Skip to main content

Privacy Policy

Last Updated: 20 July 2026

This policy explains what personal data Indiexa collects, what we do with it, who else gets to see it, and what you can ask us to do about any of it. It covers indiexa.com and everything you can do there, whether or not you have an account.

Where something might surprise you, we've tried to say so plainly rather than bury it in a longer sentence. There are three things in particular worth reading before anything else: your net worth is shown publicly on the leaderboard, the fingerprint we keep instead of your IP address is scrambled but is still information about you, and an account that owns a listed product can't be deleted until that product is removed or transferred.

I. Who we are and how to reach us.

Indiexa is a virtual stock market for indie products. Developers list what they've built, and other people trade those listings using Credits, which are an in-app unit. No real money changes hands in trading. Real money only comes into it when you buy a subscription or a one-off purchase, and those go through Polar as merchant of record.

Indiexa is the controller of the personal data described here, which means we're the ones who decide what gets collected and why. Indiexa is operated by its proprietor, Apoorv Sharma, who is also the Grievance Officer named in section XI. We don't publish a postal address, so the contact routes below are the ones that reach us.

For anything to do with your data, including any of the requests described in section VII, write to privacy@indiexa.com. If you're not happy with how we've handled something, you can also complain to the data protection supervisory authority for the country where you live or work, or contact the Grievance Officer in section XI.

If you need this policy in a different format, ask at privacy@indiexa.com and we'll provide one.

II. What we collect and why.

Everything we hold reaches us in one of three ways: you give it to us directly, such as when you fill in your profile or write a post; we collect it automatically as you use the site, such as the session and security records below; or a third party passes it to us, such as a sign-in provider sharing your name and email, or Polar reporting the outcome of a payment.

The tables below set out what we hold in each area, what it's for, the lawful basis we rely on under the GDPR, and how long it stays. Four bases come up:

  • Contract. We need the data to give you the thing you signed up for.
  • Legitimate interests. We have a practical reason, usually security or keeping the platform usable, that we've weighed against your privacy.
  • Consent. You chose to turn it on, and you can turn it off again.
  • Legal obligation. The law requires us to keep it.

Account and profile

Your bio, pronouns, location, website and social links are optional, and whatever you put in them appears on your public profile. You can clear any of them at any time.

What we collectWhyLawful basisHow long we keep it
Email addressSigning you in, verifying your address, and sending account and billing noticesContractLife of the account
Name, username and display usernameIdentifying you across the site and on your public profileContractLife of the account
Avatar imageShown on your profile, your posts and the leaderboardContractLife of the account
Bio (up to 160 characters), pronouns, location, website and social linksOptional profile details you choose to publishContractLife of the account
Email-verified flag, two-factor-enabled flag, founder flagKnowing which features and protections apply to your accountContractLife of the account

Signing in and keeping your account secure

We never store your password. What we store is an Argon2id hash of it, which is a one-way transformation we can check a login against but can't turn back into your password. OAuth tokens from social sign-in are encrypted at rest, and so are your two-factor secret and backup codes if you've set up 2FA.

What we collectWhyLawful basisHow long we keep it
Password hashChecking your password at sign-in without holding the passwordContract, and our legitimate interest in account securityLife of the account
OAuth tokens (encrypted)Keeping social sign-in workingContractLife of the account
Two-factor secret and backup codes (encrypted)Second-factor verification and account recoveryContract, and our legitimate interest in account securityLife of the account
Sessions, including the IP address and browser user-agent of each sign-inKeeping you signed in, showing you your active sessions, and spotting suspicious accessContract, and our legitimate interest in account securityDeleted 30 days after the session expires
Verification records, holding the email being verified and the magic-link or OTP valueCompleting email verification, magic-link sign-in and one-time codesContractDeleted 7 days after the record expires

Note that sessions record your raw IP address, not a hashed one. That's different from the abuse signals described further down, and it's deliberate, because showing you a list of where your account has been signed in from only works if the address is readable.

You can sign in with an email and password, a magic link, an emailed one-time code, or through Google, Apple, GitHub or X (Twitter). Choosing one of those providers means sharing data with that provider, and what they do with it is covered by their own privacy policy rather than this one.

Trading, holdings and your net worth

The whale leaderboard is public, and it displays your name, username, avatar and location next to your net worth and your quarterly earnings. Anyone can see it, including people who don't have an account. It's a public statement about your financial position in the market attached to your real identity, and it's the part of Indiexa people are least likely to expect. The figures are in Credits rather than money, but the ranking is still tied to you by name and photo. If you'd rather your location weren't part of that, clear it from your profile.

What we collectWhyLawful basisHow long we keep it
Holdings and Credits balanceRunning your portfolio and calculating what you can tradeContractLife of the account
Full buy and sell transaction historyShowing your history, and keeping the market auditable and fairContractLife of the account
Streaks and missionsAwarding Credits for activityContractLife of the account
Net-worth snapshotsCharting how your position changes over time, and ranking the leaderboardContractDaily snapshots for 180 days, weekly for 1 year, monthly kept long-term

Billing

Your card details never touch Indiexa's servers. Polar acts as merchant of record and collects payment details on its own hosted checkout, so what comes back to us is the outcome of a payment rather than the payment instrument.

What we collectWhyLawful basisHow long we keep it
Subscription and order records, amounts, currency, status and refundsGiving you what you paid for, and handling refunds and disputesContract, and legal obligation for accounting recordsLife of the account
Plan capacity and checkout attemptsApplying your listing capacity and diagnosing failed checkoutsContractLife of the account
Polar customer, subscription and order identifiersMatching your Indiexa account to your purchasesContractLife of the account
Raw billing webhook payloadsReconciling payment events and investigating billing problemsLegitimate interest in getting billing rightDeleted after 90 days

What you post

What we collectWhyLawful basisHow long we keep it
Takes (up to 280 characters), forum posts and comments written in markdownPublishing what you wroteContractLife of the account, subject to section VIII
Votes, likes, follows and saved productsRunning feeds, rankings and your saved listContractLife of the account
Product listings, team member entries, promoted products and verified domainsRunning the listings you create and confirming you control a domainContractLife of the account

Anything you post publicly is visible to anyone, including people without an account, and can be indexed by search engines.

Images you upload

Avatars, product logos and images attached to posts are stored on Cloudflare R2 and served from public URLs. That means anyone who has the URL can open the image, so treat an uploaded image as public even before you attach it to anything.

We strip EXIF, XMP and IPTC metadata from every image before we store it. Photos routinely carry the GPS coordinates where they were taken along with camera and device details, and that data is discarded rather than stored, so it never reaches our storage or the public URL.

What we collectWhyLawful basisHow long we keep it
Avatar, product logo and post image filesDisplaying the images you uploadContractLife of the account, subject to section VIII

Reports

What we collectWhyLawful basisHow long we keep it
Reports about products and users, including the free-text explanation you writeInvestigating what you've reported and keeping the platform safeLegitimate interest in platform safetyLife of the reporting account

Bear in mind that a free-text field is a free-text field. Whatever you write there, we keep.

Sensitive information

We never ask for special category data: nothing about your health, political opinions, religious beliefs, sexual orientation, trade union membership, or biometric or genetic data. But free-text fields exist, in your bio, your posts and comments, report explanations and support messages, and whatever you type there is stored exactly as written. Nothing scans for that kind of detail or filters it out, so please don't put it in. If you do, it's held on the same basis and for the same period as the rest of that field.

Forms you can use without an account

Three forms work without signing in. Each one keeps only what it needs, and each has its own clock.

What we collectWhyLawful basisHow long we keep it
Pitch form: product URL and pitch textReviewing products pitched to usLegitimate interest in reviewing submissions6 months
Support form: reply email address and messageAnswering youLegitimate interest in providing support12 months
Sponsor form: email, name, destination site, week and bid amountHandling sponsorship enquiriesLegitimate interest in handling enquiries12 months

All three also store a scrambled fingerprint of your IP address, an anonymous identifier generated by your browser, and a shortened version of your user-agent string, so that a form open to the public can't be flooded. That's the same fingerprinting described next.

Security and abuse signals

For rate limiting and abuse prevention we don't store your IP address. We run it through a keyed hash (HMAC-SHA256, using a secret only we hold) and keep the result instead.

We want to be straight about what that does and doesn't achieve, because it's often oversold. The stored value can't be read back into an address, so someone who obtained our records couldn't work out where you were. It is still information about you. The same address always produces the same value, which is exactly the point, since that's how we recognise repeated behaviour from one place. And because we hold the key, we could take an address we already suspect and test whether it matches. So it's a scrambled fingerprint, not anonymous data. We treat it as personal data and so should you.

There's one deliberate exception. Records of security events, such as failed sign-in attempts, blocked requests and rate limiting, do hold the raw address, because a security record that can't tell you where something came from isn't much of a security record.

We rely on our legitimate interest in network and information security for all of this.

Analytics

Analytics is off until you turn it on. Nothing is captured and PostHog isn't loaded before you agree in the consent banner. If your browser sends a Global Privacy Control signal, we read that as an opt-out and act on it automatically, so you don't have to do anything else.

Autocapture is switched off, so we're not recording every click and interaction on the page. Page views are sent by us at specific moments rather than collected automatically.

If you do turn analytics on, PostHog receives your email address, name, username and plan as identifying traits, along with the events you trigger, the page URLs you visit, information about your device and browser, and your IP address.

Session replay is a separate thing and a separate decision. It's off by default, it only ever runs on the getting-started and pricing pages, it requires its own consent on top of analytics consent, and all on-page text is masked in the recordings it produces.

Aggregate product view counts work differently again. They're counted using a salted hash that rotates and expires within days, and only the totals are kept, so the counter on a product page isn't a list of who looked at it.

We rely on your consent for all analytics, and you can withdraw it at any time in the cookie settings without emailing anyone.

III. Who else sees your data.

We use a small number of service providers to run Indiexa. With one exception, noted below the table, they process data on our instructions and for the purposes below, and nothing more.

WhoWhat they receiveWhat forWorth knowing
ResendYour email address and the content of transactional emailsSending sign-in, verification and notification email
PolarYour email address and nameSubscriptions and payments, as merchant of recordCollects card details directly on its own checkout, so we never see them
PostHogEmail, name, username, plan, events, page URLs, device information and IP addressProduct analytics and session replayOnly after you consent. Hosted in the United States
Cloudflare TurnstileYour raw IP address and browser informationChecking that a human submitted a formRuns on sign-in, sign-up, password reset, magic link, and the three public forms
Cloudflare R2The image files you uploadStoring and serving images
SentryError reports containing your user ID and usernameDiagnosing crashesProduction only. No email address and no IP address
AxiomServer logs: hashed IP, user-agent, referer, requested URL and user IDOperating and debugging the serviceProduction only. Email addresses are scrubbed from logs

Polar is the exception. Polar is the merchant of record for anything you buy, which means Polar is the seller and we aren't. For your purchase, Polar decides for itself what it needs to do with your details, because it carries the legal duties that come with selling: tax, invoicing, chargebacks and fraud checks. So for what it collects at its own checkout, Polar isn't only acting on our instructions, and its own privacy policy governs what it does with that. For the account details we send Polar so a purchase can be matched to your Indiexa account, it does act on our instructions.

We don't sell personal information, and we don't share it for cross-context behavioural advertising.

Three cases where data goes somewhere not in that table

We'll disclose personal data when we're legally required to, such as under a court order or a valid request from law enforcement. We'll disclose it where we believe in good faith that doing so will prevent imminent harm to someone. And if Indiexa is ever sold, merged into a company, or transferred to a new operator, your data goes with it, in which case we'll tell you before it happens rather than after.

Links to other sites

Posts on Indiexa are written in markdown, and a post can contain a link to somewhere else. Following one takes you to a site we don't run, and whatever that site collects is covered by its own privacy policy rather than this one.

Markdown posts can't embed images or other content hosted elsewhere. We strip those before anything is rendered, because an embedded image would make your browser fetch it directly from whoever hosts it and hand that host your IP address, your browser and the page you came from, just by you reading the post. Images that do appear on Indiexa are ones somebody uploaded to us, served from our own storage.

IV. Where your data goes.

Indiexa's own servers and database run in the United States, and so do all of the providers listed above. Wherever you are, using Indiexa means your personal data is transferred to and processed in the United States. Those transfers rely on the standard contractual clauses each provider has in place. We're not claiming any certification or adequacy decision beyond that.

V. Keeping your data secure.

Passwords are stored as Argon2id hashes and never in a readable form. OAuth tokens, two-factor secrets and backup codes are encrypted at rest. Traffic to and from the site runs over HTTPS. Image uploads have their EXIF, XMP and IPTC metadata stripped before storage, and IP addresses used for rate limiting are kept as keyed hashes rather than addresses.

None of that makes anything perfectly safe, and no service can honestly claim otherwise. Use a password you don't use anywhere else, and turn on two-factor authentication if you haven't.

VI. How long we keep things.

Most of what's tied to your account stays for the life of the account and goes when the account goes, with the exceptions in section VIII. The specific clocks are:

  • Sessions: deleted 30 days after the session expires.
  • Verification records: deleted 7 days after the record expires.
  • Net-worth snapshots: daily for 180 days, weekly for 1 year, monthly kept long-term.
  • Raw billing webhook payloads: deleted after 90 days.
  • Pitch form submissions: 6 months.
  • Support form submissions: 12 months.
  • Sponsor form submissions: 12 months.
  • Deletion records: 90 days, as described in section VIII.

VII. Your rights and how to use them.

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you (access);
  • correct anything that's wrong (rectification);
  • delete your data (erasure);
  • pause our use of it while something is being sorted out (restriction);
  • stop processing that relies on our legitimate interests (objection);
  • hand your data over in a portable format (portability); and
  • withdraw consent you've given, at any time, without that affecting anything we did while it was in place.

You can also complain to your local data protection supervisory authority. You don't have to come to us first, though we'd rather you did so we can fix it.

Separately, and regardless of where you live, we'll honour a request from anyone to know what we collect about them, to have it deleted, to have it corrected, and we won't treat you any differently for asking. We offer these because they're reasonable, not because we're conceding that any particular law requires them of us.

To use any of these, email privacy@indiexa.com. We'll respond within one month. Withdrawing analytics consent doesn't need an email at all, since it's a toggle in the cookie settings.

If we refuse a request, we'll explain why, and you can ask us to look at it again by replying to the same address. You can also go to your supervisory authority at any point without asking us first.

VIII. What happens when you delete your account.

Deleting your account removes your account and profile, your holdings, your trading history, your notifications, your saved products, your follows, your avatar and your billing records.

Some things stay, and here's each one with the reason:

  1. Your posts, comments and takes stay up. They're re-attributed to "Deleted user" and the link back to your account is removed. Deleting them outright would tear holes in conversations that other people took part in, leaving replies pointing at nothing.
  2. Images attached to those posts stay, because they're part of the post rather than part of your profile.
  3. Support messages you sent. The link to your account and your email address are erased straight away. The text of the message stays until its 12-month clock runs out.
  4. A deletion record is kept for 90 days. It holds no name and no email address, only the internal identifiers we need so that a late webhook from the payment provider can't quietly re-create the account you just deleted.

Two things block deletion outright rather than making it partial, and you'll need to clear both before the account will go.

If your account owns a listed product, you can't delete the account until that product is removed or transferred to someone else. This isn't us making it difficult. Other people hold positions in that product, and silently removing the owner would destroy every one of those positions along with the account. Removing the product yourself triggers the proper process for the people holding it. Once that's done, or once the listing belongs to someone else, deletion goes through normally.

If you have an active subscription, you'll need to cancel it first. That way billing stops cleanly instead of renewing against an account that no longer exists. The Terms of Service set out both of these requirements as well.

IX. Cookies and similar technology.

The Cookie Policy lists every cookie and browser storage key we use, what each one is for, how long it lasts, which consent category it falls into, and how the Global Privacy Control signal is handled. It's the complete list, so we won't repeat it here. You can change or withdraw your choices there at any time.

X. Children.

Indiexa isn't intended for anyone under 13, and you shouldn't create an account or use the site if you're under 13. If you're under 18, the Terms of Service require the approval of your parent or guardian before you use Indiexa.

XI. Grievance Officer and complaints.

In accordance with the Information Technology Act, 2000 and rules made thereunder and the Consumer Protection (E-Commerce) Rules, 2020, the contact details of the Grievance Officer are provided below. The Grievance Officer may be contacted in respect of any complaint about how your personal data has been handled.

Grievance Officer: Apoorv Sharma

Email: apoorv@indiexa.com

This sits alongside the routes in section VII rather than replacing them. You can still email privacy@indiexa.com for an ordinary request, and you can still complain to your local data protection supervisory authority without coming to us first.

XII. Changes to this policy.

The "Last Updated" date at the top of this page reflects the last substantive change we made to it. It's set by hand rather than generated, so it can't quietly say "today" on a page that hasn't actually changed.

If we make a material change, one that affects what we collect, what we do with it, or who receives it, we'll tell you rather than relying on you noticing the date.


Questions about any of this?

Email: privacy@indiexa.com