Skip to main content

Privacy Policy

What Ranksify collects, why, who else sees it, and what you can ask us to do about it.

Last updated: 2 August 2026 · Version 1.0

1. Who is responsible for your data

Ranksify is operated by Ranksify Ltd, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. Ranksify Ltd is currently being incorporated; until that completes, the controller is its founder trading as Ranksify at the same address.

For anything on this page, email [email protected]. We are not required to appoint a Data Protection Officer and have not appointed one; the founder handles privacy questions directly.

For the personal data of your own website visitors that Ranksify collects through the beacon, you are the controller and we are the processor. The terms of that arrangement are in our Data Processing Addendum. For your own account data, we are the controller.

2. What we collect

This is the full list of what the software stores. If something is not here, we do not keep it.

  • Account data — your name, email address, and either a hashed password or a Google sign-in, plus an avatar if you set one, and the workspace and role you belong to.
  • Session data — each active session record stores the IP address and user agent it was created from, so you can recognise and revoke a session you do not think is yours. This is the one place a client IP address persists in the application database.
  • Billing data — your Stripe customer and subscription identifiers and your plan status. Card numbers never touch our servers; Stripe holds them.
  • Brand data — the domains, brand names, competitors, prompts and knowledge-base content you enter.
  • AI answer data — the prompts we send to AI engines on your behalf and the full responses they return, kept so results can be re-examined over time.
  • Connected-account data — when you connect Google Search Console, Google Analytics or Bing Webmaster Tools, the search and traffic metrics those services return, plus the OAuth tokens. Tokens are encrypted at rest with AES-256-GCM under a key held outside the database and are redacted from every response the browser can reach.
  • Website visitor data — if you install the Ranksify beacon, we record the page path, the referrer, the user agent and a two-letter country code for visits arriving from AI assistants. Only AI-referred visits are stored. See §3 for exactly what the beacon sends.
  • Product analytics — first-party, server-side events about how the app is used. Web-vitals measurements sent from the browser carry no workspace or user identifier and contain only three numbers: time to first byte, largest contentful paint, and cumulative layout shift.
  • Email suppression list — if an email to you bounces or you unsubscribe, we keep your email address on a suppression list. Keeping the address is the whole point: it is how we make sure we never email it again. See §9.
  • Server logs — like any web server, ours record request lines including IP addresses. They are size-capped and rotated rather than kept indefinitely.
  • Error reports — none today. See Sentry in §5.

3. The beacon, in detail

The Ranksify tag you can install on your own site is deliberately small. When a visitor arrives from an AI assistant, it sends us four things:

  • your brand identifier;
  • the relative path and query string of the page — not the host;
  • the referrer;
  • a random session identifier it generates and keeps in localStorage.

It sets no cookie on your visitors. It honours Global Privacy Control and Do Not Track: if either is set, it sends nothing at all.

On our side we store the page path, referrer, user agent, and a two-letter country resolved at the network edge. A visitor's IP address is never stored in a traffic record. It is used transiently to rate-limit abusive requests and is then discarded.

If you send us server log lines instead of using the tag, we group visits under a key derived from a truncated SHA-1 of the IP address, user agent and date. That key changes every day and cannot be reversed by us — but it is a pseudonym, not an anonymised value, and we describe it that way deliberately rather than claiming more than it is.

4. Why we process it, and on what legal basis

  • Running your account and delivering the service — account, session, brand, AI answer and connected-account data. Legal basis: performance of our contract with you.
  • Taking payment — billing data. Legal basis: performance of the contract, and our legal obligation to keep financial records.
  • Keeping the service secure and working — session records, server logs, rate limiting, product analytics and web-vitals. Legal basis: our legitimate interest in a secure, functioning product. We have weighed this against your interests: the data is minimal, is not used to profile anyone, and web-vitals events carry no identifier at all.
  • Transactional and lifecycle email — password resets, invitations, alerts and onboarding messages. Legal basis: performance of the contract, and our legitimate interest in telling customers about the service they bought. Every non-essential email has an unsubscribe link.
  • Not emailing people who asked us not to — the suppression list. Legal basis: our legal obligation, and our legitimate interest in respecting the request.
  • Website visitor data — processed on your instructions, as your processor. Choosing a lawful basis for it and telling your visitors about it is your responsibility as the controller of your own site.

5. Who else processes it

These are the sub-processors this service actually sends data to. We will give 14 days' notice by email before adding one.

Sub-processorLocationRoleData it receives
Hetzner Online GmbHGermany (EU)Hosting — the servers and database Ranksify runs onAll service data, at rest
Cloudflare, Inc.United States / globalDNS and edge for the application domainRequest metadata in transit, including IP address
Stripe, Inc.United StatesPayments and subscription billingEmail address at customer creation; card data goes to Stripe directly and never to us
Resend, Inc.United StatesTransactional and lifecycle email deliveryRecipient address, subject and body
Anthropic, OpenAI, Google (Gemini), PerplexityUnited StatesAI answer engines — the systems Ranksify measuresOnly the prompt text a customer configures. No end-user personal data
DataForSEOUnited StatesSearch-results and domain-authority lookupsDomains and keywords only
Functional Software, Inc. (Sentry)United StatesError reporting — planned, currently disabledNothing yet — it is disabled. If we enable it, it is configured to send no personal data: headers, cookies, request bodies and user context are all scrubbed, and this row will say so

On AI training: the answer engines receive only the prompt text you configure — never your end users' personal data. Each of those providers' API terms state that inputs and outputs sent through their APIs are not used to train their models.

Services you connect yourself are not sub-processors — data flows to them only because you asked it to, and only your data flows. Today those are Google Search Console, Google Analytics, Microsoft Bing Webmaster Tools, Webflow, WordPress, Notion and GitHub. Disconnect any of them in the app and the flow stops.

6. International transfers

All service data is at rest in the European Union, on servers in Falkenstein, Germany.

Some of the processors above are in the United States. Where a processor is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on that. Where it is not, we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum.

7. Fetching pages from the web

To analyse a domain, our servers fetch public resources from it — pages, favicons and structured data — including from the competitor domains you add. We fetch only what is publicly available, as any browser would. The AI agent inside the product is restricted to fetching your brand's own and competitor domains, through a gate that blocks requests to internal and private network addresses.

8. Shared reports

A share link makes a report public to anyone who has the URL, with an optional password. A shared report exposes the brand name and domain, the visibility metrics, the competitors, the cited sources, the opportunities and the sentiment. It does not expose any user identity.

🔴 One thing worth knowing before you share: if the report owner has set a custom white-label logo, viewing the report loads that logo from whichever host the owner chose. That host therefore sees the viewer's IP address and browser user agent. We cannot prevent that without breaking the feature, so we are telling you instead.

9. How long we keep it

We will be straight with you: there is no automatic pruning today. Every category above is kept for the life of the account and subscription, and AI responses and traffic events accumulate for as long as your account is active.

You can delete your account and its data yourself at any time from your account settings — workspaces where you are the only owner are deleted outright, subscription included. Or ask us by emailing [email protected], and we will do it. Backups containing deleted data age out within 14 days of the deletion, because backup copies are retained for 14 days and are not edited in place.

Two things deliberately survive deletion. Your email address stays on the suppression list if it is on it, so that we never email you again — deleting that record would defeat its only purpose. And records we are legally required to retain, such as invoices, are kept for as long as the law requires.

10. Your rights

Under UK GDPR you have the right to:

  • ask what we hold about you and get a copy (access);
  • have inaccurate data corrected (rectification);
  • have your data deleted (erasure);
  • get your data in a portable format (portability);
  • object to processing based on legitimate interests (objection);
  • ask us to restrict processing while a dispute is resolved (restriction).

Email [email protected] and we will respond within one month. If you are not satisfied with how we handled it, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but it is your right either way.

11. Cookies

Ranksify sets these cookies, all of them first-party. There are no analytics cookies, no advertising cookies, no third-party scripts of any kind, and no Google Fonts — our Content Security Policy allows resources from our own origin only.

  • better-auth.session_token — keeps you signed in. Strictly necessary.
  • ranksify_oauth_state — protects the integration connect flow against cross-site request forgery. Strictly necessary.
  • share_unlock_<id> — a signed token proving you entered the password for a protected shared report. Strictly necessary.
  • ranksify_ws — remembers which workspace you last had open. Functionality you asked for.
  • ranksify_project — remembers which brand you last had open. Functionality you asked for.
  • ranksify_theme — remembers light or dark. Functionality you asked for.
  • ranksify_sidebar — remembers whether the sidebar is collapsed. Functionality you asked for.

Because every one of these is first-party and is either strictly necessary or a preference you set by using the product, no cookie consent banner is required, and we do not show one. The beacon you install on your own site sets no cookie at all.

12. Changes to this policy

If we make a material change we will email account owners at least 14 days before it takes effect. The version and date at the top of this page always tell you which text is current.

13. Contact

[email protected]
Ranksify Ltd (in incorporation), 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ