Privacy Policy
Last Updated: 20 July 2026
This policy explains what personal data Indiexa collects, what we do with it, who else gets to see it, and what you can ask us to do about any of it. It covers indiexa.com and everything you can do there, whether or not you have an account.
Where something might surprise you, we've tried to say so plainly rather than bury it in a longer sentence. There are three things in particular worth reading before anything else: your net worth is shown publicly on the leaderboard, the fingerprint we keep instead of your IP address is scrambled but is still information about you, and an account that owns a listed product can't be deleted until that product is removed or transferred.
I. Who we are and how to reach us.
Indiexa is a virtual stock market for indie products. Developers list what they've built, and other people trade those listings using Credits, which are an in-app unit. No real money changes hands in trading. Real money only comes into it when you buy a subscription or a one-off purchase, and those go through Polar as merchant of record.
Indiexa is the controller of the personal data described here, which means we're the ones who decide what gets collected and why. Indiexa is operated by its proprietor, Apoorv Sharma, who is also the Grievance Officer named in section XI. We don't publish a postal address, so the contact routes below are the ones that reach us.
For anything to do with your data, including any of the requests described in section VII, write to privacy@indiexa.com. If you're not happy with how we've handled something, you can also complain to the data protection supervisory authority for the country where you live or work, or contact the Grievance Officer in section XI.
If you need this policy in a different format, ask at privacy@indiexa.com and we'll provide one.
II. What we collect and why.
Everything we hold reaches us in one of three ways: you give it to us directly, such as when you fill in your profile or write a post; we collect it automatically as you use the site, such as the session and security records below; or a third party passes it to us, such as a sign-in provider sharing your name and email, or Polar reporting the outcome of a payment.
The tables below set out what we hold in each area, what it's for, the lawful basis we rely on under the GDPR, and how long it stays. Four bases come up:
- Contract. We need the data to give you the thing you signed up for.
- Legitimate interests. We have a practical reason, usually security or keeping the platform usable, that we've weighed against your privacy.
- Consent. You chose to turn it on, and you can turn it off again.
- Legal obligation. The law requires us to keep it.
Account and profile
Your bio, pronouns, location, website and social links are optional, and whatever you put in them appears on your public profile. You can clear any of them at any time.
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Email address | Signing you in, verifying your address, and sending account and billing notices | Contract | Life of the account |
| Name, username and display username | Identifying you across the site and on your public profile | Contract | Life of the account |
| Avatar image | Shown on your profile, your posts and the leaderboard | Contract | Life of the account |
| Bio (up to 160 characters), pronouns, location, website and social links | Optional profile details you choose to publish | Contract | Life of the account |
| Email-verified flag, two-factor-enabled flag, founder flag | Knowing which features and protections apply to your account | Contract | Life of the account |
Signing in and keeping your account secure
We never store your password. What we store is an Argon2id hash of it, which is a one-way transformation we can check a login against but can't turn back into your password. OAuth tokens from social sign-in are encrypted at rest, and so are your two-factor secret and backup codes if you've set up 2FA.
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Password hash | Checking your password at sign-in without holding the password | Contract, and our legitimate interest in account security | Life of the account |
| OAuth tokens (encrypted) | Keeping social sign-in working | Contract | Life of the account |
| Two-factor secret and backup codes (encrypted) | Second-factor verification and account recovery | Contract, and our legitimate interest in account security | Life of the account |
| Sessions, including the IP address and browser user-agent of each sign-in | Keeping you signed in, showing you your active sessions, and spotting suspicious access | Contract, and our legitimate interest in account security | Deleted 30 days after the session expires |
| Verification records, holding the email being verified and the magic-link or OTP value | Completing email verification, magic-link sign-in and one-time codes | Contract | Deleted 7 days after the record expires |
Note that sessions record your raw IP address, not a hashed one. That's different from the abuse signals described further down, and it's deliberate, because showing you a list of where your account has been signed in from only works if the address is readable.
You can sign in with an email and password, a magic link, an emailed one-time code, or through Google, Apple, GitHub or X (Twitter). Choosing one of those providers means sharing data with that provider, and what they do with it is covered by their own privacy policy rather than this one.
Trading, holdings and your net worth
The whale leaderboard is public, and it displays your name, username, avatar and location next to your net worth and your quarterly earnings. Anyone can see it, including people who don't have an account. It's a public statement about your financial position in the market attached to your real identity, and it's the part of Indiexa people are least likely to expect. The figures are in Credits rather than money, but the ranking is still tied to you by name and photo. If you'd rather your location weren't part of that, clear it from your profile.
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Holdings and Credits balance | Running your portfolio and calculating what you can trade | Contract | Life of the account |
| Full buy and sell transaction history | Showing your history, and keeping the market auditable and fair | Contract | Life of the account |
| Streaks and missions | Awarding Credits for activity | Contract | Life of the account |
| Net-worth snapshots | Charting how your position changes over time, and ranking the leaderboard | Contract | Daily snapshots for 180 days, weekly for 1 year, monthly kept long-term |
Billing
Your card details never touch Indiexa's servers. Polar acts as merchant of record and collects payment details on its own hosted checkout, so what comes back to us is the outcome of a payment rather than the payment instrument.
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Subscription and order records, amounts, currency, status and refunds | Giving you what you paid for, and handling refunds and disputes | Contract, and legal obligation for accounting records | Life of the account |
| Plan capacity and checkout attempts | Applying your listing capacity and diagnosing failed checkouts | Contract | Life of the account |
| Polar customer, subscription and order identifiers | Matching your Indiexa account to your purchases | Contract | Life of the account |
| Raw billing webhook payloads | Reconciling payment events and investigating billing problems | Legitimate interest in getting billing right | Deleted after 90 days |
What you post
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Takes (up to 280 characters), forum posts and comments written in markdown | Publishing what you wrote | Contract | Life of the account, subject to section VIII |
| Votes, likes, follows and saved products | Running feeds, rankings and your saved list | Contract | Life of the account |
| Product listings, team member entries, promoted products and verified domains | Running the listings you create and confirming you control a domain | Contract | Life of the account |
Anything you post publicly is visible to anyone, including people without an account, and can be indexed by search engines.
Images you upload
Avatars, product logos and images attached to posts are stored on Cloudflare R2 and served from public URLs. That means anyone who has the URL can open the image, so treat an uploaded image as public even before you attach it to anything.
We strip EXIF, XMP and IPTC metadata from every image before we store it. Photos routinely carry the GPS coordinates where they were taken along with camera and device details, and that data is discarded rather than stored, so it never reaches our storage or the public URL.
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Avatar, product logo and post image files | Displaying the images you upload | Contract | Life of the account, subject to section VIII |
Reports
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Reports about products and users, including the free-text explanation you write | Investigating what you've reported and keeping the platform safe | Legitimate interest in platform safety | Life of the reporting account |
Bear in mind that a free-text field is a free-text field. Whatever you write there, we keep.
Sensitive information
We never ask for special category data: nothing about your health, political opinions, religious beliefs, sexual orientation, trade union membership, or biometric or genetic data. But free-text fields exist, in your bio, your posts and comments, report explanations and support messages, and whatever you type there is stored exactly as written. Nothing scans for that kind of detail or filters it out, so please don't put it in. If you do, it's held on the same basis and for the same period as the rest of that field.
Forms you can use without an account
Three forms work without signing in. Each one keeps only what it needs, and each has its own clock.
| What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|
| Pitch form: product URL and pitch text | Reviewing products pitched to us | Legitimate interest in reviewing submissions | 6 months |
| Support form: reply email address and message | Answering you | Legitimate interest in providing support | 12 months |
| Sponsor form: email, name, destination site, week and bid amount | Handling sponsorship enquiries | Legitimate interest in handling enquiries | 12 months |
All three also store a scrambled fingerprint of your IP address, an anonymous identifier generated by your browser, and a shortened version of your user-agent string, so that a form open to the public can't be flooded. That's the same fingerprinting described next.
Security and abuse signals
For rate limiting and abuse prevention we don't store your IP address. We run it through a keyed hash (HMAC-SHA256, using a secret only we hold) and keep the result instead.
We want to be straight about what that does and doesn't achieve, because it's often oversold. The stored value can't be read back into an address, so someone who obtained our records couldn't work out where you were. It is still information about you. The same address always produces the same value, which is exactly the point, since that's how we recognise repeated behaviour from one place. And because we hold the key, we could take an address we already suspect and test whether it matches. So it's a scrambled fingerprint, not anonymous data. We treat it as personal data and so should you.
There's one deliberate exception. Records of security events, such as failed sign-in attempts, blocked requests and rate limiting, do hold the raw address, because a security record that can't tell you where something came from isn't much of a security record.
We rely on our legitimate interest in network and information security for all of this.
Analytics
Analytics is off until you turn it on. Nothing is captured and PostHog isn't loaded before you agree in the consent banner. If your browser sends a Global Privacy Control signal, we read that as an opt-out and act on it automatically, so you don't have to do anything else.
Autocapture is switched off, so we're not recording every click and interaction on the page. Page views are sent by us at specific moments rather than collected automatically.
If you do turn analytics on, PostHog receives your email address, name, username and plan as identifying traits, along with the events you trigger, the page URLs you visit, information about your device and browser, and your IP address.
Session replay is a separate thing and a separate decision. It's off by default, it only ever runs on the getting-started and pricing pages, it requires its own consent on top of analytics consent, and all on-page text is masked in the recordings it produces.
Aggregate product view counts work differently again. They're counted using a salted hash that rotates and expires within days, and only the totals are kept, so the counter on a product page isn't a list of who looked at it.
We rely on your consent for all analytics, and you can withdraw it at any time in the cookie settings without emailing anyone.
III. Who else sees your data.
We use a small number of service providers to run Indiexa. With one exception, noted below the table, they process data on our instructions and for the purposes below, and nothing more.
| Who | What they receive | What for | Worth knowing |
|---|---|---|---|
| Resend | Your email address and the content of transactional emails | Sending sign-in, verification and notification email | |
| Polar | Your email address and name | Subscriptions and payments, as merchant of record | Collects card details directly on its own checkout, so we never see them |
| PostHog | Email, name, username, plan, events, page URLs, device information and IP address | Product analytics and session replay | Only after you consent. Hosted in the United States |
| Cloudflare Turnstile | Your raw IP address and browser information | Checking that a human submitted a form | Runs on sign-in, sign-up, password reset, magic link, and the three public forms |
| Cloudflare R2 | The image files you upload | Storing and serving images | |
| Sentry | Error reports containing your user ID and username | Diagnosing crashes | Production only. No email address and no IP address |
| Axiom | Server logs: hashed IP, user-agent, referer, requested URL and user ID | Operating and debugging the service | Production only. Email addresses are scrubbed from logs |
Polar is the exception. Polar is the merchant of record for anything you buy, which means Polar is the seller and we aren't. For your purchase, Polar decides for itself what it needs to do with your details, because it carries the legal duties that come with selling: tax, invoicing, chargebacks and fraud checks. So for what it collects at its own checkout, Polar isn't only acting on our instructions, and its own privacy policy governs what it does with that. For the account details we send Polar so a purchase can be matched to your Indiexa account, it does act on our instructions.
We don't sell personal information, and we don't share it for cross-context behavioural advertising.
Three cases where data goes somewhere not in that table
We'll disclose personal data when we're legally required to, such as under a court order or a valid request from law enforcement. We'll disclose it where we believe in good faith that doing so will prevent imminent harm to someone. And if Indiexa is ever sold, merged into a company, or transferred to a new operator, your data goes with it, in which case we'll tell you before it happens rather than after.
Links to other sites
Posts on Indiexa are written in markdown, and a post can contain a link to somewhere else. Following one takes you to a site we don't run, and whatever that site collects is covered by its own privacy policy rather than this one.
Markdown posts can't embed images or other content hosted elsewhere. We strip those before anything is rendered, because an embedded image would make your browser fetch it directly from whoever hosts it and hand that host your IP address, your browser and the page you came from, just by you reading the post. Images that do appear on Indiexa are ones somebody uploaded to us, served from our own storage.
IV. Where your data goes.
Indiexa's own servers and database run in the United States, and so do all of the providers listed above. Wherever you are, using Indiexa means your personal data is transferred to and processed in the United States. Those transfers rely on the standard contractual clauses each provider has in place. We're not claiming any certification or adequacy decision beyond that.
V. Keeping your data secure.
Passwords are stored as Argon2id hashes and never in a readable form. OAuth tokens, two-factor secrets and backup codes are encrypted at rest. Traffic to and from the site runs over HTTPS. Image uploads have their EXIF, XMP and IPTC metadata stripped before storage, and IP addresses used for rate limiting are kept as keyed hashes rather than addresses.
None of that makes anything perfectly safe, and no service can honestly claim otherwise. Use a password you don't use anywhere else, and turn on two-factor authentication if you haven't.
VI. How long we keep things.
Most of what's tied to your account stays for the life of the account and goes when the account goes, with the exceptions in section VIII. The specific clocks are:
- Sessions: deleted 30 days after the session expires.
- Verification records: deleted 7 days after the record expires.
- Net-worth snapshots: daily for 180 days, weekly for 1 year, monthly kept long-term.
- Raw billing webhook payloads: deleted after 90 days.
- Pitch form submissions: 6 months.
- Support form submissions: 12 months.
- Sponsor form submissions: 12 months.
- Deletion records: 90 days, as described in section VIII.
VII. Your rights and how to use them.
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct anything that's wrong (rectification);
- delete your data (erasure);
- pause our use of it while something is being sorted out (restriction);
- stop processing that relies on our legitimate interests (objection);
- hand your data over in a portable format (portability); and
- withdraw consent you've given, at any time, without that affecting anything we did while it was in place.
You can also complain to your local data protection supervisory authority. You don't have to come to us first, though we'd rather you did so we can fix it.
Separately, and regardless of where you live, we'll honour a request from anyone to know what we collect about them, to have it deleted, to have it corrected, and we won't treat you any differently for asking. We offer these because they're reasonable, not because we're conceding that any particular law requires them of us.
To use any of these, email privacy@indiexa.com. We'll respond within one month. Withdrawing analytics consent doesn't need an email at all, since it's a toggle in the cookie settings.
If we refuse a request, we'll explain why, and you can ask us to look at it again by replying to the same address. You can also go to your supervisory authority at any point without asking us first.
VIII. What happens when you delete your account.
Deleting your account removes your account and profile, your holdings, your trading history, your notifications, your saved products, your follows, your avatar and your billing records.
Some things stay, and here's each one with the reason:
- Your posts, comments and takes stay up. They're re-attributed to "Deleted user" and the link back to your account is removed. Deleting them outright would tear holes in conversations that other people took part in, leaving replies pointing at nothing.
- Images attached to those posts stay, because they're part of the post rather than part of your profile.
- Support messages you sent. The link to your account and your email address are erased straight away. The text of the message stays until its 12-month clock runs out.
- A deletion record is kept for 90 days. It holds no name and no email address, only the internal identifiers we need so that a late webhook from the payment provider can't quietly re-create the account you just deleted.
Two things block deletion outright rather than making it partial, and you'll need to clear both before the account will go.
If your account owns a listed product, you can't delete the account until that product is removed or transferred to someone else. This isn't us making it difficult. Other people hold positions in that product, and silently removing the owner would destroy every one of those positions along with the account. Removing the product yourself triggers the proper process for the people holding it. Once that's done, or once the listing belongs to someone else, deletion goes through normally.
If you have an active subscription, you'll need to cancel it first. That way billing stops cleanly instead of renewing against an account that no longer exists. The Terms of Service set out both of these requirements as well.
IX. Cookies and similar technology.
The Cookie Policy lists every cookie and browser storage key we use, what each one is for, how long it lasts, which consent category it falls into, and how the Global Privacy Control signal is handled. It's the complete list, so we won't repeat it here. You can change or withdraw your choices there at any time.
X. Children.
Indiexa isn't intended for anyone under 13, and you shouldn't create an account or use the site if you're under 13. If you're under 18, the Terms of Service require the approval of your parent or guardian before you use Indiexa.
XI. Grievance Officer and complaints.
In accordance with the Information Technology Act, 2000 and rules made thereunder and the Consumer Protection (E-Commerce) Rules, 2020, the contact details of the Grievance Officer are provided below. The Grievance Officer may be contacted in respect of any complaint about how your personal data has been handled.
Grievance Officer: Apoorv Sharma
Email: apoorv@indiexa.com
This sits alongside the routes in section VII rather than replacing them. You can still email privacy@indiexa.com for an ordinary request, and you can still complain to your local data protection supervisory authority without coming to us first.
XII. Changes to this policy.
The "Last Updated" date at the top of this page reflects the last substantive change we made to it. It's set by hand rather than generated, so it can't quietly say "today" on a page that hasn't actually changed.
If we make a material change, one that affects what we collect, what we do with it, or who receives it, we'll tell you rather than relying on you noticing the date.
Questions about any of this?
Email: privacy@indiexa.com