Privacy

Minimal data by design.

Last updated: September 14, 2026

What is processed

To answer a lookup, IPKit processes the requested IP address and standard request metadata. Current-IP lookups necessarily use the public address that connects to Cloudflare.

IP intelligence provider

Detailed lookups may be sent securely to our configured IP intelligence provider. Provider credentials are never exposed to your browser.

Browser extension

The optional Chrome extension reads the current tab hostname, resolves it to an IP, and queries IPKit for country, provider and related fields. If that lookup fails, it requests your public IP instead. The extension does not read page content or inject scripts.

Storage and logs

IPKit does not maintain an application database of visitor IP addresses. Cloudflare and the data provider may retain operational logs under their own policies. We use sampled technical logs to diagnose errors and abuse.

Analytics

HTML pages may load Google Analytics 4 to count visits. The JSON API (for example curl https://ipkit.dev without an HTML Accept header) does not include analytics scripts. Lookup results are not sent to Google as page content. You can block the script; lookups still run at the Cloudflare edge.

Accuracy

IP location and security attributes are estimates. They must not be interpreted as a street address, identity, or definitive evidence of malicious behavior.

Contact

Privacy questions can be sent to privacy@ipkit.dev.