indextr ("we", "our", "us") provides an AI visibility monitoring service for businesses. This policy explains what information we collect, how we use it, and the rights you have over your data. It's written in plain English on purpose — if anything is unclear, email us at hello@indextr.ai and we'll explain.
What we collect
When you create an account and use indextr, we collect:
- Account info: your email address, a securely hashed password (we never see your actual password), and a timestamp for when you signed up.
- Business profile: the business name, website URL, city, and a short description of what your business does that you provide during onboarding.
- Searches: the phrases you select or enter for indextr to monitor, plus the full AI responses we get back.
- Competitor data: the 3 competitor businesses auto-detected during onboarding (inferred from your name, city, website content, and business description via Claude Haiku) and any competitors you later add yourself.
- Scan results: what each AI engine said about your business for each search, plus derived metrics (mentions, citations, sentiment, competitor comparisons).
- Billing info: if you upgrade to a paid plan, Stripe collects your payment details directly. We only store your Stripe customer ID and subscription status — we never see or store your card number.
How we use it
Your data is used only to:
- Run scans against AI engines on your behalf.
- Calculate your Visibility Score and generate recommendations.
- Send you welcome emails and scan reports.
- Process billing and manage your subscription.
- Investigate errors and improve the product.
We do not sell your data, share it with advertisers, or use it to train AI models. We don't send marketing emails unrelated to the product.
Third parties we use
indextr is built on a small set of trusted service providers. Each has their own privacy practices; we only share the minimum data needed for them to do their job:
- Supabase — database and authentication. Stores your account and scan data.
- Stripe — payment processing. Handles subscriptions and billing.
- OpenAI, Anthropic, Google (Gemini), Perplexity— AI engines we query on your behalf to produce your visibility data. We send your search phrases; we receive the AI's answer. Per their terms, these providers do not use API inputs to train their models.
- Resend — email delivery. Sends welcome emails and scan reports.
- Vercel — hosting and infrastructure for this website.
- Sentry — error monitoring. Captures stack traces when something breaks; does not receive your scan content.
Cookies
We use a single essential cookie: an authentication session cookie from Supabase that keeps you logged in. We do not use tracking cookies, advertising cookies, or analytics cookies that identify individual users.
Your rights
You can at any time:
- Access your data — view or export everything we have about you by emailing us.
- Correct your data — update your business profile from Settings inside the dashboard.
- Delete your account— email us and we'll delete your account and all associated data within 30 days. Scan result archives may be retained anonymously for aggregate analytics.
- Cancel your subscription — directly from the Stripe Customer Portal link in Settings.
Data retention
We keep your data as long as your account is active. If you delete your account, we delete your business profile, searches, competitor data, scans, scores, recommendations, and reports within 30 days. Stripe billing records are retained per Stripe's and applicable tax law requirements (approximately 7 years).
Children
indextr is a business tool and is not intended for users under 18. We do not knowingly collect data from children.
Changes to this policy
If we materially change how we collect or use your data, we'll email you before the change takes effect. Minor clarifications may be made without notice; the "Last updated" date at the top of this page always reflects the current version.
Contact
Questions, concerns, or data requests — hello@indextr.ai. We aim to respond within 5 business days.