashed password (bcrypt), role, and account creation/update timestamps. If you sign in with Google, we receive your Google profile and store your email address, your name, and whether Google reports the address as verified. Your Google profile picture is released to us by the sign-in scope but we do not store it, and we do not store your Google account id — we match you by email address. We do not currently operate an email-verification flow of our own, so accounts created with a password are not marked verified. | Provided by you when you sign up or update your profile. |
| API key metadata | Key label, public prefix (the first characters of the key), a SHA-256 hash of the key, status (active/revoked), and timestamps including last-used time. We do not store the key itself, so the dashboard can show it to you once and never again — see Security below. | Generated when you create or rotate a key in the dashboard. |
| Billing data | Stripe customer ID, payment and checkout identifiers, your credit balance and ledger, and — if you save a card — its brand, last four digits, and expiry month/year. Card numbers, CVCs, and bank details are collected and held by Stripe; they never reach our servers. | Collected by Stripe on our behalf when you top up or save a payment method. |
| Lookup logs | Each successful or failed lookup is logged with: the API key id, the queried IP, response status, response latency, the enrichment response, and a timestamp. We use these to render your history in the dashboard, meter credit, support you, and detect abuse. These records are retained indefinitely — see Retention below. | Created when you call the API or use the public lookup tools while signed in. |
| Optional context payload | If you choose to attach a context object to a lookup (e.g. userAgent, email, username, firstName, lastName, phone, address, city, region, country, postal, note, tags, extra), we store those values on the lookup record so you can see them in your history. Context is never forwarded to the upstream IP data provider. | Provided by you on a per-request basis. Entirely optional. |
| Contacts directory | A contacts API exists (IP, email, username, name, phone, address, note, tags, extra JSON), scoped to your account. There is currently no dashboard interface for it, so unless you have called the API directly you have no contacts stored. | Provided by you, via the API, if you use it. |
| Lookup data snapshots | To serve repeat lookups quickly we keep a snapshot of the upstream response for each IP we have queried recently. The snapshot is keyed by IP only and contains no information about which Lookip customer queried it. | Returned by the upstream IP intelligence provider. |
| Visitor IP & request metadata | When you visit lookip.io or use a public tool such as VPN check, our hosting and CDN providers receive your IP address, user agent, the URL requested, referrer, and timestamps. Bot-mitigation services may inspect these to issue a challenge. | Automatically collected at the network layer. |
| Cookies & local storage | Four first-party cookies at most: a httpOnly session cookie (signed JWT) when you sign in; a short-lived state cookie during Google sign-in; a one-hour cookie recording which IP address you passed a bot challenge for, so a public tool does not re-challenge you; plus any token set by Cloudflare Turnstile itself. Your theme preference is kept in your browser’s local storage, not a cookie, and never reaches our servers. We do not use third-party advertising or cross-site tracking cookies. | Set by us or by Cloudflare Turnstile on visit / on login. |
| Communications | Email you send to [email protected] and any replies, including support and sales threads. If you use the form on /contact, we store the name, email address, optional company name and message you submit, together with the IP address the submission came from, in our own database so we can reply and so we can tell a genuine enquiry from automated abuse. | Provided by you when you contact us. |
We do not knowingly collect special-category data (such as data revealing health, religion, sexual orientation, political opinions, biometric or genetic data) and we ask that you do not place such data into the optional context payload.
4. How we use data
- Provide the Service — authenticate you, render the dashboard, generate API keys, run lookups, return enrichment data, meter credit.
- Bill correctly — take payment for credit, debit your balance per call, and reconcile with Stripe. Stripe may send you its own payment receipts; we do not send email ourselves.
- Keep the Service safe — rate-limit, detect and mitigate abuse, bot traffic, credential stuffing, and repeat harvesting of the signup credit.
- Improve the Service — measure aggregate request volume, latency, error rates, and feature usage to guide product decisions.
- Support you — respond to your emails and dashboard messages, troubleshoot, and follow up.
- Comply with law — meet our legal, tax, accounting, and regulatory obligations, and respond to valid legal requests.
We do not sell personal data. We do not use the data you submit through the API (including queried IPs or context payloads) to train machine-learning models.
5. Legal bases (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for, and to bill you accurately.
- Legitimate interests — to keep the Service secure, prevent abuse, understand how the product is used, and communicate operational changes. We balance these interests against your rights and freedoms.
- Legal obligation — to retain records required by tax, accounting, and other applicable laws, and to respond to lawful requests.
- Consent — we do not currently rely on consent for anything, because we run no analytics and send no marketing email. If we introduce either, we will ask first and you will be able to withdraw consent at any time.
8. International transfers
Our application and database are hosted on a single dedicated server in Thailand. Our sub-processors operate globally — Cloudflare and Stripe in particular process data across multiple regions including the United States and the European Union. If you are located elsewhere, using the Service means your data is transferred to and processed in Thailand and in those sub-processors' regions.
Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum / Swiss equivalent) together with supplementary measures such as encryption in transit and at rest, access controls, and limited data minimisation. You may request a copy of the relevant transfer mechanism by writing to [email protected].
9. Data retention
We want to be straightforward about this rather than quote periods we do not yet enforce: we do not currently run automated deletion. The records below are kept until we delete them in response to a request from you, or as part of a future retention policy. If a defined retention period matters to you, tell us and we will action deletion manually.
- Account data — kept while your account is active, and after closure until you ask us to erase it, except where a longer period is required by law (for example, tax records).
- Billing records— retained for the period required by applicable tax and accounting law (typically 6–10 years). We cannot delete these on request while that obligation applies.
- Lookup history & context payloads — retained indefinitely at present. They are not purged automatically and there is not yet a delete control in the dashboard. Email us and we will delete them for you.
- IP data snapshots — refreshed when an address is looked up again and overwritten in place. A stale snapshot is not deleted, only replaced. These are keyed by IP address alone and record nothing about which customer queried them.
- Server & security logs — held by our hosting and CDN providers under their own retention settings.
- Support correspondence — kept for as long as needed to maintain the support relationship, and afterwards as a business record.
We are aware this is weaker than it should be, and building automated retention and self-serve deletion is on our roadmap. Until then, a request to [email protected] is the reliable route, and we will act on it.
We may keep aggregated, anonymised data (such as request counts per region or per hour) indefinitely; it no longer identifies you and is not personal data.
10. Security
We take security seriously and apply the controls reasonable for a service of this size and risk profile, including:
- TLS for all traffic between you and the Service.
- Passwords stored using bcrypt with a per-user salt — never in clear text.
- API keys stored as a SHA-256 hash — never in clear text. A key is shown to you once, when you create or regenerate it. We cannot read it back, which also means we cannot recover it for you: a lost key is replaced, not retrieved. Keys are accepted only in the Authorization header, which our request logs do not record. A key placed in a URL query string instead is refused — but the URL still reaches our web server's log before we can refuse it, so treat any key sent that way as exposed and regenerate it.
- Session tokens issued as signed JWTs in httpOnly, secure cookies.
- Bot mitigation through Cloudflare Turnstile on public tools.
- Principle of least privilege for production access, with audit logging.
- All traffic encrypted in transit (TLS). We do not currently claim encryption at rest for the database volume, and we do not yet operate automated off-site backups — both are on our roadmap and we would rather say so than imply protection we have not built.
No internet-connected service can be made fully secure. If we ever become aware of a security incident affecting your personal data, we will notify affected users and regulators as required by applicable law.
11. Your rights (EEA / UK / Switzerland)
Subject to applicable law and verification of your identity, you have the right to:
- request access to your personal data and a copy of it;
- request correction of inaccurate or incomplete data;
- request erasure of personal data (subject to our right to keep data necessary for legal compliance, security, or to assert legal claims);
- request restriction of, or object to, certain processing;
- request portability of data you have provided to us in a structured format;
- withdraw consent where processing is based on consent (without affecting prior processing);
- lodge a complaint with your local data-protection authority — though we hope you will write to us first so we can put things right.
To exercise any of these rights, email [email protected] from the address associated with your account. We aim to respond within thirty (30) days.
12. U.S. state rights
Residents of California, Colorado, Connecticut, Virginia, Utah, and other U.S. states with comprehensive privacy laws have rights similar to those described above, including the right to know what personal information we collect, the right to delete, the right to correct, the right to opt out of the “sale” or “sharing” of personal information for targeted advertising, and the right to non-discrimination for exercising these rights.
We do not sell personal information and we do not share personal information for cross-context behavioural advertising. Submit any request to [email protected]. We may need to verify your identity before responding; an authorised agent acting on your behalf must provide proof of authorisation.
13. Children
The Service is intended for developers and operators and is not directed to children under sixteen (16). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. People whose IPs are queried
If your IP address has been queried through the Service by one of our customers, Lookip acts as a processoron that customer's behalf — the customer determines the purposes and means of the processing, not us. We hold a snapshot of the enrichment record indexed by IP, and we hold a log of the lookup scoped to the customer's account.
We do not have a way to look you up by your real-world identity and we do not receive your name, email, or any other personal identifier from our customers unless the customer chose to attach a context payload to a lookup. To exercise rights over that data you should contact the customer (the controller). If you cannot identify the customer, write to us at [email protected] and we will assist where we reasonably can.
15. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. For material changes we will give reasonable advance notice on this page. We do not currently send email notifications, so please treat this page as the notice channel. Continued use of the Service after the change takes effect constitutes acceptance of the updated policy.
16. Contact
Privacy questions, requests, and complaints should be sent to [email protected]. If you prefer postal mail, request a postal address by email and we will provide one.