On clicking one of the random IP addresses it showed me that they had tracked, the right sidebar Facebook comment column had a comment from a developer that stated they tested the application locally, and then pushed the same database live, so many of the 192.168.0.0/16 block (and I could assume other RFC 1918 blocks) are the actual developers traffic.
Isn't this addresses easy to spoof? I thought they were only suited for scaring friends, not basing investigative articles.