Privacy Policy
·
Privacy Policy
Developer draft — not legal advice. Pending counsel review.
Effective date: 12 September 2026 Last updated: 12 September 2026
Fill before counsel:
- Legal entity name: [COMPANY_LEGAL_NAME]
- Governing state: [GOVERNING_STATE]
- Registered/notice address: [PHYSICAL_ADDRESS]
- Confirm which SDKs (PostHog, Sentry, LaunchDarkly) are actually enabled per environment
- Confirm hosting locations and any additional processors before publishing
- Confirm CCPA/CPRA applicability thresholds for the entity before publishing
1. Who we are; draft status
This is a developer foundation draft prepared for internal review. It is not final, not binding, and not legal advice. It requires review and approval by qualified counsel before publication.
[COMPANY_LEGAL_NAME] ("Rankor," "we," "us," or "our") operates rankor.ai and related development and staging environments (dev.rankor.ai, stg.rankor.ai), a business-to-business software service for AI search visibility and generative engine optimization ("GEO") (the "Service"). This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you. It applies to visitors to our marketing site and to users of the Service.
Questions about this Privacy Policy can be directed to [email protected].
2. Information we collect
We collect the categories of information described below, primarily directly from you, automatically through your use of the Service, and, where noted, from third-party AI systems we use to operate the Service.
Category
Examples
Source
Account identifiers
First name, last name, email address, hashed password
You, at signup
Profile information
Display name, avatar preset selected from a built-in catalog (not an uploaded photo)
You
Brand and setup content
Brand name, domain, industry, location and language codes, timezone, target markets, audience personas, topics, tags, competitor names/URLs
You
Prompts and AI transcripts/citations
Prompt text you configure, the full rendered answers returned by third-party AI systems, citations, retrieved URLs, mention snippets, and derived scores (visibility, share of voice, sentiment, position)
Generated via third-party AI systems, based on prompts you configure
Homepage content we fetch
Publicly available homepage HTML of a domain you provide during brand setup, used (with your inputs) to suggest a profile, topics, and prompts
Fetched from the public web at your direction, cached briefly
Team invite emails
Email addresses of people you invite to a Brand
You
Billing identifiers
Stripe customer ID, subscription plan and status, payment card last four digits (we do not store full card numbers)
Stripe, once checkout is enabled
Device and session information
Hashed IP address, user-agent string, session and refresh tokens
Automatically, when you use the Service
Cookies and SDK identifiers
Essential session cookies; analytics, session-recording, and feature-flag identifiers where those tools are configured
Automatically
Notifications
In-app notification records (for example, competitor gap, visibility change, ranking change, sentiment change alerts); transactional emails (verification, password reset, team invites)
Generated by the Service
Product analytics / session recordings
Usage events, feature interactions, error reports, session recordings, and survey responses, where analytics tools are enabled
Automatically, via analytics SDKs
3. How we use information
We use the information described above to:
- Provide, operate, and maintain the Service, including creating and authenticating your account, running scheduled or on-demand AI harvests of your configured prompts, storing and displaying the resulting data, and generating CSV exports you request.
- Operate Team functionality, including sending invitations, enforcing role-based access, and displaying a Brand's data to the teammates you have authorized.
- Communicate with you, including responding to inquiries and sending transactional emails such as email verification, password reset links, and team invitations (sent from [email protected]).
- Maintain the security and integrity of the Service, detect and prevent fraud or abuse, and enforce our Terms of Service.
- Monitor, troubleshoot, and improve the Service, including through error monitoring, product analytics, and, where enabled, session recordings and feature-flag experimentation.
- Process payments and manage subscriptions through Stripe, once checkout functionality is enabled for your account.
- Comply with our legal obligations and respond to lawful requests from public authorities.
- Generate AI-assisted suggestions during brand setup (for example, suggested profile details, topics, or prompts), which you can review, edit, or reject.
We do not use your account email or name as an identifier when sending data to our product-analytics tool; only an internal user identifier is used for that purpose.
4. When we share information
We do not sell personal information, and we do not share personal information with any advertising network for cross-context behavioral advertising. We share information with service providers who help us operate the Service, each acting under contractual obligations consistent with this Policy, including:
- AI processing providers: a third-party aggregation vendor we use to query public AI assistants (including systems from OpenAI, Anthropic, Google, and Perplexity), a direct API integration with a separate model vendor (xAI), and OpenAI directly for brand-setup suggestions. Your configured prompts and, during setup, homepage content and your inputs, are sent to these providers as described in Section 2.
- Authentication providers: Google, to support "Continue with Google" sign-in.
- Payment processing: Stripe, for subscription billing, once checkout is enabled.
- Analytics, monitoring, and feature flags: a product-analytics provider (which may also provide session recording and in-product surveys), an error-monitoring provider (configured not to receive default personal data such as IP addresses beyond what is technically necessary), and a feature-flag provider (which receives only an anonymous client identifier).
- SEO and ranking data providers: third-party providers we use to support search- and ranking-related data.
- Content management: a content-management provider that hosts our marketing site and these legal pages.
- Infrastructure providers: database, caching, and background-processing infrastructure, and an email-delivery provider used to send transactional email from [email protected].
We may also share information: (a) to comply with applicable law, legal process, or governmental request; (b) to protect the rights, property, or safety of Rankor, our users, or others; or (c) in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations consistent with this Policy.
5. Cookies and similar technologies
We do not currently display a cookie-consent banner or maintain a separate cookie policy. This section describes the cookies and similar technologies we use.
- Essential technologies, necessary for the Service to function:
- An HttpOnly cookie used to maintain your authenticated session.
- A cookie that indicates you are signed in (not itself an authentication token).
- A cookie that remembers your sidebar display preference.
- Browser session storage used for filter-bar state and to prevent duplicate analytics events.
- Browser local storage used to remember whether you have seen a one-time "first brand created" celebration message.
- Analytics, session recording, and feature flags, used where configured for an environment:
- A product-analytics tool that may record usage events, capture errors, record sessions, and present surveys. It identifies you using only an internal user identifier, never your name or email address.
- A feature-flag provider that uses an anonymous client-side identifier to determine which features you see.
- An error-monitoring tool that may capture diagnostic information about application errors.
- You may be able to limit some of these technologies through your browser settings (for example, blocking cookies or local storage), though doing so may affect parts of the Service's functionality. We do not currently offer a dedicated cookie-preference center.
6. Retention
- Deleted accounts: soft-deleted immediately upon your request, with a scheduled data purge approximately 30 days later.
- Incomplete brand setups: if you begin but do not complete brand setup, that data is hard-deleted after 7 days.
- Raw AI capture data (full third-party model responses): retained on a 90-day retention schedule.
- Active account data: retained for the life of your account, or until you delete specific data (such as a Brand) within the Service.
- CSV exports you generate (of prompts, sources, or gap analysis) are downloads that you initiate and control; they are not a comprehensive or automated data-export mechanism, and generating one does not affect our retention of the underlying data.
- Logs and backups may persist for a reasonable additional period beyond the retention periods above, for security, disaster-recovery, and operational-continuity purposes. We do not commit to a specific retention period for logs and backups.
7. Your US privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"), and similar state privacy laws may give you the right to:
- Know what personal information we have collected about you and how we have used and disclosed it.
- Delete personal information we have collected from you, subject to certain exceptions permitted by law.
- Correct inaccurate personal information we maintain about you.
- Opt out of the sale or sharing of personal information. As stated above, we do not sell personal information and do not share it for cross-context behavioral advertising, so there is currently no sale or sharing to opt out of.
- Non-discrimination for exercising any of these rights.
To exercise these rights, contact us at [email protected]. We may need to verify your identity, and the identity of anyone submitting a request on your behalf, before completing certain requests. If applicable state law grants residents outside California similar rights, we will honor verifiable requests consistent with that law.
8. International processing
Rankor is a US-first service, and our primary customer base is expected to be in the United States. However, some of our infrastructure and service providers process data outside the United States, including in Germany. Where we or our processors transfer or process personal information internationally, we take reasonable steps intended to protect that information consistent with this Policy. We do not represent or warrant compliance with the EU General Data Protection Regulation, the UK GDPR, or any specific international data-protection certification or framework at this time.
9. Children
The Service is intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us at [email protected] so we can address it.
10. Security
We use reasonable technical and organizational measures designed to protect personal information, including hashing of passwords and of stored session/refresh-token values, and access controls around our infrastructure. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security of your information.
11. Changes; contact
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. If we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice, such as an in-product notice or an email to registered users.
If you have questions or requests regarding this Privacy Policy, contact us at [email protected].
[COMPANY_LEGAL_NAME] [PHYSICAL_ADDRESS]