Controller
intelligent piXel GmbH, Enzianstraße 4a, 82319 Starnberg, Germany. Managing director George A. Rauscher. Contact my@intelligent-pixel.com. Full company details are in the imprint.
We have not appointed a data protection officer. We have reviewed the requirements of Art. 37(1) GDPR and Section 38(1) of the German Federal Data Protection Act (BDSG); there is no obligation to appoint one. Any privacy request sent to the address above reaches the managing director directly.
Principle
IP Beacon shows you what a website learns about your connection and your device. The tool itself is built not to leave new traces. That means: your IP address is checked only on our own server and is never sent to a lookup service. Everything about your device is computed by your own browser, and only after you explicitly start the scan. Tests that involve a third party run only when you click, and they are labeled as such beforehand.
There are no user accounts, no cookies, no tracking, no advertising and no behavioral profiles. We do not store results.
Hosting
We run the server in a German data center operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The operating system and all services are managed solely by intelligent piXel GmbH. Hetzner provides the hardware and the physical security of the building and is bound as a processor under Art. 28 GDPR by a data processing agreement. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the reliable and secure operation of this service.
Server logs
With every request, the web server processes the connection data required for delivery and secure operation and writes it to the access log: requested host name, IP address, date and time, the requested address including any parameters, HTTP status code, amount of data transferred, referrer and browser information. Rejected or faulty requests are additionally recorded in the error log with IP address, time and requested address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is safe, stable and abuse-resistant operation, including error analysis and attack detection. We never use these logs for profiling or marketing. Both logs are kept for 14 days at most and then deleted automatically.
IP check
On every page, the page asks our server for your IP address so it can show it in the header bar. On the start page, it also shows all the connection data that reaches the server. To answer, the server reads your IP address, source port, HTTP version and a fixed selection of the headers your browser sends with every request anyway, such as the user agent and preferred language. Cookies and credentials are not read.
Country, network operator and network type, meaning whether the address belongs to a data center, a VPN network or iCloud Private Relay, are determined from data sets stored locally on the server. Country and network operator data come from IPLocate.io (CC BY-SA 4.0); the network lists come from the X4BNet lists_vpn project and the address ranges published by Apple. Your IP address does not leave the server for this.
For the hostname, on the start page the server also looks up the reverse DNS record of your address. This query goes through our DNS resolver to the name servers responsible for your address range, which in most cases are run by your own internet provider. In the process, your IP address is queried as a name in reversed notation.
The result is returned only to your browser. We do not store it and keep no cache of it. The only thing that remains is the server log entry. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is providing the service you want to use by opening this page.
Device scan
Only when you click "Scan my device" does your browser read information from your device: among other things operating system, browser, screen, language, time zone, CPU cores, graphics card, installed fonts and test values from canvas and audio. From these it computes a fingerprint and a privacy rating.
This computation takes place entirely in your browser. The values read, the fingerprint and the rating are neither sent to us nor to third parties, not stored and not used to recognize your device. They are gone when you close the window. Accessing your device is permitted under Section 25(2) No. 2 of the German TDDDG because it is strictly necessary to provide the service you explicitly requested. We do not receive any personal data in the process.
The PDF report is produced by your browser's print function, and the JSON file is also created locally. Both go only to you.
Speed test
The test starts only when you click. Your browser sends short requests to our server and downloads and uploads randomly generated test data. The server counts the uploaded test data and discards it immediately. Only the server log entries remain. Results are neither transmitted nor stored. The legal basis is Art. 6(1)(f) GDPR.
IP and domain lookup
When you enter an IP address or a domain, our server checks it against the same local data sets. A domain is first resolved into addresses through the server's DNS resolver. The search term appears in the server log as part of the requested address and is deleted along with it after 14 days at most. Beyond that, we do not store it. Please enter only addresses you are entitled to check. The legal basis is Art. 6(1)(f) GDPR.
Third-party tests
Two additional tests cannot be run without a third party. They run only when you press the respective button, and the page labels them as third-party tests beforehand. The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG, which you give by clicking. You can withdraw it at any time for the future by not starting the test again.
WebRTC leak test
Your browser queries a STUN server operated by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (stun.cloudflare.com). Cloudflare receives your IP address and the time of the request. Cloudflare is certified under the EU-U.S. Data Privacy Framework; the transfer is based on the European Commission's adequacy decision of July 10, 2023. Only your browser evaluates the result.
IPv6 test
Your browser queries the service api6.ipify.org, whose operator is based in the US. The operator receives your IPv6 address and the time of the request. We cannot confirm a certification under the EU-U.S. Data Privacy Framework for this service, and no appropriate safeguards under Art. 46 GDPR are in place. The transfer is therefore based on your explicit consent under Art. 49(1)(a) GDPR. The risk: the US may not offer a level of protection equivalent to EU law, in particular regarding access by authorities, and your rights may be harder to enforce there.
The downloadable version of IP Beacon additionally offers a lookup via api64.ipify.org when it is opened without a server. This website does not use it.
Download
When you download the program package, the server delivers the file. Only the server log entries are created. We do not count downloads and keep no download statistics.
Obligation to provide data
You are under no legal or contractual obligation to provide personal data. Retrieving the page technically requires your browser to transmit the connection data listed under server logs; without it, the page cannot be delivered. The device scan, speed test, lookup and additional tests are voluntary. Not using them has no disadvantage for you.
Server protection
The server is protected by IPServerSec, a hardening and early-warning system we developed ourselves. It places traps on paths a legitimate visitor never requests and blocks any source that probes them. In addition, CrowdSec analyzes the logs, detects attack patterns and blocks attacking IP addresses automatically, escalating from 12 hours to 72 hours to permanent. When an address is blocked, we send the IP address, the time and the name of the attack pattern to CrowdSec SAS, Paris, France, which processes this data as an independent controller within the EU. In turn, we receive from CrowdSec lists of IP addresses that attracted attention through attacks on other participating servers. This data does not come from you: the categories are IP address, time and name of the attack pattern, and the source is CrowdSec SAS and, through it, the participating server operators. A block based on it applies for as long as the address remains on the list. The legal basis in each case is Art. 6(1)(f) GDPR; our legitimate interest is defending against attacks.
Blocking decisions are made automatically. They only affect access to this server and, in our assessment, do not reach the threshold of Art. 22(1) GDPR. Regardless, we grant you the safeguards of Art. 22(3) GDPR: on request at my@intelligent-pixel.com, a person reviews the block, you can state your point of view, and we reply within 10 working days. A detailed description of every protection layer on this server is in the privacy policy of intelligent-pixel.com.
Your device
This website sets no cookies and uses neither local storage nor session storage, IndexedDB, service workers or web beacons. The fonts (Space Grotesk, Bebas Neue) are files on our own server, and the icons (Lucide) are embedded directly in the page; no request goes to Google Fonts, a content delivery network or any other third party. For display purposes, like any website, the page reads window size, pixel density and your reduced motion setting; these values stay in your browser. Links to other websites send no referring address when clicked. When you hover over a link in the language switcher, your browser prefetches the target page from this server. Whatever your browser caches in the process serves only to deliver the requested page and requires no consent under Section 25(2) No. 2 TDDDG. For the device scan, see above.
Recipients at a glance
Recipients are exclusively: Hetzner Online GmbH, Germany, as processor for hosting; CrowdSec SAS, France, in the event of a block; the name servers of your address range for the reverse DNS lookup; and, only on your explicit click, Cloudflare, Inc., USA, or the operator of ipify.org, USA. Any further disclosure takes place only where required by law or to establish, exercise or defend legal claims. We do not share data for advertising or analytics.
Retention
We delete server logs automatically after 14 days at most. We do not store results of the IP check, the lookup, the device scan or the speed test. Blocked IP addresses remain stored for as long as the block applies; we review permanent blocks at least once a year and delete the entry after 24 months at the latest unless the address has attracted attention again.
Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability under Art. 15 to 20 GDPR. You can withdraw consent at any time with effect for the future. An email to my@intelligent-pixel.com is all it takes.
Right to object: On grounds relating to your particular situation, you may object at any time to processing based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). We will then stop the processing unless we demonstrate compelling legitimate grounds or the processing serves to establish, exercise or defend legal claims.
You may lodge a complaint with a supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
This version is dated October 5, 2026. The German version is legally binding.