Privacy Policy
Last updated: July 22, 2026
RankCharge ("we", "us") helps small businesses grow their search and AI-assistant visibility. This policy explains what we collect, why, and the choices you have. The short version: we collect what the product needs to work, we never sell your data, and your credentials are encrypted.
What we collect
- Account data — your email address and a password (handled by our authentication provider; we never see or store the password itself), plus the name you give your organization.
- Business profile — the website, business description, market, competitors, and preferences you enter to steer your content plan.
- Website and search data — pages we crawl from the public website you connect, keyword and ranking data, backlink profiles, and audit results for that site.
- Publishing credentials — if you connect WordPress, Shopify, or another platform, the access credentials you provide are stored encrypted (AES-256-GCM) and used only to publish and manage the articles you approve.
- Product usage — basic events about how onboarding is used (e.g. that a scan was started), tied to your account, so we can improve the product. We do not run third-party advertising trackers.
Google user data
If you connect Google Search Console, Google Analytics, or Google Business Profile, we request read-only scopes for Search Console and Analytics. For Business Profile, Google offers only a management scope; we currently use it to read your profile, reviews, and performance, and any future action that changes your Business Profile (such as posting an update or replying to a review) will only ever happen when you explicitly ask for it. We use this data solely to show you your own performance insights inside RankCharge and to improve the content plan we build for you. Google access tokens are encrypted at rest. We do not transfer, sell, or use Google user data for advertising, and human access is limited to what's necessary for security or support with your consent. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time at myaccount.google.com/permissions or by disconnecting in Settings.
Service providers we rely on
We share data with processors only to run the product: Supabase (database, authentication, hosting infrastructure), Anthropic (AI content generation), DataForSEO (keyword, ranking, and backlink data), Google APIs (the integrations you connect), Inngest (background job processing), Cloudflare (bot protection on sign-in), Pexels (stock imagery), and error-monitoring tooling. Each receives only what its function requires.
Cookies
We use cookies only to keep you signed in. No advertising or cross-site tracking cookies.
Retention and deletion
We keep your data while your account is active. Onboarding scan data is cleaned up automatically on a schedule. To delete your account and its data, email us at the address below and we'll complete the deletion within 30 days.
Security
All traffic is encrypted in transit (TLS). CMS credentials and Google tokens are encrypted at rest. Access to production systems is limited and credentialed.
Changes and contact
We'll update this page when our practices change and note the new date above. Questions or requests: founders@rankcharge.co.