Who we are
IndexMeAI is operated by Prateek Konduru. The product is hosted at indexmeai.com. Questions, deletion requests, or anything else: indexmeai.app@gmail.com.
What we collect
- Scan inputs
The name, optional role, and optional field you enter into the scan form. We send these to AI providers as part of the calibration prompts.
- Scan results
Model responses, factual findings, scores, and related subject details. These results can identify the person being scanned even when the cache key itself is hashed.
- Email address
If you join the cohort waitlist or subscribe to a paid tier. We use it to email you about the product and (if you paid) to bill you.
- Payment information
Card data is collected and stored by our payment processor, a PCI-compliant third party. We never see or store full card numbers.
- Usage analytics
Anonymous events (page views, scan starts/completions, share clicks) and basic device info (browser, country) via our privacy-friendly analytics tooling. No personal IDs unless you join the waitlist. Analytics in your browser run only if you accept — decline and nothing is collected from your device. Two things run either way and neither can identify you: our host's cookieless page-view and performance counting, and our own server-side tallies of things like badge loads and completed readings, which are recorded against a single fixed identifier rather than against you. See Cookies.
- Server logs
Standard request logs (IP, timestamp, path) retained briefly for security and debugging.
What we don't collect
- Browsing outside indexmeai.com
No cross-site tracking. We don't buy or use third-party data.
- Sensitive categories
No race, religion, sexual orientation, biometric, or health data.
- Children
We don't knowingly serve users under 18. Don't use IndexMeAI if you're under 18.
Your rights
- Access / export
Email us and we'll send everything we have on you within 30 days.
- Deletion
Delete your account yourself from your account page (bottom of the page) — it removes your profile, subjects, readings and their public permalinks immediately. Or email us and we do it within 30 days. Billed payment records are kept where required by law (typically 7 years for accounting).
- Correction
Email us and we'll fix anything wrong.
- Publishing to the Index
Your readings are private to your account unless you publish one. Publishing is per-reading and opt-in from that subject's page, it puts the name, role, field, score and reading permalink on the Global AI Index labelled as self-published, and “Withdraw from the Index” on the same page removes the entry and its recorded history immediately.
- Opt out of analytics
Use the control in Cookies below — it switches analytics on or off on the spot and remembers the answer. If your browser sends Global Privacy Control or Do Not Track, we treat that as a decline and never ask. You can also email us to exclude your email from analytics.
If you're in the EU/UK, you can also file with your local data-protection authority. We'd rather you talk to us first, we read every email.
Pages about you — removal
Readings on this site describe how AI models answer questions about a person. If a page here is about you and you want it gone, email indexmeai.app@gmail.com with the link. We remove Global AI Index entries and reading permalinks within 7 days, no questions asked, and the removal is honored by our refresh jobs so the page doesn't come back. Pages about people someone else tracks are never submitted to search engines and carry a noindex instruction.
Retention
- Scan cache
Cached scan payloads, including the named subject and model responses, expire after 24 hours.
- Public permalinks
Stored for up to one year unless you delete the account or request earlier removal.
- Account scan history
Stored while the account is active so history and monitoring work; deleted with the account except where law requires otherwise.
- Cohort waitlist email
Until you ask us to delete or the product shuts down.
- Paid subscriber records
Required minimum for tax/accounting (typically 7 years).
- Analytics events
Our analytics provider's default retention (currently 7 years; we may shorten).
Security
All traffic is HTTPS. Secrets are stored in our host's encrypted environment, not in the codebase. We follow standard least-privilege access internally. We'll tell you in plain English if there's a breach affecting your data within 72 hours of discovery.
Changes
If we change this policy materially, we'll email everyone on the cohort waitlist and update the date at the top. Continued use after a material change means you accept it; you can always delete and walk away.