Skip to content
Privacy policy

How Index8 handles your information.

Last updated July 31, 2026. Questions: privacy@index8.app.

Who we are

Index8 is an operating intelligence platform for small businesses, operated from the United States. It reads your market, your competitors, and the context you share, then briefs you with sourced conclusions and recommended actions. This policy covers the public site at index8.app and the signed-in workspace.

What we collect

Account information: your name, work email, company name, and password (stored as a hash by our authentication provider, Supabase). Workspace content you choose to add: your business profile (company, market, goals, constraints), competitors you name, context notes you write, decisions you record and their outcomes, conversation messages, and team member names and emails you invite.

Workspace content Index8 produces for you: signals, analyses, insights, recommendations, and briefs, each carrying citations to the public sources it was built from.

Guided setup and research submissions on the public site: the details you give, your name, work email, and company, stored so we can follow up.

Technical information: server logs, a hashed (never raw) IP address for rate limiting and abuse prevention, and product analytics events that contain identifiers, plan names, and event names. Our analytics are configured without cookies, without session recording, and without collecting names, emails, or free-text answers.

What we never collect

Payment card details never touch Index8 servers; checkout and billing are handled by Stripe on Stripe-hosted pages. We ask you not to store regulated identifiers (Social Security numbers, full payment card numbers, login credentials) in workspace fields, and our guidance says the same.

How we use information

To run your workspace: research your market from public sources, prepare your brief, answer your questions in the conversation, send transactional email (sign-in, invitations, receipts), respond to support requests, and improve the product using the aggregated, non-identifying analytics described above. We do not sell personal information, and we do not use your workspace content for advertising.

Who can see your workspace

Your workspace is private to your organization. Every read and write is scoped to your organization in our application layer and protected by row-level security in our database. Index8 staff access customer data only when necessary to support you, and that access is logged. Public sharing happens only when you create a share link, which you can expire or revoke at any time.

Service providers

We use a small set of processors to run Index8: Anthropic (the model provider behind the intelligence engine), Supabase (authentication, database, file storage), Vercel (hosting), Stripe (payments), and, when configured, Sentry (error monitoring, scrubbed of personal data before sending), PostHog (cookieless product analytics), Resend (email delivery), and Upstash (rate limiting and engine job orchestration). Each receives only what its function requires. The full, versioned list is on our subprocessors page.

How the intelligence engine uses a model provider

The engine sends your business profile, the workspace content it has produced, and your conversation messages to Anthropic, our model provider, so it can research your market and draft conclusions. Research queries derived from your profile also run through Anthropic’s server-side web search, which means terms such as your company name and city can appear in searches against the public web.

This is processing on our instruction under our commercial agreement with the provider, not a sale or sharing of your data for anyone else’s purposes. For the provider’s own retention period and its handling commitments, see the entry for Anthropic on our subprocessors page.

Connected accounts

Index8 does not currently connect to your accounts at other services. If connectors ship, this policy will describe what they access, and how to disconnect, before they are available to you.

Retention and deletion

You can remove records from your workspace as you work; removed records are held briefly so accidental deletions can be recovered, then purged. To delete your account and workspace data entirely, contact privacy@index8.app and we will complete the deletion and confirm it to you.

Security

Traffic is encrypted in transit. Access is organization-scoped with role-based permissions, enforced in the application layer and by row-level security in the database. Staff access to customer data is limited to support needs and is logged. We describe our practices in more detail in our security posture. No vendor can promise perfect security, and we do not.

Your choices and rights

You can access and update your information in workspace settings and request a copy or deletion of your data at privacy@index8.app. Depending on where you live, you may have additional rights under laws such as the CCPA; we honor verified requests regardless of residence.

Changes

If this policy changes in a way that matters, we will update the date above and note the change on this page. Continued use after a change means the updated policy applies.