Skip to content
IndexMeAI
Sign in
Legal · Updated 2026-08-07

Privacy.

What we collect, why we collect it, who we share it with, and how to remove it. Plain English where the law allows.

01

Who we are

IndexMeAI is operated by Prateek Konduru. The product is hosted at indexmeai.com. Questions, deletion requests, or anything else: indexmeai.app@gmail.com.

02

What we collect

  • Scan inputs

    The name, optional role, and optional field you enter into the scan form. We send these to AI providers as part of the calibration prompts.

  • Scan results

    Model responses, factual findings, scores, and related subject details. These results can identify the person being scanned even when the cache key itself is hashed.

  • Email address

    If you join the cohort waitlist or subscribe to a paid tier. We use it to email you about the product and (if you paid) to bill you.

  • Payment information

    Card data is collected and stored by our payment processor, a PCI-compliant third party. We never see or store full card numbers.

  • Usage analytics

    Anonymous events (page views, scan starts/completions, share clicks) and basic device info (browser, country) via our privacy-friendly analytics tooling. No personal IDs unless you join the waitlist. Analytics in your browser run only if you accept — decline and nothing is collected from your device. Two things run either way and neither can identify you: our host's cookieless page-view and performance counting, and our own server-side tallies of things like badge loads and completed readings, which are recorded against a single fixed identifier rather than against you. See Cookies.

  • Server logs

    Standard request logs (IP, timestamp, path) retained briefly for security and debugging.

03

What we don't collect

  • Browsing outside indexmeai.com

    No cross-site tracking. We don't buy or use third-party data.

  • Sensitive categories

    No race, religion, sexual orientation, biometric, or health data.

  • Children

    We don't knowingly serve users under 18. Don't use IndexMeAI if you're under 18.

04

Who we share with

We share personal data only with service providers required to operate IndexMeAI. We do not sell personal information or use advertising networks.

AI servicesRunning and evaluating readingsName, role, field, prompts, and model responses
Hosting + monitoringServing and securing the productIP address, request metadata, page views, performance, and error context
Account + storageAuthentication, readings, history, cache, and permalinksAccount details, subject details, and scan results
PaymentsProcessing subscriptionsOur payment processor collects card and billing data; we receive customer identifiers and subscription status
EmailSending transactional and cohort messagesEmail address and message content
AnalyticsUnderstanding product usageConsent-based usage events; account email only where described above
05

Your rights

  • Access / export

    Email us and we'll send everything we have on you within 30 days.

  • Deletion

    Delete your account yourself from your account page (bottom of the page) — it removes your profile, subjects, readings and their public permalinks immediately. Or email us and we do it within 30 days. Billed payment records are kept where required by law (typically 7 years for accounting).

  • Correction

    Email us and we'll fix anything wrong.

  • Publishing to the Index

    Your readings are private to your account unless you publish one. Publishing is per-reading and opt-in from that subject's page, it puts the name, role, field, score and reading permalink on the Global AI Index labelled as self-published, and “Withdraw from the Index” on the same page removes the entry and its recorded history immediately.

  • Opt out of analytics

    Use the control in Cookies below — it switches analytics on or off on the spot and remembers the answer. If your browser sends Global Privacy Control or Do Not Track, we treat that as a decline and never ask. You can also email us to exclude your email from analytics.

If you're in the EU/UK, you can also file with your local data-protection authority. We'd rather you talk to us first, we read every email.

Pages about you — removal

Readings on this site describe how AI models answer questions about a person. If a page here is about you and you want it gone, email indexmeai.app@gmail.com with the link. We remove Global AI Index entries and reading permalinks within 7 days, no questions asked, and the removal is honored by our refresh jobs so the page doesn't come back. Pages about people someone else tracks are never submitted to search engines and carry a noindex instruction.

06

Cookies

Here is everything this site puts on your device. Only the analytics entry is optional, and it waits for your answer.

  • Session cookie

    Set by Supabase, our authentication provider, when you sign in. It keeps you signed in between pages. Strictly necessary, so there's no toggle for it: without it there's no account.

  • Analytics

    Set only after you accept on the banner: one first-party PostHog cookie plus its matching entries in local and session storage, which together deduplicate visits within a session. Decline and none of it is written; accept and change your mind and we delete all of it, cookie and storage alike. Your answer itself is kept in local storage, not in a cookie — that is how we know not to ask again.

  • Your own settings

    Two small entries that only exist because you acted. Light or dark mode is remembered in local storage. If you ask us to re-run a reading and we send you to sign in first, the subject you typed is held in session storage until the reading runs, then deleted. Dismissing the cookie banner with Escape is remembered for the tab so we don't ask twice in one visit.

  • Vercel Analytics

    Page-view and performance measurement (Analytics + Speed Insights) from our host. Cookieless by design: no cookie, no local storage, no cross-site identifier, so there is nothing here to consent to.

No third-party ad cookies, no tracking pixels, no cross-site tracking. Your analytics choice:

Analytics

Checking your setting…

07

Retention

  • Scan cache

    Cached scan payloads, including the named subject and model responses, expire after 24 hours.

  • Public permalinks

    Stored for up to one year unless you delete the account or request earlier removal.

  • Account scan history

    Stored while the account is active so history and monitoring work; deleted with the account except where law requires otherwise.

  • Cohort waitlist email

    Until you ask us to delete or the product shuts down.

  • Paid subscriber records

    Required minimum for tax/accounting (typically 7 years).

  • Analytics events

    Our analytics provider's default retention (currently 7 years; we may shorten).

08

Security

All traffic is HTTPS. Secrets are stored in our host's encrypted environment, not in the codebase. We follow standard least-privilege access internally. We'll tell you in plain English if there's a breach affecting your data within 72 hours of discovery.

09

Changes

If we change this policy materially, we'll email everyone on the cohort waitlist and update the date at the top. Continued use after a material change means you accept it; you can always delete and walk away.