Privacy policy
What personal data this service processes, why, for how long, and how to get it removed.
Last updated Sep 9, 2026
1Controller
AP Interactive Solutions S.L. is the controller of the personal data described here.
- Legal name
- AP Interactive Solutions S.L.
- Trade name
- AP Interactive
- Tax ID (CIF)
- B56483407
- Registered office
- C/ Sierra del Co 18 A3 4I, Málaga (España)
- [email protected]
- Telephone
- +34 900 433 337
- Website
- www.apinteractive.es
- Service covered
- https://geofeed.network
No data protection officer has been appointed; the service does not carry out processing that requires one. Write to the address above for anything covered by this policy.
2The short version
This service holds an email address, a username and a password hash for each account, the network data you choose to publish, a record of administrative actions, and a log of who fetches your feeds. It sends no email, runs no analytics, loads no third-party scripts and shows no advertising. It does not profile you and makes no automated decisions about you.
The rest of this page is the detail.
3What we process, and why
Your account. Username, email address, a bcrypt hash of your password (never the password), your language and feed-format preferences, the identifier that forms your feed URL, whether you are an administrator, when the account was created and when you last signed in. Purpose: to give you an account and run the service. Legal basis: performance of a contract, GDPR article 6(1)(b).
Two-factor authentication, if you enable it. Your TOTP secret, encrypted with AES-256-GCM, and one-way hashes of your recovery codes. Purpose: to protect your account, at your request. Legal basis: article 6(1)(b).
What you publish. The ASNs you add and, for each prefix, the country, region, city and postal code you enter. Purpose: to generate and serve your geofeed. Legal basis: article 6(1)(b). This data is public by design — see the section below.
API tokens, if you create them. A SHA-256 hash of the token, the first characters so you can recognise it, and the address that last used it. Purpose: authenticating your own automated access. Legal basis: article 6(1)(b).
Security and administration log. For actions that change something — signing in, adding a prefix, an administrator deleting an account — the action, what it acted on, the time, the email address of whoever did it and their IP address. Purpose: accountability and abuse investigation. Legal basis: legitimate interest, article 6(1)(f).
Who fetches your feeds. Every request to a published feed URL is recorded: the time, which feed, the response status, the source IP address and the User-Agent string. This is personal data of whoever or whatever made the request, not only of the account that owns the feed. Purpose: telling the operator whether any geolocation provider actually reads their feed, which is the point of publishing one, and detecting abuse of these public endpoints. Legal basis: legitimate interest, article 6(1)(f). We have weighed this against the interests of the requester: a public endpoint is being fetched, the retention is short, the data is not combined with anything else, is not used to profile anyone, and is shown only to the operator whose feed was fetched.
Rate limiting. Sign-in, registration, validation and other sensitive actions are counted per IP address in memory only. Nothing is written to disk and the counters disappear when the process restarts. Legal basis: article 6(1)(f).
The validator. If you paste a feed or give a URL, the content is processed to produce the report and is not stored afterwards.
4Your geofeed is public
This is the most important thing on this page. A geofeed exists to be fetched by third parties. Your feed is served at a public URL with no authentication, and geolocation providers, researchers, search engines and anyone else may read, copy, cache and keep it indefinitely.
Do not put anything in a geofeed that you do not want published. The format only has room for a prefix, a country, a region, a city and a postal code — but a postal code can be precise, and a location you publish is a location you have told the world about. Country-level data is a valid geofeed and is what most published feeds contain.
Once a provider has fetched a feed we cannot recall it. Deleting an entry stops it being served; it does not delete the copies already taken.
5How long we keep it
- Account and published data
- Until you or an administrator deletes the account.
- Feed request counters
- 90 days.
- Raw feed request log
- 30 days, and at most the newest 5,000 entries per account.
- Security and administration log
- Kept after the account is deleted, but stripped of the email address and IP address at that moment.
- Rate-limit counters
- Minutes, in memory only.
- Validator submissions
- Not stored.
Deleting an account removes, immediately and by cascade, its ASNs, prefixes, feed history, API tokens, two-factor secret and recovery codes, and its published feed URLs stop answering. The entries in the security log survive without the identifiers that pointed at you, because the record that an action happened is what an audit log is for.
6Who else is involved
Processors. Cloudflare, Inc. provides DNS, TLS termination, caching and protection against attack for geofeed.network. All traffic passes through it, including IP addresses and request metadata, and it may set strictly necessary security cookies. Cloudflare is in the United States and processes data under the European Commission's standard contractual clauses.
The servers themselves run on infrastructure operated by AP Interactive Solutions S.L., on its own IP address space, in Germany. No other processor holds this data. There is no analytics provider, no advertising network, no customer-support tool and no email provider, because the service sends no email.
Third parties we contact when you ask us to. These are independent controllers, not processors, and only the request itself reaches them:
- RIPE NCC (stat.ripe.net) — when you import the prefixes your ASN announces
- IANA (data.iana.org) and the regional internet registries' RDAP servers — when you check whether a registry object points at your feed
- the host you name — when you ask the validator to fetch a feed by URL
Disclosure. We do not sell personal data and do not share it for advertising. We would disclose data if a court or a competent authority required it, and would tell you unless legally prevented.
7Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable form. Where processing rests on legitimate interest you may object to it, and we will stop unless we have compelling grounds not to.
Much of this you can do yourself: the panel lets you edit your details, change your language, export your feed as a file, delete prefixes and ASNs, and revoke tokens. For anything else, including erasure of the whole account, write to [email protected]. We will reply within one month, and will ask you to confirm your identity if there is any doubt.
If you fetch a feed hosted here and want the log entry for your request removed, write to the same address with the address and the approximate time; those entries expire on their own within 30 days.
If you think we have handled your data badly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es). We would rather you told us first.
8Security
Passwords are stored as bcrypt hashes and are never recoverable, by us or by anyone else. Two-factor secrets are encrypted at rest with AES-256-GCM. API tokens are stored only as SHA-256 hashes and are shown once, at creation. The session cookie is HttpOnly, Secure and SameSite=Lax, and all traffic is served over TLS.
No system is perfectly secure. If you believe you have found a vulnerability here, write to [email protected] and we will treat it seriously.
9Children
This service is aimed at people who operate networks and is not directed at children. We do not knowingly hold data about anyone under 14, the age of consent for information society services in Spain.
10Changes
If we change this policy, the new version appears here with a new date. If a change materially affects how we process your data, we will make it visible in the panel rather than relying on you re-reading this page.

