Sitewide privacy notice

What IPSpy.net processes

Version v2 · updated 2026-07-21. This notice covers the utility tools and the #CleverGirl reader chat. It does not promise zero collection, perfect filtering, or immediate erasure from provider recovery systems.

Information kept in your browser

The encoding tool can keep up to 50 recent input/output history items in browser localStorage under encoding_history. You can remove individual items, clear that history in the tool, or clear site data in your browser.

The theme control uses browser storage under theme to remember light, dark, or system appearance. These browser values remain on the device until the tool or browser removes them. The #CleverGirl handle, transcript, reports, and session credential do not use this storage.

IP lookup, map, and site assets

  • Cloudflare Pages/CDN delivers the static site. Every page or asset request can send Cloudflare ordinary connection data such as IP address, user agent, requested path, referrer allowed by browser policy, and time.
  • The home page asks Cloudflare's trace endpoint for the public IP address visible to that service.
  • It sends that IP address to ipapi.co to obtain approximate location, network, postal, and time-zone results.
  • The site loads Leaflet CSS from unpkg.com. The map requests tiles from the a, b, or c.tile.openstreetmap.org hosts. Tile coordinates and ordinary connection data can reveal an approximate viewed area to those services.
  • The footer links to a LinkedIn profile. LinkedIn receives a request only if you follow that external link; the link is configured not to send an opener or referrer from the page.

Browsers and these providers may process ordinary request data such as IP address, user agent, requested URL or tile, time, and site origin according to their own policies. IPSpy.net does not control their independent retention.

#CleverGirl reader chat

Before a session is created, the browser loads Cloudflare Turnstile. Turnstile evaluates browser and interaction signals and returns a short-lived token. The Worker validates that token with Cloudflare. Do not enter passwords, private records, contact details, or identifying information in the handle or chat.

After creation, a host-only HttpOnly cookie identifies one isolated session. The service processes the selected handle, visitor messages, generated replies, policy versions, request state, timestamps, quotas, and minimum operational metadata. No other visitor can join or read that session.

The same-origin Cloudflare Worker enforces the session and sends approved work through Cloudflare D1, Vectorize, Workers AI, and AI Gateway. D1 holds short-lived session and transcript state. Workers AI may receive a bounded query for embedding and the guarded prompt for generation. Vectorize receives the query vector and searches only the approved Book 1 corpus. AI Gateway applies configured controls and usage metadata; the launch contract disables raw prompt/response logging, response caching, and third-party model fallback.

Visitor messages are not used to fine-tune a model, train the characters, automatically improve replies, or add records to the Book 1 corpus. Cloudflare's current Workers AI documentation also says it does not use customer content to train Workers AI models or improve its or third-party services without explicit consent. That provider statement does not replace the site's own restrictions.

Retention, clearing, and reports

  • Completed chat data expires after 7 days without a completed exchange and no later than 30 days after session creation.
  • A session keeps at most 120 completed visitor/crew messages. A model request uses at most the most recent 24 stored messages.
  • Choosing Clear session invalidates active access, removes the active transcript/session rows, clears the cookie, and hides the in-memory transcript. The old transcript is not restored into a new visitor session.
  • D1 maintains provider recovery history for a plan-dependent period. Cloudflare currently documents 7 days for Workers Free and up to 30 days for Workers Paid. Cleared rows can therefore remain recoverable to authorized provider/database operators until the applicable recovery window ends.
  • If you report an AI reply, a minimal redacted generated excerpt and fixed reason may be retained for up to 30 days. The visitor message and handle are excluded by default. Clearing the session does not erase this separately disclosed report snapshot early.

Logs and analytics

The utility tools have no application-side server log or marketing analytics pipeline. Recoverable browser errors are handled locally without sending tool input or error details to IPSpy.net. Cloudflare and the named lookup, CDN, and map providers may still process ordinary connection and security data under their own policies.

For #CleverGirl, raw prompt/response logging, AI response caching, Workers invocation payload logs, third-party model fallback, and marketing analytics are disabled. D1 retains the short-lived session records described above. Content-free counters needed for quotas, costs, cleanup, and safety may remain in D1 only for their operational window; they contain no handle, message text, cookie, Turnstile token, raw IP address, prompt, retrieved corpus text, or secret. Incident diagnostics are enabled only when necessary, kept content-free, access-limited, and removed as soon as the incident or provider retention window permits.

Your choices and privacy requests

You can clear encoding history in that tool, clear theme/site data in your browser, leave before creating a chat session, or use Clear session inside the chat.

For a request that cannot be completed with those controls, privately contact the site owner through the linked LinkedIn profile. Do not put secrets or sensitive records in a public post. Because the utility tools have no account and the chat intentionally avoids identity collection, the owner may be unable to locate data that cannot be safely connected to you.

For the chat-specific behavior rules, read the AI-chat terms.