Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Indices Inc., a Delaware corporation (“Indices”, “we”, “us”, “our”), collects, uses, shares, and protects personal data when you use our services, including our website at indices.io, our platform, APIs, SDKs, CLI, and dashboard (together, the “Services”), or otherwise interact with us.
“Personal data” means information relating to an identified or identifiable individual. Capitalised terms not defined here have the meanings given in the Indices Terms of Service at https://indices.io/terms/ (the “Terms”).
If your personal data reached us through a customer’s use of the Services, that customer is the controller. Please direct privacy requests to the customer.
1. Personal data we collect as controller
Data you provide to us:
- Account data: name, email address, organisation name, password or other authentication information, and account settings.
- Billing data: billing contact and address, tax identifiers, and payment method details. Payment card information is processed by our payment processor, not stored by us.
- Communications: support requests, sales enquiries, shared support channels such as Slack or Discord, or other communications with us.
- Support information: technical issue descriptions, error reports, screenshots, logs, configuration details, or other information you provide when requesting support.
- Marketing data: subscription preferences and interactions with our emails.
Data we collect automatically:
- Usage data: Connector and Run activity metadata, API request metadata, and dashboard interactions including pages viewed.
- Device and log data: Including IP address, browser type, operating system, device identifiers, and server logs, browser information and web page referrers, mobile network, connection information, mobile operator or internet service provider (ISP), time zone setting, geolocation, telemetry and performance traces.
- Cookies: as described in Section 10.
Data from other sources: We may receive information from third parties, including authentication providers such as Google or GitHub, payment processors, analytics providers, business partners.
We do not intentionally collect special categories of personal data as a controller.
2. How and why we use personal data
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Providing the Services, operating accounts, authentication | Account, usage, device data | Contract (Art. 6(1)(b)); legitimate interests where you act for an organisation |
| Billing, metering Runs, invoicing, tax and accounting | Account, billing, usage data | Contract; legal obligation (Art. 6(1)(c)) |
| Service operations: monitoring, debugging, incident response | Usage, telemetry, log data | Legitimate interests (Art. 6(1)(f)) |
| Security: fraud and abuse prevention, enforcing acceptable use, protecting Customer Credentials | Usage, device, log data | Legitimate interests; legal obligation where applicable |
| Improving the Services, including aggregated usage insights (Section 4.1 of the Terms) | Usage data, feedback | Legitimate interests; aggregated or de-identified wherever practicable |
| Support and service communications | Account data, communications | Contract; legitimate interests |
| Marketing to business contacts | Contact, marketing data | Legitimate interests; consent where required (you may opt out at any time) |
| Legal compliance and claims | As relevant | Legal obligation; legitimate interests |
| Corporate transactions | As relevant | Legitimate interests |
You may object to processing based on legitimate interests and withdraw consent at any time (Section 8). We do not use personal data for automated decision-making with legal or similarly significant effects.
3. Customer Content
We process personal data in Customer Content (including Customer Credentials and personal data in Outputs retrieved from Third-Party Systems) as a processor, on our customers’ documented instructions, under the Terms and our Data Processing Addendum (the “DPA”).
4. How we share personal data
- Sub-processors and service providers, under contracts consistent with this Policy and the DPA. Our current sub-processors and vendors that may process personal data or Customer Content on our behalf include Google Cloud Platform, Cloudflare, WorkOS, Stripe, Metronome, Dash0, PostHog, Sentry, Slack, Kernel, Loops, OpenAI, Anthropic, SpaceXAI, and OpenRouter. This list may be updated from time to time as our vendor relationships change. All use of LLM providers is subject to zero data retention agreements.
- Affiliates: our group companies, affiliates, and related entities.
- Your Organization: If your account is part of an organization, or you use an email address owned by your employer or another organization, then information about your account and use of the Services may be available to that organization’s administrators.
- Corporate transaction parties: in a financing, merger, acquisition, bankruptcy, or other situation involving the transfer of business assets, Indices may receive or disclose your personal data as part of these corporate transactions.
- Business partners including our professional advisers.
- Third-Party websites, integrations, and services as necessary to execute your instructions, such as communicating with third-party systems called as part of a Connector. Indices does not control, and is not responsible for, the data practices of Third-Party Services. Before creating or using a Connector, you should ensure you have the authority to grant such access and that doing so complies with any applicable terms, policies, or confidentiality obligations, and that you have reviewed that third party’s privacy policy.
- Authorities where required by law: to comply with legal obligations, enforce our Terms, or protect the rights, property, or safety of Indices, our customers, or others.
- Aggregated or de-identified information: We may disclose aggregated or de-identified information that does not reasonably identify you or your organization, for example to publish research into how our Services are used.
Indices does not sell Customer Content.
5. International transfers
Our primary service infrastructure is hosted in the United States, European Economic Area and United Kingdom. Personal data may be accessed from or transferred to any of these locations, and other countries where we or our service providers operate. Where transfers of GDPR- or UK GDPR-protected data leave the relevant jurisdiction, we ensure it benefits from an adequate level of data protection by relying on: adequacy decisions; or the EU Standard Contractual Clauses and, for UK transfers, the UK Addendum or IDTA.
6. Retention
Indices retains your personal data for as long as reasonably necessary for the purposes and criteria outlined in this Privacy Policy.
In particular:
- Account and billing data: for the life of the account, then as required for tax and legal purposes (typically up to seven years for financial records).
- Usage and log data: for periods appropriate to operations, security, and billing, then deleted or aggregated.
- Communications and marketing data: for as long as relevant, or until you opt out or ask us to delete them.
- Retention of Customer Content is governed by the DPA and the customer’s configuration.
7. Security
We implement commercially reasonable technical and organisational measures to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. This includes encryption in transit and at rest, secrets management for Customer Credentials, least-privilege access controls, and logging and monitoring.
8. Your rights (EEA and UK)
Subject to conditions under applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict processing; data portability; object to processing based on legitimate interests, and to direct marketing at any time; and withdraw consent at any time.
To exercise these rights, contact support@indices.io. We may verify your identity and will respond within the timescales required by law. If your data was submitted by one of our customers, we will refer your request to that customer.
You may have the right to lodge a complaint with your supervisory authority: in the UK, the Information Commissioner’s Office; in the EEA, the authority in your country.
9. US state privacy notice
We collect the categories of personal information in Section 1 for the purposes in Section 2. We do not sell personal information or share it for cross-context behavioural advertising. Depending on your state, you may have rights to access, correct, delete, or obtain a copy of your personal information; contact support@indices.io. Where we process personal information for a business customer, we act as a “service provider” under those laws.
10. Cookies
The Services use cookies that are strictly necessary for operation (authentication, session management, security) and, where enabled, analytics cookies. Where required by law, we will ask for consent before setting non-essential cookies. You can also manage cookies in your browser. If you disable cookies, some parts of the website or Services may not function properly.
11. Children
The Services are for business users and are not directed to children under 18. We do not knowingly collect children’s personal data; if you believe a child has provided us personal data, contact support@indices.io and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a revised “Last updated” date.
13. Contact
Indices Inc. Email: support@indices.io