Privacy Policy
Last updated: July 16, 2026
Overview
IPly("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains our practices regarding data collection on iply.dev. In short: We minimize retention and do not persist raw visitor IPs in application-controlled storage as part of normal product behavior. We use Vercel Analytics and Speed Insights for aggregate product metrics. When IP enrichment runs after a visitor requests details or submits an IP lookup, the IP being looked up is sent to ipwho.is to retrieve ISP, ASN, and location metadata unless request headers already provide the needed visitor network details. Standard DNS lookups send the queried domain to Cloudflare's 1.1.1.1 DNS-over-HTTPS resolver for TXT, DMARC, and SRV records; other standard DNS and reverse DNS records use the platform resolver. When you enable public resolver comparison, the queried domain is sent to both Cloudflare and Google over DNS over HTTPS for A, AAAA, MX, TXT, and NS records. WHOIS lookups send the queried domain to rdap.org and any RDAP service it redirects to over HTTPS; .bg fallback lookups use whois.register.bg over TCP. When you run the WebRTC leak test, your browser may contact the listed Google and Cloudflare STUN servers to gather ICE candidates. Some transient operational processing may still occur for security, abuse prevention, hosting, and caching. App-controlled storage can include short-lived hashed rate-limit identifiers, keyed cache identifiers, and cached tool results.
Information We Do Not Persist
- Raw visitor IP storage: We do not persist raw visitor IPs in application-controlled storage as part of normal product behavior.
- Personal profiles: We do not provide accounts, user profiles, or account-linked personal data storage.
- Advertising trackers: We do not use Google Analytics, Facebook Pixel, ad-tech beacons, or social tracking scripts.
- Device fingerprinting: We do not build persistent fingerprint-based visitor profiles.
Cookies
We may use essential cookies only when necessary for site functionality. We also use Vercel Analytics and Speed Insights for aggregate product metrics. We do not use advertising cookies, social media trackers, or third-party ad-tech scripts.
- • Vercel Analytics for aggregate usage metrics
- • Vercel Speed Insights for performance measurement
- • Essential cookies only when needed for functionality
- • No advertising or social tracking cookies
Third-Party Services
Our runtime depends on third-party infrastructure and enrichment providers. Current external services include:
- Vercel: Our site is hosted on Vercel and uses Vercel Analytics plus Speed Insights for aggregate product and performance metrics.
- ipwho.is: When IP enrichment runs, the IP being looked up is sent to ipwho.is to retrieve ISP, ASN, and approximate location metadata.
- DNS-over-HTTPS providers: Standard DNS lookups send the queried domain to Cloudflare's 1.1.1.1 DNS-over-HTTPS resolver for TXT, DMARC, and SRV records; other standard DNS and reverse DNS records use the platform resolver. When you enable public resolver comparison, the queried domain is sent to both Cloudflare and Google over DNS over HTTPS for A, AAAA, MX, TXT, and NS records.
- WHOIS/RDAP services: WHOIS lookups send the queried domain to rdap.org and any RDAP service it redirects to over HTTPS; .bg fallback lookups use whois.register.bg over TCP.
- Google and Cloudflare STUN: When you run the WebRTC leak test, your browser may contact the listed Google and Cloudflare STUN servers to gather ICE candidates.
Data Retention
We do not persist raw visitor IPs in application-controlled storage as part of normal product behavior. Some transient operational processing may still occur for security, abuse prevention, hosting, and caching. App-controlled storage can include short-lived hashed rate-limit identifiers, keyed cache identifiers, and cached tool results. Recent lookups are opt-in and stored in browser localStorage on your device. They store query text, not lookup results; disabling or clearing recent lookups removes that local browser storage. Third-party providers may also apply their own retention policies.
Your Rights
Because we do not maintain user accounts or persistent visitor profiles, there is generally no application-managed profile for you to access, correct, or delete. If you need details about third-party processing, consult the relevant provider policies.
Security
All connections to IPly are encrypted using HTTPS/TLS. We implement security headers including Content Security Policy, X-Frame-Options, and other best practices to protect your browsing session.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date.
Contact
If you have questions about this Privacy Policy, please visit ourAbout page.