Privacy Policy
Last updated: 2026-04-27.
This explains what myipcat.com collects when you visit, and what we and our advertising partners do with it.
What we collect ourselves
Almost nothing. The tools on this site run entirely in your browser using JavaScript โ anything you type into a calculator stays in your browser and isn't sent to our servers.
The one exception is the IP-lookup feature: to show your IP, your browser fetches it from Cloudflare's free trace service (1.1.1.1/cdn-cgi/trace). That request goes from your browser directly to Cloudflare and includes your IP by definition. We don't store or log it.
Our hosting provider (Cloudflare) keeps standard server logs containing IP, page, user-agent, and timestamp. These are used for security and abuse prevention.
Cookies and Google AdSense
We use Google AdSense for ads. Google and its partners use cookies and similar technologies to:
- Serve ads based on your prior visits to this and other sites.
- Measure ad performance and detect fraud.
- Personalize ads based on inferred interests.
You can opt out of personalized advertising at Google Ads Settings, aboutads.info, or networkadvertising.org.
For visitors in the EEA, UK, or Switzerland, Google's consent management tool requests your consent for personalized advertising in line with the GDPR.
Children's privacy
This site isn't directed at children under 13. We don't knowingly collect personal information from children.
California, Virginia, and other state rights
If you're a California resident, the CCPA/CPRA grants you the right to know what personal information is collected, request deletion, and opt out of "sale" or "sharing." We don't sell personal info traditionally, but cross-site advertising cookies may qualify as "sharing" under California law. Opt out via the links above. Similar rights apply under Virginia (VCDPA), Colorado (CPA), and other state laws.
Your choices
- Disable cookies. Tools still work; ads will be non-personalized.
- Use an ad blocker. We won't stop you. We'll be a little sad.
- Opt out of personalized ads via the links above.
Changes
If this policy changes substantively, we'll update the date at the top and highlight the change for at least 30 days.
Contact
Get in touch with privacy questions.
The specific data flow for each kind of tool
Different tools on this site handle data differently. Some run entirely in your browser and never send anything to a server. Some make queries through a Cloudflare Worker to public data sources. Understanding the difference helps you decide what to feel comfortable pasting where.
Browser-only tools
The Base64 Encode/Decode, JWT Decoder, Hash Generator, UUID Generator, Password Entropy Calculator, IP Converter, Subnet Calculator, CIDR Range Tool, Email Header Analyzer, and Email Spam Score all run entirely in JavaScript on your device. Nothing you paste is sent to any server. You can verify this by opening browser developer tools before pasting and confirming that no network activity happens when you click compute, encode, decode, or check.
For sensitive inputs โ passwords you're testing, JWTs containing real user identifiers, email headers with internal server names, hashes of confidential documents โ this matters. The compute stays local and there's no external record.
Tools that query public data through our Worker
The IP Lookup, DNS Lookup, DNS Propagation Checker, WHOIS Lookup, Reverse DNS, Blacklist Check, Email Health Check, SSL/TLS Cert Inspector, MAC OUI Lookup, MTU Calculator, and Domain Infrastructure Lookup send the specific input (an IP, a domain, a hostname) to our Cloudflare Worker, which forwards the query to the appropriate public data source (a DNSBL, a DNS resolver, an RDAP endpoint, an IP geolocation provider). Results come back and are shown to you.
What we log: standard Cloudflare Web Analytics โ page views and referrer information, aggregated, no individual user tracking. What we don't log: the specific inputs you submitted, the specific results returned, or anything else that would let us reconstruct your usage. Query results for popular inputs are cached in Cloudflare KV so repeat lookups are fast, but the cache is keyed by the input and doesn't identify who submitted it.
The Speed Test
The speed test uses Cloudflare's official speed test SDK, which measures throughput directly between your browser and Cloudflare's edge network. Test traffic doesn't go through our Worker at all. Cloudflare, as the measurement endpoint, sees the traffic as an anonymous test session. Results are displayed only to you.
The CGNAT and WebRTC Leak tools
Both of these run in your browser. The CGNAT detector compares your public IP (as observed by Cloudflare's edge) against known CGNAT ranges. The WebRTC leak detector gathers candidates using the browser's WebRTC API and displays what your browser reveals. Neither sends any additional data to any server beyond the initial page load.
Cookies and analytics, specifically
No first-party cookies are set. No third-party cookies are set. Your session ends when you close the tab and nothing is retained.
Cloudflare Web Analytics is the only analytics on the site. It counts page views without setting cookies or fingerprinting devices. Aggregate data (page views per URL, referrer breakdown, country-level geography) is visible in the Cloudflare dashboard. Nothing about individual users is retained or exposed.
What happens if you use the site with an ad blocker or VPN
The site works fine with any ad blocker. Nothing on the site depends on ad-tracking infrastructure. If your ad blocker is aggressive enough to block the Cloudflare Web Analytics beacon, that's fine too โ the tools work regardless.
The site also works fine with a VPN. Some tools might report your VPN's exit IP instead of your real IP (the IP Lookup will show whichever IP is visible from Cloudflare's edge, which is your VPN's exit IP if you're on one). This is expected behavior.
Data retention specifically for shared tool results
The Speed Test has a "share result" feature that generates a URL you can send to someone. When you share, the result is stored in Cloudflare KV for 7 days, then automatically deleted. The stored data includes only the measured speed values โ download, upload, latency, jitter โ with no identifying information about who took the test.
WHOIS lookup results are cached for 1 hour per domain to reduce load on RDAP endpoints. IP lookup results are cached for 30 days per IP for the same reason. Domain Infrastructure results are cached briefly (30 minutes per domain, 7 days per IP). These caches contain publicly-available data (WHOIS records, IP ownership, DNS records) and don't identify who queried them.
Contact-form and email privacy
There is no contact form. The site's contact address is hello@myipcat.com, which is a real inbox I read. Email you send goes to me directly, is not shared, sold, or given to any third party, and isn't used for any marketing. See the Contact page for the fuller policy.
What we don't do
- No user accounts. Nothing to log in to. Nothing to compromise via credential theft.
- No email newsletters. Nothing you can be unsubscribed from because you never subscribed.
- No cross-site tracking. Nothing follows you to other sites.
- No cookies for any user-identifying purpose.
- No selling data to third parties. Nothing to sell.
- No advertising retargeting infrastructure.
- No fingerprinting or device identification.
- No data enrichment services building a profile from your inputs.
Legal jurisdiction and applicable law
The site is operated by me personally from Vermont, USA. Vermont state law and applicable US federal law govern. GDPR compliance is achieved in practice by not collecting personal data beyond what's needed to serve pages. CCPA compliance is the same โ no sale of personal information is possible because none is collected.
If you're a resident of a jurisdiction with specific data-protection rights and you have a specific request (right to know, right to deletion, right to opt out of sale), the honest answer for most requests is "we don't have anything about you to expose, delete, or opt out." If you nonetheless want to submit a formal request, email hello@myipcat.com and I'll respond.
Changes to this policy
This policy might get updated as the site evolves. If the changes are substantive (say, adding a new class of data collection, or adding an integration with a service that changes what's happening under the hood), I'll note the change in a visible way. Minor rewording won't be flagged. The current version of this policy is what applies at the time you're reading it.
