Skip to main content

Privacy Policy

Last updated: 2026-09-24

1. Introduction and Data Controller

Indexhog ("we", "us", or "our") is a search indexing and monitoring service for website owners, accessible via https://www.indexhog.com. The data controller responsible for your personal data is MB Laimingas Verslas, a Lithuanian small partnership (mažoji bendrija) registered under company code 302630890, VAT number LT100007071010, with registered office at Didlaukio g. 80-96, LT-08326 Vilnius, Lithuania, trading as Indexhog. Contact us about privacy at [email protected].

2. Our Two Roles: Controller and Processor

We act as controller for the data we need to run our own business: your account, organisation and membership records, billing history, support conversations, security and audit logs, and product analytics.

We act as processor for the data we handle on your instruction about the websites you monitor: your URL inventory and its monitoring results, and any data we retrieve from a search engine account you connect. We process that data only to provide the service, on your documented instructions, and we do not use it to train models, build profiles, or enrich datasets sold to anyone. If you need a data processing agreement for this activity, request one at [email protected].

3. Personal Data We Collect

  • Account information: name, email, password hash, and (if you use social login) the public profile information provided by Google, GitHub, LinkedIn, X, or Facebook. If you enable them: passkey credentials, two-factor secrets, and browser push subscriptions and tokens.
  • Organisation and project data: organisation name, members, roles and invitations, the domains you register as projects, ownership-verification tokens (DNS TXT records and IndexNow key values), API keys, and OAuth client registrations.
  • Monitoring data about your websites: the URLs in your inventory and how each was discovered; sitemap contents and fetch history; HTTP status codes, redirect targets and hop counts, error messages, response-content hashes; robots.txt, meta robots, X-Robots-Tag and canonical values; derived health, indexability and cadence states; issues; IndexNow submission history; daily counter snapshots; and any URL-list file you upload for import. This data describes web pages rather than people, but it can contain personal data if your own URLs or page content do.
  • Connected search engine data: if you connect Google Search Console, we store an encrypted OAuth refresh token, the property you selected, and the per-URL index state returned by Google's URL Inspection API. If you connect Bing Webmaster Tools, we store your API key encrypted and the per-URL index information Bing returns. We request read-only Search Console access, we do not request or receive your Google account password, and disconnecting revokes our access.
  • Billing data: subscription, purchase, and credit-ledger history. Card details are processed directly by Stripe and never stored on our servers.
  • Technical and security data: IP address, browser, device information, pages visited, timestamps, authentication events, audit logs, error reports, and device-fingerprint identifiers created for abuse prevention.

Do not submit special categories of personal data (health, biometric, political, etc.) or secrets to project names, imported URL lists, support messages, or other organisation content unless you have a lawful basis to do so.

4. Legal Basis and How We Use Your Data

We process personal data to provide accounts and organisations, discover and monitor your URLs, submit URLs to search engines on your instruction, retrieve index state from engines you connect, raise issues and send digests, run subscriptions and metering, provide API, MCP, and CLI access, deliver customer support, monitor security, prevent abuse, measure product usage, send transactional email, and meet legal obligations. Our legal bases are contract performance, legitimate interests, consent for non-essential analytics and marketing technologies, and legal obligation.

5. Your Monitoring Data Is Not Public

Projects, URL inventories, health and indexability states, index states, issues, and submission history are private to your organisation and visible only to its members and, where necessary, to our staff as described in section 9. The public parts of this site are our own marketing, blog, glossary, comparison, use-case, and documentation pages, together with the RSS, sitemap, and llms.txt surfaces generated from them; none of them contain customer monitoring data.

6. Website Retrieval

Monitoring requires retrieving pages from sites you register. We use service providers to perform those requests on our behalf, so their network addresses may appear in the site operator's logs. Retrieved page content and request metadata are processed only to provide monitoring, diagnose failed checks, and measure included usage. You may only register domains you own or are authorised to monitor.

7. Cookies and Tracking

We use essential cookies and local storage for authentication, sessions, preferences, saved articles, and security. We use device-fingerprint identifiers for fraud and abuse prevention. Simple Analytics and DataFast use cookieless trackers. Google Analytics and Meta Pixel load only after you accept the matching category in the consent banner, and you can change or withdraw that choice at any time.

Our Cookie Policy lists every cookie and storage entry we use, what each one does, and how long it lasts.

8. Third-Party Service Providers and Engine Transfers

We share personal data with service providers only to operate the service. As of the last update of this policy, those categories are:

  • Payment processing (Stripe): Taking payment, managing subscriptions, and handling refunds and disputes. Card details go directly to the processor and are never stored on our servers.
  • Identity providers: Verifying your identity when you choose to sign in with an external account. Only used if you pick social login.
  • Bot and abuse protection (Cloudflare Turnstile): Distinguishing human visitors from automated abuse on protected forms.
  • Analytics: Usage measurement. Simple Analytics and DataFast use cookieless trackers; Google Analytics and Meta Pixel load only after you accept the matching category.
  • Transactional and lifecycle email: Delivering account, security, billing, and notification email.
  • Error and performance monitoring: Recording application errors so we can diagnose and fix faults.
  • Push notification delivery: Delivering the notifications you opt in to through your browser. Receives the delivery token and the notification content.
  • Hosting, database, caching, and file storage: Running the platform and storing your account and uploaded content.
  • Website retrieval: Retrieving pages from domains you register so we can provide health and indexability monitoring.

We may add, remove, or replace providers with equivalent services. Business customers can request the complete list of named sub-processors as part of a data processing agreement. We do not sell your personal data. If you consent to advertising measurement, browser and event data may be disclosed to Meta under its Business Tools terms; Meta's role is governed by those terms.

Two transfers are inherent to the product and happen on your instruction:

  • Search engines you connect. When you connect Google Search Console or Bing Webmaster Tools, we call Google's and Microsoft's APIs with your credentials to read index state for your URLs. That use is governed by their terms and privacy policies in addition to this one.
  • IndexNow submissions. URLs you submit are sent to the IndexNow endpoint operated by Microsoft, which forwards them to participating search engines including Bing, Yandex, Naver, and Seznam. Some of those operators are established outside the European Economic Area, including in jurisdictions without an adequacy decision. Submitted URLs leave our control once forwarded, and a submission cannot be recalled. Only submit URLs that are intended to be public.

9. Staff Access and Support

Our staff can access account and monitoring data where necessary to operate the service, investigate abuse, or answer a support request. Administrators can, for support purposes, sign in as a user account; such sessions are recorded in the audit log and are shown in the product while they are active.

10. Data Retention and Your Export Responsibility

Account data is retained until you delete your account; deletion runs after a 30-day grace period, after which the account and its data are removed from active systems. Backup copies are held on a rolling 30-day cycle and are overwritten thereafter. Within the product we apply these windows: audit logs are kept for 90 days; per-URL submission records are kept for 90 days while the batch submission record is retained; URL-import history and uploaded import files are kept for 90 days; and deleted projects, URLs, sitemaps, and issues are purged permanently 180 days after deletion. Billing records are retained as required by applicable tax law. Before deleting your account you are responsible for exporting any inventory, issue, or submission data you wish to retain; once deleted, data may not be recoverable.

11. Data Security and International Transfers

We apply reasonable, industry-standard security measures including encryption in transit (TLS), hashed passwords, encryption at rest for search engine credentials, tenant isolation enforced in the database, and access controls. No method of transmission or storage is completely secure. You are responsible for keeping your credentials confidential, enabling available security features such as two-factor authentication, and notifying us of suspected unauthorised access at [email protected]. Your data may be processed in countries outside the European Economic Area where our infrastructure, analytics, payment, email, support, or security providers are located; such transfers rely on Standard Contractual Clauses approved by the European Commission or on transfers to jurisdictions that the Commission has determined provide an adequate level of data protection. The IndexNow forwarding described in section 8 is a separate transfer made on your instruction.

12. Your Data Protection Rights

We are established in the European Union, so these rights apply to your personal data wherever you are located. You have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.

You can export your personal data as structured JSON and request account deletion from account settings, or contact [email protected] to exercise any of these rights. We respond within one month of receiving your request; where a request is complex or you have made several requests, we may extend that period by up to two further months and will tell you within the first month if we do, as permitted by Article 12(3) GDPR.

You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate or with your local data protection supervisory authority. We do not make solely automated decisions concerning you that produce legal or similarly significant effects within the meaning of Article 22 GDPR. We will notify you without undue delay after becoming aware of a personal data breach likely to result in a high risk to your rights and freedoms, as required by Article 34 GDPR.

13. Children, Changes, and Contact

The service is not directed to individuals under 18 and our Terms of Service require account holders to be adults. We do not knowingly collect personal data from minors. We may update this Privacy Policy from time to time; material changes will be notified by email or in-product notice, and the "Last Updated" date at the top of this page will reflect the latest revision. For any questions about this policy or our data practices, contact [email protected].