LEGAL · UPDATED 9 AUGUST 2026

Privacy at
IndexHalo.

This notice explains the information IndexHalo processes to produce GEO reports, operate prepaid credits, secure the service, and improve reliability.

1. Who operates IndexHalo

IndexHalo is operated by the IndexHalo team. Contact: support@indexhalo.com.

2. Information you provide

We process URLs, pasted text, uploaded files, account email addresses, and passwords protected with a salted one-way hash. Submitted content is used to generate the report you request. Do not submit confidential, regulated, or third-party material unless you have the right to process it.

3. Report, crawl, and monitoring data

IndexHalo stores generated reports, page inventories, crawl outcomes, timestamped monitoring snapshots, configured provider observations, prepaid credit balances and transactions, and limited technical data needed for abuse prevention and reliability. Provider observations may contain the query, response summary, source URLs, competing domains, model, provider, and observation time.

Signed-in users may import server-log exports or stream crawler events. Before saving crawler evidence, IndexHalo discards IP addresses and the raw log body. The retained evidence is limited to the request time, method, same-site URL or path, response status, response-byte count, declared user agent, and IndexHalo’s crawler classification. A declared user agent is not treated as independently verified source identity.

4. Payments

One-time credit top-ups are handled by Stripe. IndexHalo receives the checkout identifiers, internal account reference, and credit amount needed to update the prepaid ledger; it does not receive or store complete card details. Stripe processes payment information under its own privacy terms.

5. Built-in analysis and OCR

IndexHalo’s core reporting engine processes submitted material within the service and does not require you to connect an AI account or provide an AI API key. OCR runs within IndexHalo for supported scanned PDFs and images. Original uploaded files are processed for report generation and are not retained as source files; the resulting extracted and report data is stored so the report can be reopened.

6. Answer observations

New answer evidence is supplied by the customer or captured through an explicitly authorized customer-owned session. The hosted service does not send prompts through platform-funded provider credentials or shared browser sessions. Reports retain the declared question, answer experience, capture time, returned text and citations, and model identifier when available. If you use a third-party answer provider or browser session, that provider’s retention and processing terms apply to your use of it.

7. Security and sharing

We use reasonable technical safeguards and do not sell submitted content. Information may be shared with hosting, email-delivery, and payment providers only as needed to operate the service, or where law requires it.

8. Website analytics and consent

IndexHalo uses Google Analytics 4 to understand aggregate website use and improve the service. Advertising, user-data, and personalisation storage are denied for every visitor at all times. Analytics storage is denied by default in the EEA, the United Kingdom, and Switzerland, and is only enabled if you accept in the privacy banner; in other regions analytics storage is enabled by default and the same banner lets you switch it off. Either choice can be reopened from the footer at any time. Google may receive consent-state and measurement data according to the selected choice and its own terms.

9. Your choices

You can change analytics consent, pause monitoring, choose whether to buy more credits, and reset your password through account recovery. To request access, correction, export, restriction, or deletion of personal data, email support@indexhalo.com.

10. Changes

This notice may be updated as IndexHalo adds providers, account features, or new legal requirements. Material changes will be reflected by the updated date above.