Legal

Privacy Policy

This Privacy Policy describes what personal data Lookip collects, how we use and retain it, who we share it with, and the rights you have over it. It applies to everyone who interacts with the Service — website visitors, registered users, API callers, and the data subjects whose information may be processed through it.

Effective date: May 11, 2026 · Last updated: August 12, 2026

1. Overview

Lookip operates https://lookip.io, the dashboard, the public lookup tools, and the IP intelligence API at api.lookip.io (collectively, the “Service”). This Privacy Policy supplements our Terms of Service and uses the same defined terms.

We try to keep this policy plain and complete. If anything is unclear, write to [email protected] and we will explain.

2. Our role

Under the EU General Data Protection Regulation, the UK GDPR, and equivalent laws, we act in two roles:

  • Controller — for the data we collect about you directly: your account, billing, sessions, support correspondence, and the way you use the Service.
  • Processor — for data you put into the Service about other people, such as the optional context payload you attach to a lookup, contacts you save, or end-user IPs you query on behalf of your own application. You remain the controller of that data and decide its purposes and means; we process it on your instructions.

California and other U.S. state laws use different terms (“business” vs “service provider”) — the substantive distinction is the same.

3. Data we collect

The table below describes what we collect and where it comes from.

CategoryWhat it containsWhere it comes from
Account dataName, email address, hashed password (bcrypt), role, and account creation/update timestamps. If you sign in with Google, we receive your Google profile and store your email address, your name, and whether Google reports the address as verified. Your Google profile picture is released to us by the sign-in scope but we do not store it, and we do not store your Google account id — we match you by email address. We do not currently operate an email-verification flow of our own, so accounts created with a password are not marked verified.Provided by you when you sign up or update your profile.
API key metadataKey label, public prefix (the first characters of the key), a SHA-256 hash of the key, status (active/revoked), and timestamps including last-used time. We do not store the key itself, so the dashboard can show it to you once and never again — see Security below.Generated when you create or rotate a key in the dashboard.
Billing dataStripe customer ID, payment and checkout identifiers, your credit balance and ledger, and — if you save a card — its brand, last four digits, and expiry month/year. Card numbers, CVCs, and bank details are collected and held by Stripe; they never reach our servers.Collected by Stripe on our behalf when you top up or save a payment method.
Lookup logsEach successful or failed lookup is logged with: the API key id, the queried IP, response status, response latency, the enrichment response, and a timestamp. We use these to render your history in the dashboard, meter credit, support you, and detect abuse. These records are retained indefinitely — see Retention below.Created when you call the API or use the public lookup tools while signed in.
Optional context payloadIf you choose to attach a context object to a lookup (e.g. userAgent, email, username, firstName, lastName, phone, address, city, region, country, postal, note, tags, extra), we store those values on the lookup record so you can see them in your history. Context is never forwarded to the upstream IP data provider.Provided by you on a per-request basis. Entirely optional.
Contacts directoryA contacts API exists (IP, email, username, name, phone, address, note, tags, extra JSON), scoped to your account. There is currently no dashboard interface for it, so unless you have called the API directly you have no contacts stored.Provided by you, via the API, if you use it.
Lookup data snapshotsTo serve repeat lookups quickly we keep a snapshot of the upstream response for each IP we have queried recently. The snapshot is keyed by IP only and contains no information about which Lookip customer queried it.Returned by the upstream IP intelligence provider.
Visitor IP & request metadataWhen you visit lookip.io or use a public tool such as VPN check, our hosting and CDN providers receive your IP address, user agent, the URL requested, referrer, and timestamps. Bot-mitigation services may inspect these to issue a challenge.Automatically collected at the network layer.
Cookies & local storageFour first-party cookies at most: a httpOnly session cookie (signed JWT) when you sign in; a short-lived state cookie during Google sign-in; a one-hour cookie recording which IP address you passed a bot challenge for, so a public tool does not re-challenge you; plus any token set by Cloudflare Turnstile itself. Your theme preference is kept in your browser’s local storage, not a cookie, and never reaches our servers. We do not use third-party advertising or cross-site tracking cookies.Set by us or by Cloudflare Turnstile on visit / on login.
CommunicationsEmail you send to [email protected] and any replies, including support and sales threads. If you use the form on /contact, we store the name, email address, optional company name and message you submit, together with the IP address the submission came from, in our own database so we can reply and so we can tell a genuine enquiry from automated abuse.Provided by you when you contact us.

We do not knowingly collect special-category data (such as data revealing health, religion, sexual orientation, political opinions, biometric or genetic data) and we ask that you do not place such data into the optional context payload.

4. How we use data

  • Provide the Service — authenticate you, render the dashboard, generate API keys, run lookups, return enrichment data, meter credit.
  • Bill correctly — take payment for credit, debit your balance per call, and reconcile with Stripe. Stripe may send you its own payment receipts; we do not send email ourselves.
  • Keep the Service safe — rate-limit, detect and mitigate abuse, bot traffic, credential stuffing, and repeat harvesting of the signup credit.
  • Improve the Service — measure aggregate request volume, latency, error rates, and feature usage to guide product decisions.
  • Support you — respond to your emails and dashboard messages, troubleshoot, and follow up.
  • Comply with law — meet our legal, tax, accounting, and regulatory obligations, and respond to valid legal requests.

We do not sell personal data. We do not use the data you submit through the API (including queried IPs or context payloads) to train machine-learning models.

6. Cookies & similar tech

We use a small number of strictly first-party cookies and similar storage:

  • Session cookie — an httpOnly, secure JWT cookie set after you sign in. It identifies your session and is required for authenticated routes.
  • Google sign-in state — a short-lived (10 minute) httpOnly cookie used only during a Google sign-in, to prevent cross-site request forgery and to remember where to send you afterwards.
  • Challenge result — a one-hour httpOnly cookie recording which IP address you completed a bot challenge for, so that a public lookup tool does not challenge you twice for the same address. Note this stores the address you looked up, which may not be your own.
  • Cloudflare Turnstile — challenge tokens that prove a visitor is not an abusive bot. These are set on lookip.io by Cloudflare on our behalf.

Your light/dark theme preference is stored in your browser's local storage, not in a cookie. It stays on your device and is never sent to us.

We do not run third-party advertising trackers, cross-site tracking pixels, or behavioural analytics that profile you across the web. If we add an opt-in analytics tool in the future, we will update this policy and respect your preference.

7. Sharing & sub-processors

We share personal data only with vendors that help us run the Service, and only as much as they need. Each is bound by a written agreement to handle data securely and only on our instructions.

Sub-processorPurposeData sharedRegion
Upstream IP intelligence providerWe forward the queried IP address to a third-party data provider to obtain enrichment fields (geolocation, ASN, network classification). No Customer-supplied context is forwarded.The queried IP address only.United States
Stripe, Inc.Payment processing for credit top-ups, including saved cards and off-session auto-recharge. Receives card and billing details directly from you.Name, email, card details (held by Stripe, not us), billing address, transaction history.United States & global
Cloudflare, Inc. (Turnstile)Bot mitigation on public lookup tools and the login flow, to prevent abuse without using CAPTCHAs that target individuals.IP address, user agent, challenge token, basic browser signals.Global edge
Google LLC (Sign-in with Google)Optional OAuth identity provider, used only if you choose to sign in with Google.Google releases your account id, email address, name, and profile picture to us at sign-in. We store only the email address, name, and verified-email flag.United States & global
Hosting & infrastructure providersRun the web application, API, database, and supporting infrastructure. Process all traffic at the network layer.All data we hold, encrypted in transit, only to the extent needed to serve requests.A single dedicated server in Thailand, behind Cloudflare’s global edge

We may also disclose personal data: (a) to comply with applicable law or a valid legal request; (b) to protect the rights, property, or safety of Lookip, our customers, or others, including to prevent fraud or security incidents; (c) in connection with a merger, acquisition, financing, reorganisation, or sale of assets, in which case we will require the recipient to honour this policy. We do not sell personal data and we do not share it for cross-context behavioural advertising.

8. International transfers

Our application and database are hosted on a single dedicated server in Thailand. Our sub-processors operate globally — Cloudflare and Stripe in particular process data across multiple regions including the United States and the European Union. If you are located elsewhere, using the Service means your data is transferred to and processed in Thailand and in those sub-processors' regions.

Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum / Swiss equivalent) together with supplementary measures such as encryption in transit and at rest, access controls, and limited data minimisation. You may request a copy of the relevant transfer mechanism by writing to [email protected].

9. Data retention

We want to be straightforward about this rather than quote periods we do not yet enforce: we do not currently run automated deletion. The records below are kept until we delete them in response to a request from you, or as part of a future retention policy. If a defined retention period matters to you, tell us and we will action deletion manually.

  • Account data — kept while your account is active, and after closure until you ask us to erase it, except where a longer period is required by law (for example, tax records).
  • Billing records— retained for the period required by applicable tax and accounting law (typically 6–10 years). We cannot delete these on request while that obligation applies.
  • Lookup history & context payloads — retained indefinitely at present. They are not purged automatically and there is not yet a delete control in the dashboard. Email us and we will delete them for you.
  • IP data snapshots — refreshed when an address is looked up again and overwritten in place. A stale snapshot is not deleted, only replaced. These are keyed by IP address alone and record nothing about which customer queried them.
  • Server & security logs — held by our hosting and CDN providers under their own retention settings.
  • Support correspondence — kept for as long as needed to maintain the support relationship, and afterwards as a business record.

We are aware this is weaker than it should be, and building automated retention and self-serve deletion is on our roadmap. Until then, a request to [email protected] is the reliable route, and we will act on it.

We may keep aggregated, anonymised data (such as request counts per region or per hour) indefinitely; it no longer identifies you and is not personal data.

10. Security

We take security seriously and apply the controls reasonable for a service of this size and risk profile, including:

  • TLS for all traffic between you and the Service.
  • Passwords stored using bcrypt with a per-user salt — never in clear text.
  • API keys stored as a SHA-256 hash — never in clear text. A key is shown to you once, when you create or regenerate it. We cannot read it back, which also means we cannot recover it for you: a lost key is replaced, not retrieved. Keys are accepted only in the Authorization header, which our request logs do not record. A key placed in a URL query string instead is refused — but the URL still reaches our web server's log before we can refuse it, so treat any key sent that way as exposed and regenerate it.
  • Session tokens issued as signed JWTs in httpOnly, secure cookies.
  • Bot mitigation through Cloudflare Turnstile on public tools.
  • Principle of least privilege for production access, with audit logging.
  • All traffic encrypted in transit (TLS). We do not currently claim encryption at rest for the database volume, and we do not yet operate automated off-site backups — both are on our roadmap and we would rather say so than imply protection we have not built.

No internet-connected service can be made fully secure. If we ever become aware of a security incident affecting your personal data, we will notify affected users and regulators as required by applicable law.

11. Your rights (EEA / UK / Switzerland)

Subject to applicable law and verification of your identity, you have the right to:

  • request access to your personal data and a copy of it;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data (subject to our right to keep data necessary for legal compliance, security, or to assert legal claims);
  • request restriction of, or object to, certain processing;
  • request portability of data you have provided to us in a structured format;
  • withdraw consent where processing is based on consent (without affecting prior processing);
  • lodge a complaint with your local data-protection authority — though we hope you will write to us first so we can put things right.

To exercise any of these rights, email [email protected] from the address associated with your account. We aim to respond within thirty (30) days.

12. U.S. state rights

Residents of California, Colorado, Connecticut, Virginia, Utah, and other U.S. states with comprehensive privacy laws have rights similar to those described above, including the right to know what personal information we collect, the right to delete, the right to correct, the right to opt out of the “sale” or “sharing” of personal information for targeted advertising, and the right to non-discrimination for exercising these rights.

We do not sell personal information and we do not share personal information for cross-context behavioural advertising. Submit any request to [email protected]. We may need to verify your identity before responding; an authorised agent acting on your behalf must provide proof of authorisation.

13. Children

The Service is intended for developers and operators and is not directed to children under sixteen (16). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. People whose IPs are queried

If your IP address has been queried through the Service by one of our customers, Lookip acts as a processoron that customer's behalf — the customer determines the purposes and means of the processing, not us. We hold a snapshot of the enrichment record indexed by IP, and we hold a log of the lookup scoped to the customer's account.

We do not have a way to look you up by your real-world identity and we do not receive your name, email, or any other personal identifier from our customers unless the customer chose to attach a context payload to a lookup. To exercise rights over that data you should contact the customer (the controller). If you cannot identify the customer, write to us at [email protected] and we will assist where we reasonably can.

15. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. For material changes we will give reasonable advance notice on this page. We do not currently send email notifications, so please treat this page as the notice channel. Continued use of the Service after the change takes effect constitutes acceptance of the updated policy.

16. Contact

Privacy questions, requests, and complaints should be sent to [email protected]. If you prefer postal mail, request a postal address by email and we will provide one.