Skip to content
InternetData

Privacy Policy

Last updated: 4 October 2026

This notice explains how Mslm Dev, trading as InternetData ("we", "us"), collects, uses and shares personal information when you visit internetdata.io or use the InternetData API. Questions go to [email protected].

1. What we collect

We collect the following from you directly:

  • Account details: your name, email address, and a hashed password. We never store your password in a form we can read.
  • Authentication data: if you sign in with Google or GitHub, the identifier and email that provider returns to us.
  • Licensing and invoicing details: the contact, entity and billing details needed to put a license agreement in place and to invoice under it.
  • Support correspondence: whatever you choose to send us.
  • Newsletter: if you subscribe, your email address, the topics you choose, and a record of your signup and its confirmation (when, which page, your IP address and your browser), which we keep to show the subscription was asked for. We also record each email we send you and whether it was delivered.

We collect the following automatically when you use the Service:

  • Session and security data: the IP address a request came from, the browser or client user agent, and timestamps. We use this to keep you signed in, to show you your own active sessions, and to detect abuse.
  • Download records: a record of each database download, refused attempts included: the organization and, where one was used, the API key behind it, the database and format, when, the address it came from and the client's user agent. We use it to show you your download history, to support you and to investigate abuse.
  • Usage data: a record of each API request, and of each address lookup and sample download on this website, including any key that made it, what it asked for and when, so we can support you and investigate abuse.
  • Lookup counts: when you look up an IP address on this website, a count of the lookups made from your address in the past hour, kept against that address so we can limit automated use. Each count expires an hour after it starts.
  • Server logs: for every request that reaches our servers, including visits to this website, the address it came from, the user agent, the page or endpoint asked for, the referring page and when. We use them to run and secure the Service, and match the address against our own network data to tell people from automated traffic.

We do not process special category or sensitive personal information, and we do not buy personal information from third parties.

2. IP addresses we classify are not personal information about you

This is worth stating plainly because it is the part people ask about. Our classification datasets describe network infrastructure, such as which ranges belong to VPN operators or hosting providers, and are derived from network measurement, published operator server lists and public internet registry records.

Because we license databases rather than answering lookups, the addresses your own users connect from never reach us: you query a database you hold, inside your own infrastructure, and we see none of it.

3. How we use it

  • To create and operate your account, and to authenticate you.
  • To provide the Service, and to administer and invoice your license.
  • To keep the Service secure, including preventing fraud and automated abuse.
  • To respond to your support requests.
  • To send you the newsletter, if you subscribe or have an account.
  • To understand aggregate usage so we can improve the Service.
  • To comply with our legal obligations.

Account holders get the monthly product update unless they opt out. The sign-up form offers it with a box that's already ticked, which you can untick, and you can turn it off at any time under Notifications in the console's settings. Every newsletter email has a one-click unsubscribe link.

4. Legal bases (EEA and UK)

  • Contract: operating your account, and providing the Service and the databases you license.
  • Legitimate interests: securing the Service, preventing abuse, and improving what we offer, where those interests are not overridden by your rights.
  • Legal obligation: retaining records we are required to keep, and responding to lawful requests.
  • Consent: optional cookies, and marketing email where we rely on consent. You can withdraw consent at any time.

5. Canada

Where PIPEDA applies, we rely on your express or implied consent, which you may withdraw at any time. In limited circumstances the law permits processing without consent, for example to investigate a breach of an agreement or to detect fraud.

6. Sharing

We share personal information only with:

  • Cloudflare, whose Turnstile challenge protects sign-up, sign-in, the contact form, the newsletter signup and the address lookup from automated abuse.
  • Google and GitHub, if you choose to sign in with them.
  • Google, whose Analytics measures how the Service is used, unless you turn measurement off.
  • Infrastructure providers that host the Service under contract with us.
  • Authorities, where we are legally required to.

We may transfer information in connection with a merger, acquisition or sale of assets. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

7. Cookies

We set strictly necessary cookies, one optional functional cookie that is off until you agree to it, and analytics cookies that measure how the site is used, which are on until you turn measurement off. We set no advertising or cross-site tracking cookies. In full:

CookieSet byPurposeRetention
vd_sessionUsKeeps you signed in. Not readable by scripts.30 days
vd_deviceUsRecognizes a browser you have signed in from before, so we can tell you about a sign-in from a new device. Not readable by scripts.180 days
vd_trusted_deviceUsLets a browser you asked us to remember skip the second sign-in step. Not readable by scripts.30 days
internetdata_consentUsRecords your cookie choices so we do not ask again.180 days
Turnstile cookiesCloudflareDistinguishes people from bots on sign-up, sign-in, the contact form, the newsletter signup and the address lookup.Set by Cloudflare
g_stateGoogleOptional, functional. Remembers that you closed the Google sign-in prompt so it does not reappear. Set only if you accept functional cookies.Set by Google
_ga, _ga_<id>GoogleAnalytics. Tells visits and visitors apart so we can count them and see which pages help. On unless you turn measurement off.Up to 2 years
internetdata_srcUsAnalytics. Where your recent visits came from: a search engine, another site, a campaign link or an ad. If you sign up, we keep it with your account so we know what brought you. On unless you turn measurement off.180 days

Signing in with Google or GitHub sends you to that provider, which sets its own cookies on its own domain under its own privacy policy. We do not set cookies on their behalf.

Everything above except the Google sign-in prompt and the analytics cookies is strictly necessary to provide a service you asked for. The prompt is a convenience rather than a necessity, so it is off until you accept functional cookies, and nothing is loaded from Google for it until you do. The analytics cookies are on until you turn measurement off in the cookie banner or from the Cookie preferences link in the footer; turning it off deletes them and stops anything being sent to Google Analytics. You can change either choice at any time from that link.

There is no single agreed standard for Do Not Track signals, so we do not currently respond to them.

8. Retention

We keep account information for as long as you have an account, and for a limited period afterwards where we need it to meet legal, tax or accounting obligations or to resolve disputes. Session and security logs are kept for a short period appropriate to detecting abuse. Download records, holding the time, the database, the address the request came from, the client's user agent, and the organization and any API key that made it, are kept without a set deletion date, for support and abuse investigation. Server logs, and what we derive from them about each address, are kept for 90 days. Records of API requests and of this website's lookups and sample downloads, holding the time, what was asked for and, where there is one, the key and organization that made it, are kept for 13 months, for support and abuse investigation. Hourly counts of the addresses and user agents that make the most of those requests are kept without a set deletion date, and those of the addresses and user agents that reach our servers most for 400 days. A newsletter subscription and the record of its signup are kept until the address is removed. If email to an address bounces or is reported as spam, we keep the address on a list of addresses not to email again, even after it is removed. When we no longer need information, we delete or anonymize it.

9. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, hashed passwords, first-party session cookies that scripts cannot read, and optional multi-factor authentication. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Your rights

Depending on where you live, you may have the right to access your personal information, to correct it, to delete it, to restrict or object to processing, to portability, and to withdraw consent. We will act on requests in line with applicable law and will not treat you differently for exercising a right.

To exercise a right, email [email protected]. We will verify your identity before acting, usually by confirming control of the account email. You can also export your data, deactivate your account or delete it yourself, from Settings → Data & privacy in the console. If you subscribed to the newsletter without an account, you can delete your address and its record yourself from the preferences page every newsletter email links to.

If you are in the EEA or UK and believe we are processing your information unlawfully, you may complain to your local supervisory authority. In Switzerland, that is the Federal Data Protection and Information Commissioner.

11. California

The categories of personal information we have collected in the past twelve months, using the CCPA's own categories:

CategoryExamplesCollected
A. IdentifiersName, email address, account name, IP addressYes
B. California Customer Records categoriesName, contact detailsYes
C. Protected classificationsAge, gender, raceNo
D. Commercial informationLicense and invoicing recordsYes
E. Biometric informationFingerprints, voiceprintsNo
F. Internet or network activityDownload records, sign-in eventsYes
G. Geolocation dataPrecise device locationNo
H. Audio, visual or similarRecordingsNo
I. Professional or employment informationEmployment historyNo
J. Education informationStudent recordsNo
K. InferencesProfiles built from the aboveNo

We have not sold or shared personal information in the preceding twelve months, and we do not intend to. California residents may request access, deletion, or correction, and may use an authorized agent who provides proof of authorization.

12. Children

The Service is for users aged 18 or over. We do not knowingly collect information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.

13. Changes

We update this notice as our practices or the law change. The "Last updated" date above shows the current version, and we will notify account holders of material changes.

14. Contact

Mslm Dev
195-B Jasmine Block Sector C Bahria Town
Lahore, Punjab 53720, Pakistan
[email protected]