Frequently Asked Questions
Learn about our data collection methodology, technical definitions, and how the global BitTorrent ecosystem operates.
Torrent Analytics specializes in systematic monitoring of the global BitTorrent ecosystem. Our platform aggregates and analyzes data from the BitTorrent network to surface insights into traffic trends, content popularity, and peer behavior over time.
We work with rights holders, law enforcement agencies, researchers, and network security teams who need reliable, up-to-date visibility into how content moves across P2P networks.
Our global crawlers continuously monitor the Distributed Hash Table (DHT) network and public trackers to discover active P2P participants and their IP addresses.
Because anyone can announce an IP address on the DHT network, raw DHT data can be spoofed by malicious actors. To ensure high accuracy, we heavily curate our data before it ever reaches our platform.
This curation includes cross-referencing DHT announcements against verified peer connections, filtering out IP ranges associated with known abuse, and removing duplicate observations. See our answer on DHT Announcements vs. Peer Connections below for more on how we tell the two apart.
The data shown on this platform comes exclusively from public DHT and tracker infrastructure. Private tracker communities operate under their own access and membership rules, so we handle that kind of work on a case-by-case basis.
If you have a specific need in this area, we're happy to discuss it with selected parties. Contact us.
Throughout the site, you will see toggles allowing you to switch between DHT and Peer data:
- DHT Announcements: A daily count of how many times an IP address and port announced to the public DHT network that it was requesting peers for a specific file.
- Peer Connections: A count of verified, successful torrent protocol handshakes our crawlers established directly with the IP address. This confirms the IP was actually running a BitTorrent client and actively participating in the network, rather than simply appearing in a DHT announcement.
Peer Connections are generally the stronger signal of the two, since they require a live, verified handshake rather than a broadcast that anyone could have sent.
Because BitTorrent is a public, decentralized protocol, downloading or uploading files inherently exposes your IP address to everyone else sharing that same content. If your IP is listed, it means a device on your network announced itself to the public DHT or was discovered sharing files through a direct connection from our crawlers.
Common reasons your IP may appear include:
- Shared Local Networks: Someone else on your Wi-Fi (such as children, a spouse, roommates, or guests) is using a torrent application.
- VPNs and Proxies: Many VPN providers route thousands of customers through the same exit IP address. If another customer on that shared exit node was torrenting at the time, the activity will appear associated with that IP, even though it wasn't your traffic.
- CGNAT (Carrier-Grade NAT): Your Internet Service Provider may pool your connection with hundreds of other subscribers behind a single public IP address. When that happens, activity from any of those subscribers can appear under the same shared IP, with no way for an outside observer to tell whose traffic it actually was.
- Background Applications: Many legitimate software programs, gaming clients, and media players use hidden P2P protocols in the background to distribute updates efficiently.
- Compromised Network: Your home or company network, a connected smart device, or an IoT appliance may have been hacked and is being used maliciously to distribute files.
- DHT Spoofing: A malicious actor falsely announced your IP address to the DHT network. This does happen in the BitTorrent ecosystem, and we take great care to filter out those occurrences.
Appearing in our data only confirms that the IP address was observed. It doesn't tell us, or you, which of these explanations applies in any given case.
There are several common reasons why a torrent user might not appear in our public database:
- Disabled DHT: Your client may have DHT disabled and rely on private trackers, or you may use public trackers exclusively. Public tracker data is less reliable for IP identification, since it contains many inaccurate entries and is harder to curate; every entry needs a verified TCP connection before we trust it, which naturally slows down data collection from that source.
- Niche or Low-Activity Torrents: Torrents with very few active peers generate fewer DHT announcements overall, so there is simply less activity for our crawlers to observe and record.
- Timing: Our crawlers scan vast amounts of network traffic globally, but we do not guarantee 100% coverage of every peer at every exact second.
- Filtered Shared IPs: If your IP address is shared with peers known for polluting or abusing the DHT network, we may withhold that IP from the public database entirely to keep our results reliable.
Not as a general rule. The BitTorrent protocol is inherently public. When you participate in public BitTorrent transfers, your client explicitly broadcasts your IP address to other participants worldwide to facilitate the transfer. We simply act as an observer, aggregating this non-PII, publicly-broadcast network metadata.
We do curate the data to maximize its analytical value, but we only remove IP addresses from the platform in special circumstances. If you believe your situation qualifies, contact us and we'll take a look.
No. We exclusively monitor the public BitTorrent protocol network. We cannot and do not monitor traffic routed through centralized or encrypted channels such as HTTPS direct downloads, Usenet, or web-based streaming platforms. None of that traffic is broadcast to a public network the way BitTorrent DHT and tracker traffic is.
This is how we uniquely identify each torrent in our analytics without exposing the complete hash. Every torrent has a unique SHA-1 infohash, a 20-byte fingerprint generated from its metadata. A torrent prefix is simply the first 8 bytes (16 hexadecimal characters) of that infohash. That's enough to identify specific content for analysis, but not enough on its own to reconstruct a working magnet link and initiate a download.
Yes, what we do is completely legal. Torrent Analytics strictly processes publicly available network metadata: the same information that BitTorrent clients broadcast openly as part of how the protocol works. We do not host, store, or provide tools for downloading copyrighted content, and we do not access any private, authenticated, or non-public systems to obtain our data.
We take data protection seriously and design our processes with frameworks like the GDPR in mind. We do not knowingly collect or publish Personally Identifiable Information beyond what is inherently present in publicly-broadcast network metadata.
Our core team and technical infrastructure are based in Poland, but our monitoring reach is global. IP address geolocation data is sourced from IPinfo.
Have a non-standard query?
We offer custom data extraction, specific regional monitoring, and historical deep-dives for verified researchers and partners.
contact@torrentanalytics.net