subnethistory.
How it works Use cases Sources Blog Privacy Get the API

Privacy

Plain talk about what we keep, what we build from it, and who else sees anything.

Last updated 2026-08-10

The short version
  • Every lookup is logged. When you search an IP, prefix or ASN, we keep the query and the time. We do not keep your IP address: it is turned into a salted hash on arrival, and the salt is discarded and replaced whenever the service restarts, so the hash cannot be reversed or matched to you later.
  • Your searches feed our dataset. We run our own algorithms over what people look up, and queries decide what we fetch, re-check and archive next.
  • We use analytics, including session recording. Google Analytics and PostHog run on this site, set cookies, and record how you move through the pages, so we can see which parts of the interface do not work. Only after you accept. Decline and nothing is loaded or recorded at all. What you type is never recorded.
  • History is the product. Records and observed changes are kept indefinitely, which is the whole point of the service.
  • We do not sell your personal data. The dataset we build is about networks and address space, not about you as a person.

1. What we collect

Using the site or the API, we record:

  • Lookups. The subject you search (IP, prefix or ASN), when you searched it, and what we answered.
  • Visitor data. Your IP address reaches our server with every request, as it must for any website. We use it to answer you and to build the salted hash described above, and then discard it. We do not store your address, browser, device, referrer or location. The analytics providers in section 5 collect their own data under their own policies.
  • API usage. Endpoints called, request volumes, and your key once keys exist.
  • Cookies and identifiers. Set by us and by the analytics tools below.

2. What we build from it

This is the part most privacy policies bury, so here it is plainly: query logs are an input to the product.

  • What gets searched tells us which address space to fetch, sample and re-check. Your lookup can trigger our own checks on that subject.
  • Our algorithms run over the log, including how often a block is looked up, from where and in what bursts, to prioritise archiving and to propose labels.
  • The result is a dataset about networks: records, routing history, sampling verdicts and derived signals. It may include aggregate query interest, meaning "often looked up", and never who looked it up.
  • We also use logs for the boring, necessary things: serving cached reports, rate limiting, and abuse prevention.

3. Analytics and third parties

We use two third-party analytics tools to understand how the site is used: Google Analytics, and PostHog for product analytics. Both set cookies and receive your IP address and usage data under their own privacy policies. Our PostHog project is hosted in the European Union.

Neither loads unless you accept. Until you answer the cookie question, and for as long as you decline it, no analytics script is fetched and no analytics cookie is set. Declining also deletes the analytics cookies and stored identifiers we already have, so a choice made today applies to what was set before you made it. You can change your answer from the "Cookies" link in the footer of any page.

One thing we deliberately hold back. A report lives at a web address that contains the subject you searched, so an analytics tool would ordinarily record it just by recording the page. We strip the subject out of every address these tools see. What you searched is reported separately, and never at all when the subject is your own IP address, so neither tool receives an identifier for the person browsing.

PostHog records sessions. When you accept analytics, it records the pages you see and how you move through them, so we can find the parts of the interface people struggle with. Two things are never in those recordings: anything you type, because every input is masked before the recording is made, and your own IP address on the one screen that would show it, because looking up your own address is the single search that identifies you rather than a network. Request and response contents are not recorded either.

If you would rather not be recorded, decline the cookie question and nothing is recorded at all. You can change your mind at any time from the "Cookies" link in the footer, and declining later also deletes what was stored before.

Separately: when your lookup is not in our cache, the subject of the lookup, meaning the IP, prefix or ASN and never your identity, is forwarded to upstream data sources such as RDAP registries, RIPEstat, Team Cymru, PeeringDB, ipapi and Scamalytics so we can fetch fresh records.

4. How long we keep things

Indefinitely, by default. The service exists to remember what others overwrite, so cached records, observed changes and query-derived signals are part of the permanent archive. The lookup log is part of that: the query, the time and the salted hash. Because the salt is discarded on every restart, the oldest entries cannot be linked to the newest even by us.

5. What we share

  • We do not sell or rent your personal data: your IP, your identity, or your individual search history.
  • The network dataset we build, including signals derived in aggregate from queries, is the product, and may be published, licensed or sold.
  • We disclose data if the law genuinely requires it.

6. Your choices

  • Block or clear cookies; the site works without them. Analytics respects standard opt-outs.
  • Use the API directly, which means no browser, no analytics scripts and no cookies. Lookup logging still applies.
  • Email us with any question about this policy. We cannot look up what you personally have searched, because nothing in the log identifies you: the salted hash is one-way and its salt is already gone.

7. Changes and contact

If this policy changes in a way that matters, the date at the top changes and we will say so on the site. Questions and requests: [email protected]

© 2026 subnethistory.com
Docs Sources API Status Privacy Terms Abuse