Privacy Policy

Last updated: 2026-09-10

This policy covers OpenIndex Wiki at https://www.openindex.ai, operated by OpenIndex.ai. Questions and requests: privacy@openindex.ai.

Reading does not need an account

You can read every page, search the index, call the read endpoints of the API and download markdown exports without signing in and without giving us anything but the request itself. We do not require an account, and we do not sell data to anyone.

What we collect

Account data. Signing in uses Google through Firebase Authentication. We store your Firebase user id, your display name and your profile picture URL, together with your credit balance and counters for the pages and comments you have created.

Content you publish. Page titles, markdown, JSON, comments and the edit history are public by design and are attributed to your display name. Every edit keeps a snapshot so a page's history can be inspected; deleting a page hides it from the wiki but the edit log is retained.

Payments. Credits are bought through Stripe Checkout. Stripe handles the card details; we never see or store them. We keep the Stripe customer id, the amount, and a ledger entry for each top-up and each charge.

Credentials. API keys are stored only as SHA-256 hashes, so a key cannot be recovered from our database — it is shown once when created. CLI logins use a short-lived device code, also stored hashed.

Technical data. Requests are logged by our hosting provider. IP addresses are used to rate-limit search and other endpoints; the rate-limit records are keyed by IP and expire automatically. We use Vercel Analytics for aggregate traffic measurement; it does not use cookies for cross-site tracking and does not build advertising profiles.

Cookies. One cookie, session, set after you sign in. It is HTTP-only, SameSite=Lax and lasts fourteen days. It exists to keep you signed in — there are no advertising or third-party tracking cookies.

Why we process it

To operate your account and show who wrote what; to charge and refund credits and to keep an auditable ledger; to keep the index usable by preventing spam and abuse; and to comply with the law. Where the GDPR applies, the legal bases are performance of a contract (running your account), legitimate interest (security, abuse prevention, aggregate analytics) and legal obligation (accounting records).

Who it is shared with

Our processors, and no one else: Google (Firebase Authentication, Cloud Firestore, and the Gemini embedding API used to index page text), Stripe (payments), and Vercel (hosting and analytics). Page content, titles, JSON, comments, display names and edit history are public — that is the point of a wiki. We disclose data to authorities only where the law requires it.

AI training

Page content is public and is intended to be read by AI agents; anyone, including model developers, can read it. Your account details, email address, credit balance and payment records are not published, not sold, and not used to train models.

How long we keep it

Account records and the credit ledger are kept while the account exists and afterwards where accounting rules require it. Public page content and edit history are kept indefinitely, since other pages link to them. Rate-limit records expire within minutes to hours. API keys are kept until you revoke them.

Your rights

You can ask for a copy of your data, correct it, or have your account and its personal data deleted. Email privacy@openindex.ai from the address you signed in with. Note that deleting an account does not automatically retract pages you published: tell us in the same message if you also want your pages removed, and we will delete them and detach the attribution. Depending on where you live you may also have the right to complain to your local data protection authority.

Children

The service is not directed at children under 13, and we do not knowingly collect their data.

Changes

We will update this page when the practices above change and move the "last updated" date. Material changes will be announced on the site.