Privacy Policy

Effective September 5, 2026 · Applies to rankright.dev, app.rankright.dev, the RankRight API and MCP server, and related services (together, the “Service”).

RankRight is operated by Innersite Solutions (“RankRight”, “we”, “us”) of Aiken, South Carolina, USA. This policy explains what information we collect, why, who we share it with, and the choices you have. If you use RankRight through a reseller or agency that has white-labeled it, that partner’s own privacy terms also apply to your relationship with them.

  1. Information we collect
  2. How we use information
  3. AI processing
  4. Google user data
  5. Who we share information with
  6. Cookies
  7. Retention and deletion
  8. Security
  9. Your rights and choices
  10. International transfers
  11. Children
  12. Public sandbox and docs
  13. Changes
  14. Contact

1. Information we collect

Account information

When you create an account or are invited to an organization: your email address, display name, a hashed password (or, for single sign-on, the identity your provider shares — see Google user data), your organization and role, and, if you enable it, an encrypted two-factor secret. We also record sign-in times and failed sign-in attempts to protect the account.

Workspace data you provide

RankRight is a tool for managing SEO and AI visibility for websites — typically your own or your clients’. You choose what to add: client names and websites, services and service areas, keywords, pages, notes, questions to ask AI engines, and competitors. If you connect a site so RankRight can publish changes for you, you may store credentials for that site (for example a WordPress application password or FTP login). Those credentials are used only to perform the actions you request and are never shared.

Data from services you connect

If you connect Google Search Console, we retrieve performance data for the properties you authorize (queries, pages, clicks, impressions, positions) and store snapshots of it in your workspace. See section 4 for how Google user data is handled.

Data we generate

Using the Service produces reports, audits, action items, rankings and keyword history, drafted content, and “AI Visibility” captures — records of what AI answer engines retrieved, cited and named for the questions in your workspace. This data belongs to your workspace.

Automatically collected

Server logs (IP address, user agent, request path, timestamps), an audit log of API calls (which key or user called which method, when), rate-limit counters, and error reports. Our CDN provider (Cloudflare) also processes connection metadata to protect the Service.

Billing

Payments are processed by Stripe. We store your Stripe customer and subscription identifiers, plan and seat counts, and invoice history. We do not store full card numbers.

Integrations you create

API keys (stored as hashes; the plaintext is shown to you once), webhook endpoints and their signing secrets (encrypted at rest), the delivery log for webhooks, and — when you authorize a third-party application or AI assistant through OAuth — the application's name, the scopes you approved, and the access/refresh tokens it holds (stored as hashes, listed under Connected apps where you can revoke them). Organization owners may also register their own single sign-on provider: for OpenID Connect we store its issuer, client id, allowed email domains and an encrypted client secret; for SAML 2.0 its entity ID, sign-on URL, public signing certificate, allowed email domains and the ids of sign-in requests we issued (kept 24 hours to prevent replay).

2. How we use information

We do not sell personal information, and we do not use your workspace data to advertise to you or to anyone else.

3. AI processing

Parts of the Service are powered by third-party AI models. Depending on the feature, content from your workspace (page text, keyword data, service descriptions, your instructions) is sent to Anthropic (Claude), OpenAI, Google (Gemini) and, for images, fal.ai, under their API terms. Under those terms the providers do not use API inputs or outputs to train their models. AI output can be wrong; you review it before publishing.

AI Visibility (answer-engine observation). To measure whether AI assistants name and cite a business, we ask public questions such as “who is the best HVAC company in Charleston, SC?” of AI engines, either through the engines’ official APIs or through their consumer products operated by our own staff on our own devices. Those questions contain business names and locations you configure — not personal data about individuals — and the answers we store are the engines’ public responses.

4. Google user data

Google Sign-In

If you sign in with Google we receive your email address, name and profile picture from Google (OpenID Connect scopes openid email profile). We use them to create or match your RankRight account and display your name. We do not receive your Google password.

Google Search Console

If you connect Search Console we request the webmasters scope so RankRight can read performance data for the properties you authorize (and, where you ask it to, submit sitemaps or inspect URLs). We use this data only to display it inside your workspace and to produce the analyses and reports you request. You can revoke access at any time at myaccount.google.com/permissions; RankRight keeps the snapshots already stored in your workspace until you delete them.

Limited Use disclosure. RankRight’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, is not used for advertising, is not transferred to third parties except as needed to provide the features you use (our hosting and AI processing sub-processors listed below) or as required by law, and is only accessed by humans with your consent, for security, or to comply with law.

5. Who we share information with

We share information only with the providers we need to run the Service (“sub-processors”), with people you authorize, and when the law requires it.

ProviderPurposeLocation
WHG Hosting Services (VPS)Application and database hosting, backupsDallas, Texas, USA
CloudflareCDN, DNS, DDoS protection, TLSUSA / global edge
Anthropic, OpenAI, Google (Gemini)AI analysis, drafting, answer-engine observationUSA
fal.aiImage generation for content featuresUSA
DataForSEO, SerpAPISearch ranking and keyword dataUSA / EU
StripePayments and subscription billingUSA
Google (Search Console, Sign-In)Data you connect; single sign-onUSA

People and systems you authorize: members of your organization (per their role), sites and CMS accounts you connect (changes are pushed to them on your instruction), webhook endpoints you register, and, if you use RankRight through an agency or reseller, that partner.

Legal and safety: we may disclose information to comply with law, enforce our terms, or protect the rights, property or safety of RankRight, our users or the public. Business transfers: if RankRight is acquired or merged, information may transfer to the successor under this policy.

6. Cookies

We use a session cookie to keep you signed in (HttpOnly, Secure, SameSite=Lax), a short-lived cookie during single sign-on to protect against forged requests, and cookies our CDN sets for security. We do not use advertising or cross-site tracking cookies. Blocking cookies will prevent sign-in.

7. Retention and deletion

8. Security

Traffic is encrypted with TLS. Passwords are stored as bcrypt hashes; two-factor secrets, stored provider keys and webhook signing secrets are encrypted at rest; API keys are stored as hashes and carry explicit scopes; organizations are isolated at the API layer and every API call is audited. No method of transmission or storage is perfectly secure, and you are responsible for keeping your credentials and API keys confidential. If you believe an account or key has been compromised, contact us immediately.

9. Your rights and choices

You can view and update your profile, enable two-factor authentication, mint and revoke API keys, disconnect applications you authorized, and manage webhooks in the app. Organization owners can export the whole organization (every table as JSON and CSV plus filed reports) with one action under Account → Data export or the API, and delete clients.

Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA, UK and Switzerland have these rights under the GDPR and UK GDPR; our legal bases are performance of our contract with you, our legitimate interests in operating and securing the Service, and consent where we ask for it. California residents have the rights described in the CCPA/CPRA; we do not sell personal information or share it for cross-context behavioral advertising, and we do not discriminate against you for exercising your rights. To exercise any right, email us (section 14). We will verify the request and respond within 30 days. You may also complain to your local data-protection authority.

10. International transfers

The Service is hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the US. Where required, we rely on standard contractual clauses or comparable safeguards for transfers from the EEA and UK.

11. Children

RankRight is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children; if you believe we have, contact us and we will delete it.

12. Public sandbox and docs

Our public documentation and sandbox (a read-only API key over a fictional demo workspace) contain no personal information. Requests made with the sandbox key are logged like any other API request (IP address, key, method) for rate limiting and abuse prevention.

13. Changes

We may update this policy as the Service changes. We will post the new version here with a new effective date and, for material changes, notify organization owners by email or in the app before the changes take effect.

14. Contact

Innersite Solutions · Aiken, South Carolina, USA
Privacy requests and questions: [email protected]