LEGAL
Privacy Policy
This policy explains what information IPRevealed processes, why it is processed, how long it may be retained and the choices available to visitors.
Last updated: August 3, 2026
No advertising profiles currently
Contact details are used to handle enquiries
Standard infrastructure logging applies
An on-demand connection check is live; further diagnostics remain in development
Contents
04
Rights and contact
Who is responsible for this site
IPRevealed is the public-facing name of the operator of this website. The operator determines how information submitted through the site is processed. Privacy enquiries and requests concerning personal information may be sent to privacy@iprevealed.com.
Scope of this policy
This policy applies to:
- iprevealed.com
- Enquiries submitted through the Contact form
- Infrastructure and security processing carried out to operate the site
- The homepage’s on-demand connection check, and any future diagnostic functionality once explicitly enabled
Links on this site may lead to third-party websites. Those websites operate under their own privacy policies, which IPRevealed does not control.
Information currently processed
Information submitted through Contact
- Name, which is optional
- Email address
- Selected topic
- Subject
- Message
Technical request information
- IP address
- Request time
- Requested URL
- Response status
- Browser or user-agent information, where recorded at the infrastructure level
- Security and rate-limiting metadata, described further under Contact form processing
Administrative information
Authenticated WordPress administrators use standard login and security cookies necessary to manage the site. Ordinary visitors browsing the site anonymously do not receive administrator cookies.
Why information is processed
- To deliver the website to visitors
- To respond to enquiries submitted through the Contact form
- To investigate technical feedback
- To handle privacy or security-related requests
- To prevent spam and abuse of the Contact form
- To maintain the security and availability of the site
- To meet legal obligations, where applicable
IPRevealed does not currently send marketing communications of any kind, and this policy will be updated if that changes.
Legal grounds
Depending on the specific processing activity and the visitor’s jurisdiction, IPRevealed relies on one or more of the following grounds:
- Processing necessary to respond to a visitor’s request, such as replying to a Contact submission
- Legitimate interests in operating, securing and maintaining the website
- Compliance with a legal obligation, where one applies
- Consent, only where consent is genuinely and separately requested
Standard server logging, described later in this policy, is not based on consent. It is a necessary part of operating the website and instead relies on legitimate interest and, where applicable, legal obligation. The specific legal basis that applies to any given processing activity may depend on the visitor’s jurisdiction.
Contact form processing
This section describes the Contact form as it is actually implemented.
Information submitted
- Name, which is optional
- Email address
- Selected topic
- Subject
- Message
Delivery and storage
The form uses WordPress’s own mail system to send each submission to contact@iprevealed.com.
WordPress does not keep a permanent database copy of the message once it has been sent.
Contact messages are retained for up to 12 months after the last exchange, then deleted unless longer retention is necessary to resolve a dispute, prevent abuse, or comply with a legal obligation.
Abuse prevention
- A salted, one-way cryptographic hash is temporarily used for rate limiting.
- Raw IP addresses are not stored by the Contact form’s rate-limit mechanism.
- The transient hash and counter expire automatically after 15 minutes.
- A hidden honeypot field rejects automated submissions.
No attachments. No mailing-list enrollment. No marketing subscription.
Server logs and security
Like virtually all websites, iprevealed.com runs on hosting and caching infrastructure that automatically records standard technical request information. IPRevealed does not claim that zero logging occurs. These records may include the visitor’s IP address, request timestamp, requested URL, response status and, where captured at the infrastructure level, browser user-agent information.
These logs may be used for:
- Security
- Abuse prevention
- Error diagnosis
- Service availability
The site also uses a caching layer (LiteSpeed Cache) to serve pages efficiently; this may create its own short-lived operational records as a normal part of server operation. These logs are retained by the hosting provider according to its operational, security and backup schedules, and removed or overwritten in accordance with those schedules.
Cookies and similar technologies
As verified when this policy was last updated, browsing iprevealed.com anonymously does not set any cookies.
- If a WordPress administrator logs in to manage the site, WordPress sets standard login and session cookies necessary for that authenticated session. Ordinary visitors do not receive these.
- Comments are not currently used or displayed anywhere on the site. If comments are enabled in the future, WordPress’s standard behavior would apply: a cookie would only be set if a commenter chooses to have their name and email remembered for future comments.
- No analytics, advertising, or consent-management cookies are currently installed or active.
This section must be updated before analytics, advertising, consent-management or personalization technologies are enabled.
Diagnostic information
IPRevealed offers an on-demand connection check on the homepage. The check runs only when a visitor actively chooses to run it; it never runs automatically and is never triggered simply by loading a page.
When a visitor runs the check, their browser sends requests directly to IPRevealed’s own services: the main connection-check service (an IPRevealed Cloudflare Worker) and separate, protocol-specific IPv4 and IPv6 test services. Each service only ever receives the public IP address visible to that particular request, and returns information such as IP version, autonomous system number (ASN), associated network organization, and transport protocol so it can be displayed on the page. Each request is a direct connection between the visitor’s browser and the corresponding IPRevealed-operated service; none of these requests pass through the WordPress site itself.
The protocol-specific IPv4 and IPv6 services determine network operator (ASN) information using a MaxMind GeoLite2 ASN database file that is hosted locally on IPRevealed’s own server. No live request is sent to MaxMind, or to any other third party, during the check; the ASN lookup is performed entirely against this locally hosted database file.
IPRevealed does not write diagnostic results to the WordPress database, to cookies, to browser local storage or session storage, or to any application log, and does not create a history of past diagnostic results. IPRevealed does not intentionally persist diagnostic results. Results normally remain only in the current page state, although browser features such as back-forward caching may temporarily restore that state.
Cloudflare Workers Logs, Traces, Exports and Sampling are disabled for the main connection-check Worker. Cloudflare, and the hosting infrastructure and content delivery network supporting the protocol-specific IPv4 and IPv6 services, may still process request information as part of operating their own networks, for standard infrastructure, security and operational purposes, under their own respective policies.
This on-demand connection check is the only diagnostic feature currently live. Other diagnostics described elsewhere on the site, including DNS exposure, WebRTC exposure, VPN and proxy indicators, and reputation signals, are not yet enabled. This policy will be updated to document their signals, data providers, retention, storage, sharing, automated classifications and visitor controls before any of them is launched.
Sharing and service providers
IPRevealed does not sell personal information. Depending on the processing activity, information may be shared with the following categories of recipients:
- Hosting infrastructure necessary to operate the website
- Email delivery infrastructure used to transmit Contact form notifications
- Security and operational service providers involved in running the site
- Professional advisers, where necessary
- Public authorities, where legally required
This policy does not claim that information is never shared under any circumstance. Sharing is limited to the categories above, for the purposes described in this policy.
International processing
Hosting infrastructure
Provider
Hostinger (verified hosting and caching infrastructure)
Purpose
Hosting and delivery of the website
Processing location
Not independently confirmed by the hosting provider at this time
Transfer safeguards
Not independently confirmed at this time
Contact email delivery
Delivery method
Sent through the hosting account’s own mail infrastructure
Dedicated delivery provider
None currently verified
Processing location
Not independently confirmed by the hosting provider at this time
No conclusion about international-transfer safeguards is made until the relevant locations and arrangements have been verified.
Retention
The table below sets out, for each category of information described in this policy, how long it is kept.
| Category | Retention |
|---|---|
| Contact messages | Up to 12 months after the last exchange, unless longer retention is necessary for a dispute or legal obligation |
| Rate-limit hashes | 15 minutes, then automatically expired |
| Server logs | Retained by the hosting provider according to its operational, security and backup schedules, and removed or overwritten in accordance with those schedules |
| Security records | Retained by the hosting provider according to its operational, security and backup schedules, and removed or overwritten in accordance with those schedules |
| Administrative account data | For as long as the associated administrator account exists |
| Backups | Retained by the hosting provider according to its operational, security and backup schedules, and removed or overwritten in accordance with those schedules |
Privacy rights
Depending on the law that applies to you, you may have rights that can include:
- Access
- Correction
- Erasure
- Restriction
- Objection
- Portability, where applicable
- Withdrawal of consent, where processing relies on consent
- The right to lodge a complaint with a competent supervisory authority
The specific supervisory authority you may contact, and the process for exercising these rights, depends on the law that applies to you. To exercise any of these rights, use the privacy contact details in the final section of this policy.
Security
IPRevealed applies a number of reasonable technical safeguards, including:
- HTTPS encryption for all traffic
- Restricted, credential-protected administrative access
- Security response headers, including protections against content-type sniffing and clickjacking
- Restriction of anonymous access to certain WordPress API endpoints
- Restriction of legacy remote-publishing access
- Server-side input validation on the Contact form
- Rate limiting on the Contact form to reduce automated abuse
- Regular backups and software updates
No website can guarantee absolute security. This policy intentionally does not describe the site’s specific internal defensive configuration.
Children’s information
IPRevealed is a general technical information service and is not designed to intentionally collect personal information from children. Visitors should not submit unnecessary personal or sensitive information through the Contact form.
Changes to this policy
This policy may change as the site evolves, including when:
- Diagnostics launch
- Analytics or advertising is introduced
- Service providers change
- Legal requirements change
- New products, accounts or features are introduced
When this policy changes, IPRevealed commits to updating the “Last updated” date shown at the top of this page.
Contact and complaints
Privacy enquiries
Questions about this policy, or requests concerning personal information, may be sent to privacy@iprevealed.com.
Supervisory complaints
Depending on applicable law, individuals may also have the right to contact a competent data-protection authority.