Privacy Policy
Last updated: June 28, 2026
IndexerNow ("we", "us") operates indexernow.com and the IndexerNow service. This page explains what we collect, why, and your rights. We aim to keep this short and plain.
What we collect
When you sign in with Google, we receive and store:
- Your Google account email and profile (id, name, picture)
- A refresh token that lets us call Google's APIs on your behalf, scoped strictly to
webmasters.readonlyandindexing— only for properties you've verified in Search Console
When you use the tools, we store:
- The URLs you submit and the tool (index / status / audit)
- The tier (free or paid), counters for your daily free-tier usage
- Results returned by Google's APIs for each URL (indexed verdict, last crawl time, etc.)
When you pay:
- We pass your email to Dodo Payments to create the checkout
- We store the resulting payment id + status on the batch record
- We never see or store card numbers — those go directly to Dodo Payments
Analytics
We use Microsoft Clarity to understand how the product is used — aggregate heatmaps and session replays of page interactions (clicks, scrolls, navigation) that help us spot broken flows and improve the interface. Clarity masks page text and form inputs by default, and we use it strictly for first-party product analytics — never for advertising, cross-site tracking, or selling data. It sets its own cookies and is operated by Microsoft under the Microsoft Privacy Statement. It loads only when we have it configured, and any standard tracker-blocking extension (or your browser's "Do Not Track") will stop it.
What we don't collect
- No advertising networks, ad-retargeting, or cross-site tracking pixels — the only analytics we run is first-party Microsoft Clarity, described above
- No reading or scraping of the content of your pages — we only call Google's APIs about the URLs you provide
- No selling, sharing, or marketing-list sale of your data, to anyone, ever
Where data lives
- Firebase Firestore (Google Cloud) — primary database, encrypted at rest
- Vercel — hosting and serverless runtime; does not persist data beyond standard logs
- Microsoft Clarity (Microsoft) — usage heatmaps and session replays, retained per Microsoft's policy
- Refresh tokens are stored on your user record and only usable while our server holds the Google OAuth client secret — they're useless on their own
Who we send data to
- Google APIs (Indexing, Search Console, PageSpeed Insights) — called as you, using your OAuth grant
- Dodo Payments — paid batches only
- Firebase (Google Cloud) — our database
- Vercel — our hosting
- Microsoft Clarity — first-party product-usage analytics
How long we keep your data
Until you delete it. Open Settings → Delete my data to wipe everything immediately — user record, all batches, all usage docs. After deletion, residual logs on Vercel and Firebase may persist briefly per their retention policies; we cannot access them.
Your rights
- Access: view your data in /app/settings and your batch history
- Deletion: one-click in Settings — also revoke our access at myaccount.google.com/permissions
- Portability: every batch has a CSV export button
- GDPR / CCPA: if your jurisdiction grants additional rights, email support@indexernow.com and we'll honor them within 30 days
Cookies
We use one essential cookie (idx_session) to keep you signed in, and a short-lived OAuth state cookie during login. Microsoft Clarity sets its own analytics cookies (e.g. _clck, _clsk) to measure product usage. We use no advertising or marketing cookies.
Children
This service is not directed to children under 13 (or under 16 in some jurisdictions). We do not knowingly collect data from minors.
Changes
If we materially change this policy, we'll update the "Last updated" date and notify signed-in users via in-app banner.
Contact
Questions? support@indexernow.com