Privacy policy

Your IP address reaches this site because the internet protocol requires it. We show it back to you, we keep network-level statistics from it, and we never keep the address itself. This page says exactly what happens, in the order it happens.

Who runs this site

whatsmyip.fyi is an independent project. The controller for the purposes of the UK GDPR and the EU GDPR is the operator of whatsmyip.fyi, reachable at hello@whatsmyip.fyi.

An IP address is personal data

A dynamic IP address can be personal data under Recital 30 of the GDPR and under the Court of Justice ruling in Breyer (C-582/14). We treat every address that reaches this site as personal data, including yours.

Lawful basis

  • Showing you your own address, and running the tool you asked for: performance of a contract you requested (Article 6(1)(b)), because that is the entire service you came here for.
  • Rate limiting and abuse prevention: legitimate interests (Article 6(1)(f)). Without it, the lookup and diagnostic tools become a free scanner for other people.
  • Network-level statistics: legitimate interests (Article 6(1)(f)). They carry no identifier and cannot be traced back to you; they exist to make the location estimates on this site less wrong.
  • Advertising, if and when it is switched on: consent (Article 6(1)(a)), collected through a certified consent platform before any ad script loads. See "Cookies" below.

What we see on every request

From the request itself we read: the source IP address, the country, region, city, postal area, approximate coordinates and time zone derived from the routing table, the autonomous system number and name, the location that served the request, the HTTP and TLS versions, the round-trip time of the connection, the User-Agent string and the Accept-Language header. All of it is used to build the response. Everything except the network-level statistics below is then discarded.

What we keep

DataWhyRetention
Your full IP addressNever. We do not write it anywhere.Not kept
Network-level statistics: the first 24 bits of an IPv4 address or the first 48 bits of an IPv6 address, the network number, the approximate location our systems computed, the location that served the request, and coarse latency, counted per dayTo measure how wrong the location estimates are, and to build our own datasetAggregated statistics, kept indefinitely
Rate-limit counters against the same network rangeSo one visitor cannot exhaust a shared quotaRolling minute and day counters that expire on their own
The text you type into the wrong-location form, with the country and city we showed youTo correct the location dataKept with the statistics above, with no name, email or full address
What you type into a lookup, port, DNS or probe toolAnswering the request is the only useNot stored
Short-lived session data for the DNS leak testTo match the resolvers that answered to your test runMinutes, then deleted
Server logs held by our hosting and content delivery providerOperated by them as our processor, not by usTheir standard retention. We do not export them.

The counts are approximate. They are batched before they are written, so a small number of them are lost, and no figure here is an audited total. Nothing in them singles out one visitor: there is no address, no cookie, no user agent and no timestamp finer than a day.

The homepage makes no third-party call. Your address is resolved at the edge and rendered into the HTML. No lookup provider is contacted unless you ask for a full report or use a lookup tool.

Third parties that can receive an IP address

  • Our hosting and content delivery provider. Every request passes through it. It acts as our processor.
  • IP intelligence providers, only on the pages that need them. The full report, /json?full=1, the lookup tools and the privacy flags send the address being looked up to them. Nothing else does.
  • Public DNS resolvers. Used for reverse DNS and DNS lookups. They receive the name being queried, which for reverse DNS contains the address.
  • The regional internet registries. Their RDAP and WHOIS servers receive the address or domain you look up.
  • The map provider, only when you open the map. Until you open the panel yourself, no request goes to it.
  • The advertising network and its consent platform. Only if advertising is switched on, and only after you consent where consent is required.

Cookies and analytics

This site sets no tracking cookie, and no cookie at all today. Your theme choice lives in your browser's local storage and is never sent to us. Our analytics is cookieless and collects no cross-site identifier.

If advertising is switched on, the advertising network sets its own cookies. In the EEA, the UK and Switzerland those scripts will not load until you give consent through a certified consent platform, and you can withdraw consent from the same banner. Outside those regions you will still see an ad-choices control.

Your rights

You can ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Write to hello@whatsmyip.fyi. Be aware of the practical limit: because we never keep your address and the statistics carry no identifier, we usually hold nothing that identifies you, so there is nothing to export or delete. If you have sent us a message or a correction, tell us which one and we will remove it.

You may also complain to your supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority in your member state.

Children

This is a network utility, not a service aimed at children. We do not knowingly collect data from anyone under 16, and we do not build profiles of anyone.

Security

Everything is served over HTTPS with HSTS. Report a vulnerability to security@whatsmyip.fyi or read /.well-known/security.txt. Report abuse of the tools to abuse@whatsmyip.fyi.

Changes

When this policy changes in a way that affects you, the date at the bottom of this page changes and the change is listed on the transparency page.

Last reviewed 2026-09-05.