NetKnife-001
Privacy Policy
Status: Live
Effective: September 2026
Contact: andy@ondrya.com
Abstract
NetKnife is operated by Ondrya. This page describes exactly what data the tool collects, why, how long it’s kept, and which third parties it’s ever sent to — reflecting what the running application actually does, not a generic template.
Email address and display name — if you request an API key (to save lookups, set up alerts, or submit/vote on community BGP-community meanings), we store the email you provide and an optional display name, tied to a randomly generated API key. Account creation is intentionally lightweight: an email mints or reuses a key with no email-verification step. This is a deliberate simplification for a free operator tool, not an oversight — don’t reuse a sensitive password-recovery email as your API-key email.
Your IP address — used for two things: (1) rate limiting, where it’s held in a short-lived counter that expires automatically after 60 seconds and is never written to permanent storage; (2) if you view the homepage, it’s looked up against a third-party geolocation service (see §2) to show your own connection info back to you.
Saved lookups and alert subscriptions — the prefixes/ASNs you save or subscribe to for change alerts, tied to your account, kept until you delete them or ask us to.
Community-dictionary submissions — a BGP-community meaning you submit or vote on is stored attributed to your account and is, by design, publicly visible to every visitor (it’s a crowdsourced reference dictionary).
ASN ownership-claim contact emails — if you claim an ASN, we look up its real RDAP administrative/ technical/abuse/registrant contact and send a verification code to it. That address is used server-side only to send the code and is always masked (e.g. a***@example.com) in every response your browser or anyone else’s ever sees.
ip-api.com — the GeoIP tool and the homepage’s own “your connection” line send an IP address (either one you typed in, or your own visiting IP for the homepage feature) to this third-party geolocation service and relay back its response. No account identifier is sent alongside it.
RIPEstat, RIPE Atlas, public RIR RDAP registries (ARIN / RIPE NCC / APNIC / LACNIC / AFRINIC), and RADB — the prefix, ASN, or domain you look up is sent to these public registries and research platforms to retrieve routing history, ASN registration, and IRR route-object data. These are the same public data sources anyone can query directly; we don’t send your account email or identity to them.
RPKI validation is checked against our own self-hosted Routinator instance — nothing is sent to a third party for this.
We do not use analytics scripts, advertising trackers, or any cookie-based tracking. The only thing stored in your browser is your API key itself (in localStorage, not a cookie), so it persists across visits without a server-side session.
Accounts, saved lookups, alerts, community submissions, and ASN claims are stored in our Postgres database and kept until you ask us to delete them (contact us at the address above).
Rate-limit counters live in Redis and expire automatically after 60 seconds — we don’t retain a history of who queried what, when, for this purpose.
Raw BGP routing data (the AS-path/community/RPKI history that powers lookups) is stored in ClickHouse and is not personal data — it’s public internet routing announcements. It’s automatically deleted after 90 days.
You can use the core BGP/IP/DNS lookup tools with no account at all — an API key is only needed for saved lookups, alerts, and community-dictionary contributions. Clearing your browser’s localStorage removes your stored key from that browser (your account and its data still exist server-side until you ask us to delete them).
To request a copy of your data, ask us to delete your account, or ask any other question about this policy, email andy@ondrya.com.
This policy is written to accurately describe what the running application does, not as a substitute for legal advice. If you need this policy to satisfy a specific regulatory regime (GDPR, CCPA, or otherwise), have it reviewed by counsel before relying on it.