IPForge legal · Updated 2026-09-23
Privacy Policy
This policy has two halves, because IPForge sits on two sides of the same subject.
Part A is about you, the account holder: what IPForge knows about you and why. Here IPForge is the controller. Part B is about the people who open the links you create: what their browser is asked for, what is stored, and for how long. There the workspace owner is the controller and IPForge only processes, under the Data Processing Addendum.
Part B is written in full detail on purpose. A measurement product that describes itself vaguely leaves its customers unable to tell anyone the truth.
1. Part A — what IPForge holds about you, the account holder
- Identity and sign-in
- An email address and a hashed password, or a Google account identifier, or a crypto wallet address — whichever you sign in with. A display name if you set one. Passwords are stored only as bcrypt hashes and are never recoverable.
- Security records
- The IP address you signed up from and the IP address and coarse location of your most recent sign-in. These exist to detect account takeover and to recognize when you are testing your own link, so your own visits are not counted as real activity.
- How you found us
- The source, medium, campaign and referring page of your first visit, if any were present. Used to understand which channels bring people who stay.
- Billing
- Your credit balance, your orders, the chain and the transaction hash of each purchase, and the wallet address that paid. Blockchain transactions are public by nature; IPForge does not add anything to that record.
- Support and enforcement
- Messages you send us, and — if it happens — the reason an account or a link was blocked.
The lawful bases are performance of the contract (running your workspace and billing it), legitimate interests (keeping the service secure and free of abuse, and understanding which channels work), and legal obligation (tax and accounting records). We do not sell your data, do not share it for advertising, and run no third-party analytics or advertising scripts on this site.
2. Part B — what a tracked link asks a visitor's browser for
When someone opens a link, a landing page or a tracking image created in a workspace, the request itself carries data, and — unless the owner has switched the group off for that resource — a script asks the browser for more. Everything below is collected by default. A workspace owner can disable the groups marked configurable per link.
- Request data
- IP address, User-Agent, Accept-Language and Referer headers, and the JA4 TLS fingerprint of the connection. Sent by the browser with every request; recorded server-side. (always recorded — it is part of the request)
- Approximate location and network
- Country, region, city, latitude/longitude at city resolution, ISP, ASN, and flags for VPN, proxy, Tor and hosting networks — derived on our own server from licensed MaxMind databases. The IP address is never sent to a third-party lookup service. (always recorded — it is part of the request)
- Device and browser profile
- Device type, operating system, browser and version, screen and window metrics, timezone, languages, hardware concurrency, memory class, touch support, media queries and feature support. (configurable per link; on by default)
- Rendering fingerprints
- Canvas, WebGL, audio and installed-font measurements, plus a math/benchmark profile. Combined into one fingerprint hash used to recognize a repeat capture within 24 hours. (configurable per link; on by default)
- Browser environment probes
- Ad-blocker presence, detectable browser extensions — including a hidden bait form that password managers and writing assistants inject into — announced crypto-wallet providers (EIP-6963), permission states, battery, network type, media devices and speech voices. (configurable per link; on by default)
- Local network probes
- WebRTC candidates, requests to common localhost development ports, and requests to common router gateway addresses, to detect what responds. These run in the visitor's browser and reach only that browser's own network; they read no content from any service they reach. (configurable per link; on by default)
- Engagement (opt-in, landing pages only)
- Visible-tab dwell time, a coarse scroll-depth bucket and whether a call to action was used. No click coordinates, keystrokes, form values or page content. (configurable per link; on by default)
Two of these deserve to be named plainly rather than left inside a category. The browser-environment probes include a hidden form planted on the page so that password managers and writing assistants reveal themselves by filling it in, and a check for announced crypto-wallet browser extensions. The local-network probes ask the visitor's own browser to contact common development ports and common router addresses to see what answers. Both run in the visitor's browser, reach nothing outside that browser's own network, and read no content from whatever answers — but both go beyond what “analytics” normally means, and a workspace owner who does not want them should switch the group off.
3. What is never collected
- Keystrokes, form values, passwords or anything typed on any page.
- Page contents, screenshots or the DOM of a page a visitor came from or went to.
- Precise pointer paths or click coordinates.
- Browsing history, or any profile of a visitor across sites that are not the workspace owner's own.
- The contents of any local service or router the local-network probes detect — only that something answered.
A tracked link also sets no cookie and writes nothing to the visitor's browser storage. Recognizing a repeat capture within 24 hours is done with a hash of the signals above, not with anything stored on the device. The Cookie Notice lists every cookie ipforge.xyz itself sets — three strictly necessary, and one that records which campaign brought you.
4. How long each record is kept
- Captures (the visitor records above)
- Until the workspace owner deletes the link, the image or their account. Deleting any of them deletes the captures with it; there is no separate archive.
- Engagement sessions
- 30 minutes of session lifetime, then the row expires and is swept.
- Raw delivery-test observations
- 7 days, after which only the summarized evidence remains. A delivery test itself lives at most 7 days.
- Account records
- For as long as the account exists, and afterwards only what is needed for tax, accounting and abuse records.
Deletion is real deletion: removing a link, an image or an account removes the captures attached to it from the database, not merely from the interface.
5. Where the data is, and who else touches it
The application, its database and its reverse proxy run on a single server in Germany. Approximate location is derived on that server from licensed MaxMind databases — a visitor's IP address is never sent to a third-party lookup service.
The full list of everyone outside IPForge who touches any data, what they receive and where they are, is published in the Data Processing Addendum. It is short: hosting, optional Google sign-in for account holders, a blockchain RPC used to confirm payments, and optional Telegram alerts if an operator turns them on.
6. Your rights
If you hold an account, you can ask us for a copy of what we hold about you, ask for it to be corrected, or ask for your account and everything in it to be deleted. Write to admin@ipforge.xyz; we answer within 30 days.
If you are the person who opened someone else's link, the record is controlled by the workspace owner, not by us — we do not know who you are and cannot identify you from it. Write to admin@ipforge.xyz with the link URL and roughly when you opened it, and we will pass the request to the owner responsible and tell you that we have. Where the law requires us to act ourselves, we will.
You may also complain to the data-protection authority where you live. The authority competent for IPForge follows from PENDING — the operator's establishment.
7. Security
Passwords are bcrypt-hashed; API tokens are stored as hashes and shown once; every connection is served over TLS; the dashboard and the API require authentication and are excluded from search engines. The client IP the service records is taken from the reverse proxy in front of the application rather than from a client-supplied header, so it cannot be spoofed by the visitor.
8. Children
IPForge is not for people under 16 and accounts are not knowingly opened for them. Tell us at admin@ipforge.xyz if you believe a child has an account and it will be closed.
9. Changes, and who to contact
When this policy changes the date at the top changes with it; a change that widens what is collected will be announced in the dashboard before it takes effect. The controller for Part A is IPForge — PENDING — registered legal name and address — reachable at admin@ipforge.xyz.