Skip to main content

Privacy Policy

This policy explains what personal data RankInAI collects, why it is collected, how long it is kept and what rights you have over it.

Last updated: April 1, 2026

Template document

This document is a software-generated starting template provided with the RankInAI platform. It has not been reviewed by an attorney and does not constitute legal advice. Have it reviewed and adapted to your jurisdiction and business before commercial launch.

1. Data we collect

We collect only what the service needs to operate:

  • Account data — email address, name, hashed password, role, account status, creation and last sign-in timestamps.
  • Profile data you choose to provide — company name, website, business type and primary use case.
  • Audit data — the website URLs you submit, business context you enter, and the analysis results produced from public pages.
  • Billing data — Stripe customer and subscription identifiers, payment amounts, status and dates. Card details are handled entirely by Stripe and never reach our servers.
  • Support data — contact form submissions including your name, email, company, subject and message.
  • Operational data — hashed IP addresses and hashed identifiers used for rate limiting and abuse prevention, plus internal product analytics events.

2. What we deliberately do not collect

We do not store payment card numbers. We do not store raw IP addresses for rate limiting — only a salted one-way hash. Internal analytics events never contain form field values, credentials, message contents or payment details, and are restricted to a fixed whitelist of properties.

The free homepage preview stores only the domain, a hashed client identifier, the resulting score and timing information. No page content is retained.

3. Why we process it

Each category of data has a specific purpose:

  • To provide the service — running audits, storing your reports and applying entitlements.
  • To take payment and meet accounting obligations.
  • To secure the platform — rate limiting, abuse prevention and audit trails for privileged actions.
  • To improve the product — aggregate, non-identifying usage patterns.
  • To communicate with you — transactional email about your account and audits, and marketing email only where you have opted in.

4. Website content we retrieve

To produce an audit we retrieve publicly accessible pages from the website you submit. We store structured observations — titles, headings, word counts, schema types, link counts and bounded excerpts — not complete page copies. Retrieved content is used solely to produce your report.

5. Third-party processors

We share data only with processors required to run the service:

  • Stripe — payment processing, subscription management and the customer billing portal.
  • Our hosting and database provider — application hosting and data storage.
  • An email delivery provider — transactional email, where configured.
  • An AI provider — only if narrative enhancement is enabled, and only computed scores and check outcomes are sent. Passwords, payment data and unnecessary personal information are never included.
  • A search data provider — only if public-web observations are enabled, and only the brand and service terms used in the queries are sent.

6. Retention

Account and audit data are kept while your account is active. Rate-limit records are pruned automatically. Financial records are retained as long as required by law and accounting practice, typically seven years.

When you request account deletion, personal data is removed or irreversibly anonymized except where retention is legally required.

7. Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, to object to or restrict processing, and to withdraw consent for marketing at any time.

You can update your profile and email preferences, and request account deletion, from the settings page. For anything else, contact us.

8. Security

Passwords are hashed with bcrypt and never stored in plain text. Reset and verification tokens are stored only as salted hashes. Access to administrative functions is restricted by role and checked server-side on every request, with an audit trail of privileged actions. Data is transmitted over TLS. Secrets are held in environment variables and never in the database or the client bundle.

No system is perfectly secure. If you believe you have found a vulnerability, please report it through the contact page.

9. Cookies

RankInAI uses a small number of cookies, described in the Cookie Policy. Third-party analytics are optional and disabled unless explicitly configured by the operator.

10. Children

The service is not directed at children under 16 and we do not knowingly collect their personal data.

11. Changes and contact

We will post any changes to this policy on this page and update the date above. Material changes affecting how personal data is used will be notified by email.

Privacy questions can be sent through the contact page.