Privacy Policy

Last updated 1 September 2026

This is a starting point, drafted for review — not legal advice. It describes what the software actually does, which is the hard part, but a lawyer should review it against your jurisdiction and your commitments before you rely on it.

The short version

We store the email address you sign up with, the domains and competitor names you ask us to track, the questions we generate from them, and the answers AI engines give to those questions. We do not collect information about your customers or your website’s visitors. We have no advertising, no tracking pixels, and we do not sell anything to anyone.

What we collect

Account data

Your email address, and the account and membership records that link it to your projects. Authentication is passwordless — we send a one-time link and never create, store, or see a password.

Project data

The domain you track, your brand name and aliases, the competitors you name, your category, and the description of your buyer that you write during onboarding. That buyer description is used verbatim inside the questions we ask, so do not put anything confidential in it.

Measurement data

For every question we ask, we store the full text of the engine’s answer, the sources it cited, and what we extracted from that answer — which brands were mentioned or recommended, in what order, and how much of each cited source appeared in the wording. This is the product; it is also the largest thing we hold about you.

Billing data

Stripe holds your payment method. We store only a Stripe customer identifier, your plan, and your subscription status. Card details never reach our servers.

Operational data

Standard server logs from our hosting provider, including IP addresses and request metadata. We do not run analytics or advertising trackers of any kind.

What leaves our systems when we measure

Measuring means sending your tracked questions to third-party AI providers. Those questions contain your brand name and your competitors’ brand names, because that is what makes them the questions your buyers actually ask. Assume anything in a tracked prompt is disclosed to OpenAI, Perplexity, Google and Anthropic, subject to their own terms and data retention. We send no account identifiers, no email addresses and no billing data with them.

Where a provider returns a citation without usable text, we may fetch that public page to score how much of it shaped the answer. We identify ourselves as RankliBot and fetch only pages an AI engine already cited.

Subprocessors

ProcessorPurposeData involved
VercelApplication hosting and edge networkRequest metadata, IP addresses
SupabasePostgres database and authentication (us-east-2)All account and measurement data
StripePayments and subscription billingBilling contact, payment method (held by Stripe)
OpenAIMeasurement — asks your tracked questions of ChatGPTPrompt text only
PerplexityMeasurement — asks your tracked questions of PerplexityPrompt text only
GoogleMeasurement — asks your tracked questions of GeminiPrompt text only
AnthropicMeasurement — asks your tracked questions of ClaudePrompt text only

Where it lives

In a Postgres database hosted by Supabase in AWS us-east-2 (Ohio, United States). Access between accounts is separated at the database level, and every read the application makes is filtered to your account.

How long we keep it

Measurement history is kept for as long as your account exists, because comparing a round against an old baseline is the entire point of the product. If you cancel, we downgrade the account rather than deleting your history — we would rather you could come back to it. Ask us to delete it and we will, within 30 days.

Your choices

  • Ask for a copy of everything we hold about you, in a machine-readable form.
  • Ask us to correct anything that is wrong.
  • Ask us to delete your account and its measurement history.
  • Stop measurement at any time by pausing or deleting a project.

Email hello@rankli.io and we will act within 30 days. Depending on where you live you may have additional statutory rights; we will honour them.

Security

Traffic is encrypted in transit. Data is encrypted at rest by our database provider. Payment credentials never touch our infrastructure. Authentication has no password to steal. We will tell affected customers about a breach that puts their data at risk, without waiting to have a complete story first.

Children

Rankli is a business tool and is not directed at anyone under 16.

Changes

If we change this in a way that materially affects what we do with your data, we will email you before it takes effect rather than quietly changing the date at the top.

Questions: hello@rankli.io · Terms of Service · Back to Rankli