// privacy
Privacy policy.
Effective 2026-05-11. asn.zone is operated by IPXO. This policy describes what we collect, how we use it, and your rights.
This is a working draft. Final policy lands before public launch of the paid tier.
What we collect
- Customer data - email, optional name, password hash (bcrypt). Set when you register or sign in through an OAuth provider.
- Session metadata - IP address and user agent captured at session issue, used for revocation and abuse-handling.
- API request logs - endpoint, response code, latency, and the requesting customer / IP. Retained 30 days for ops + abuse handling, then aggregated.
- Cookies -
asnzone_session(HMAC-signed, HttpOnly),asnzone_locale(language preference). No advertising or cross-site trackers.
What we don't do
- No advertising. No third-party analytics SDKs in the browser.
- No sale of personal data.
- No tracking pixels in emails we send.
Public RIR data
The directory itself surfaces records published by the regional internet registries (allocations, delegations, transfer logs, peering relationships). These records identify organisations and ASNs, not individuals. We do not augment that surface with personal data.
Your rights
You can export or delete your customer profile by writing to [email protected]. Customer deletion revokes all sessions and API keys and removes the row from our database; cached responses expire within 24 hours.
Contact
Privacy questions: contact form or [email protected].