Privacy by design
Privacy Policy
How this IP Lens installation processes connection information.
Internet Speed Test
The test runs only when you choose Start and transfers at most approximately 15.25 MiB per run, excluding headers and ping responses, between your browser and the IP Lens server. Payloads are processed transiently in bounded chunks; the application does not persist payloads or results in its database, analytics table, cache or application-controlled logs. Expiring request-limit records use HMAC keys derived from the IP for abuse prevention; they contain no payloads or measurement results.
Results reflect the route to this server, may be below the ISP's advertised speed and do not certify a plan's speed.
Information processed
The server necessarily receives an IP address when a browser connects. IP Lens uses it to display connection details, apply abuse limits and perform optional network lookups. Browser checks read only capabilities needed to show the result on the page.
The authenticated recent-activity view combines a masked network hint with country, browser, operating system, device and time. It does not show the page or URL visited. Bot activity shows only a normalized bot name/category, country and time.
The web server or hosting provider may keep access and error logs independently of the application cache. The operator is responsible for configuring and disclosing that retention.
Cache design
Approximate country, city, network owner, ISP and ASN data is cached by IPv4 /24 or IPv6 /48 for 30 days by default. That cache does not keep the exact IP.
Short-lived network-risk and rate-limit records use a keyed one-way identifier derived from the IP. Risk retention is 24 hours by default. IP Lens does not create user accounts or account-linked visit histories.
First-party visit statistics
When JavaScript is available, IP Lens records one page view with UTC time, page path, approximate country, browser, operating system, device type, language, time zone, screen-size bucket and referring host.
Recognized bots are recorded server-side after successfully loading public HTML pages. Classification uses the User-Agent and stores only a normalized bot family and category, never the full User-Agent. User-Agents can be spoofed: this is unverified classification, with no reverse DNS or external bot-detection service. Bot recording does not call a network-information provider; a country code is taken only from Cloudflare when configured as trusted.
The raw IP is not written to the page-view table. Human rows store only a masked network hint such as 203.0.113.xxx (approximate IPv4 /24) or 2001:db8:85a3:… (approximate IPv6 /48), allowing an authenticated operator to see a few recent visits without a full IP address. Bot rows do not store this hint. Both human and bot events use an HMAC derived from the IP and UTC date that changes each day. Only human keys contribute to visitor-days, which do not represent unique people across multiple days. The masked hint follows the page-view retention period, which defaults to 180 days and can be reduced in config.
External services
On a cache miss, the server may send the requested IP to the configured network-information provider; the default is ipwho.is. If weather is enabled, the server sends approximate coordinates to WeatherAPI.com and caches current conditions for the configured TTL. The IPv6 test may contact api6.ipify.org. WebRTC may use Google's public STUN service.
The map uses approximate coordinates inferred from an IP address, not a precise GPS location. Only when you open connection details and coordinates are available does your browser load the map and send a request to OpenStreetMap. OpenStreetMap receives your connecting IP address and the approximate coordinates in that map request; this page sends no referring page address. If you use the Google Maps fallback, your browser opens Google with the same approximate coordinates; no request is sent to Google until you choose the link.
Google Analytics and AdSense
Both are disabled by default. If the operator enables them with valid IDs, Google tags load directly and this site does not display a consent-choice banner.
The operator must update this policy and deploy consent/CMP controls wherever required by Google or applicable law before enabling advertising or Analytics in those regions.
Your choices
You can stop using the service, block JavaScript, disable WebRTC or avoid optional tests. Blocking JavaScript limits interactive results.
Effective: September 13, 2026. The operator must review this starter policy for applicable law and real business details.