Back to Indicadora

INDICADORA / EARLY ACCESS

Privacy policy

How we handle your information when you explore Panel, join early access and use IndiVision.

Last updated: 19 September 2026

1. Who to contact

Indicadora is responsible for the personal information handled through this website. Contact policy@indicadora.com with privacy questions, data requests or concerns.

2. Information we handle

  • Account information: your email address, authentication records and account identifiers. Supabase manages password authentication; passwords are not stored by us as readable text.
  • IndiVision submissions: photos you choose to upload or capture, the item type you select, submission times and processing status.
  • Results and feedback: visible-condition findings, scores, confidence, care suggestions, ratings and comments you submit.
  • Service records: your remaining complimentary allowance, usage records and any earlier account or transaction records that need to be retained.
  • Technical information: browser and device information, page views, referring pages, approximate location derived from connection information, and security or error logs. Service providers may process IP addresses.
  • Correspondence: information you send when asking for support or exercising your rights.

Camera access is optional and requested through your browser. Only photos you submit are uploaded for analysis. Avoid including faces, addresses, documents or other unnecessary personal information in photos and feedback.

3. Why we use information

  • To provide the account and analysis you request, save your results and manage your allowance: performance of our agreement with you.
  • To respond to feedback and support requests, maintain security, investigate failures and understand use of the early-access service: our legitimate interests in operating and improving the service, balanced against your rights.
  • To meet applicable legal obligations, including handling requests concerning your information and retaining records when required.
  • For optional marketing where offered: consent when required. Accepting our Terms is not a blanket consent to marketing or model training.

4. How IndiVision processes photos

Your photos are stored in private Supabase storage. When you request an analysis, our server validates your account and submission, then gives OpenAI temporary access to the submitted images for visual analysis. Approved Indicadora reference images may be included as comparison context. Your account password is not included in that analysis request.

We save the resulting findings and calculate the condition score on the server. Results describe visible evidence and can be incomplete or incorrect. The current IndiVision flow does not add your uploaded photos to an Indicadora training or reference library. Feedback you choose to submit can be reviewed to improve the service.

OpenAI states that API data is not used to train its models by default unless the customer opts in. API abuse-monitoring logs may retain content for up to 30 days, with exceptions described in its data controls documentation. We do not promise zero retention by AI providers.

5. Service providers

  • Supabase: account authentication, database, private image storage and server-side processing.
  • Vercel: website hosting, delivery and operational logs. Vercel Web Analytics provides visitor and page-view measurements.
  • OpenAI: image analysis through its API.
  • Cloudflare Turnstile: security checks on account forms, using browser and connection information to help prevent abuse.
  • Stripe: handling of earlier payment records where applicable. New purchases, top-ups and renewals are not offered in the current early-access website.

Authorised support or administration may access information when needed to operate the service or respond to a request. Photos are not publicly listed. Information may also be disclosed where required by law or necessary to protect users and the service.

6. How long information is kept

Account information, submitted photos, results and feedback are kept to provide your account and saved history. Uploads can remain stored after a failed or incomplete scan. They are not automatically deleted after a fixed 90-day period.

You can request deletion of your account, photos or results by emailing policy@indicadora.com. We assess retention against the purpose for keeping the data, account status, outstanding requests, security needs and applicable legal obligations. Some transaction records, restricted backups or records needed for a dispute may need to remain after an account closes. Provider logs and backups follow their applicable retention arrangements.

7. Security and international processing

We use HTTPS, authenticated access and database/storage access controls. Privileged server processes can access data to perform requested analyses. No online service can guarantee absolute security.

Our providers may process information outside the UK, including in the United States. Their published processing terms describe their international-transfer arrangements and safeguards. Contact us for information about the arrangements applicable to your data. A provider link does not replace Indicadora's responsibilities for your information.

8. Your rights

Depending on the applicable law and the reason for processing, you may request access, correction, erasure, restriction or portability of your data, object to processing based on legitimate interests, and withdraw consent where consent is used. These rights can have exceptions. To make a request, email policy@indicadora.com; we may need to verify your identity.

We respond within the applicable legal time limit, normally one month for UK data-rights requests, and explain any permitted extension. You can complain to the UK Information Commissioner's Office or your local data-protection authority.

9. Cookies, analytics and age

Our Cookies & analytics notice explains session cookies, browser preferences, security checks and Vercel Web Analytics. The service is intended for people aged 16 or over. Contact us if you believe information about someone under 16 has been submitted.

10. Changes

We update this notice when the service or its data use changes. The revision date appears above. Material changes will be explained through an appropriate notice on the service or direct communication where required.