OpenPostcodes

Privacy

OpenPostcodes looks up UK postcodes. It holds no names or addresses, has no accounts and sets no cookies. This page says what is collected when you use it, why, and for how long.

Who we are

OpenPostcodes is run by Jason Cartwright, an individual, who is the data controller. It is one of the OpenCommons sites. To ask about anything on this page, get in touch through jasoncartwright.com.

What this site publishes

The ONS Postcode Directory is the authoritative source. Where anything here differs from it, the ONS release takes precedence, and corrections belong with the Office for National Statistics. Every page is open to search engines, and the postcode, sector, district and area pages are listed in the sitemap.

What we collect when you visit

Analytics

Every HTML page loads two analytics scripts. Neither sets a cookie.

Both use your IP address and browser to tell visitors apart for the day, and say they do not store either. The JSON and Markdown formats, the API and the MCP server load no analytics. A content blocker that blocks plausible.io and fiveb.ar stops both.

Logs

The site runs on Cloudflare Workers, with Cloudflare's Workers Logs turned on. For each request they record the method and address, which includes the postcode looked up, the request headers, such as your browser's user agent, and details Cloudflare adds, such as your country. They can include your IP address. They are kept for up to 7 days and are used to find faults and keep the site running.

The postcodes you look up are not stored anywhere else. Responses are cached at Cloudflare's edge by postcode, not by who asked. The lookup box on the home page puts the postcode in the address and sends you on to that postcode's page.

Cookies and browser storage

None. The site sets no cookies and keeps nothing in your browser's storage.

What your browser fetches from elsewhere

Like any request a browser makes, each of these carries your IP address and user agent.

The API and AI assistants (MCP)

The API needs no key or sign-up. Its requests are logged like any other, as above.

The MCP server lets AI assistants use the same data. It is stateless: no sessions, no cookies and no sign-in. Each call writes one log line: the protocol version, the method, the tool's name, how long it took, the outcome and the assistant's own name for itself. It never logs what was asked: no arguments, postcodes or search text.

The send_feedback tool lets an assistant send us a short note about the tools, only once you have agreed. We keep:

A note with an email address, an IP address or a web address with a query string in it is refused. The note is never written to the logs. Notes are kept in the site's database on Cloudflare and deleted after 365 days.

Third parties and where data is processed

Nothing is sold, and nothing is used for advertising.

Why we use it

We rely on legitimate interests: keeping the site working and secure, understanding how it is used, hearing what is wrong with it, and publishing open postcode data.

How long we keep it

Your rights

Under UK data protection law you can ask to see the personal data we hold about you, and to have it corrected or deleted. You can also object to how we use it, or ask us to restrict it. We hold very little that identifies anyone, so we may not be able to find you in it, but we will look. Get in touch through jasoncartwright.com.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office.

Changes

When what we collect changes, this page changes with it.

Last updated: 11 October 2026.