Legal

Privacy Policy

How RankGrow collects, uses, shares, stores, and protects your personal data across our website, SEO tools, AI features, and integrations.

Last updated: June 1, 2026

1. Introduction

This Privacy Policy explains how RankGrow ("RankGrow", "we", "us", or "our") collects, uses, discloses, stores, and protects personal data when you access or use our website, application, SEO tools, AI assistants, integrations, paid plans, support, and related services (collectively, the "Service").

RankGrow helps users understand and improve search engine optimization by connecting website data, including Google Search Console data, and by generating AI-assisted analysis, recommendations, tasks, and reports.

For purposes of applicable data protection laws, including the General Data Protection Regulation ("GDPR") and UK GDPR, the data controller for personal data processed under this Privacy Policy is:

Bartosz Zagrodzki
Operating under the brand name RankGrow
Country of establishment: Poland
Email: hello@rankgrow.io

If your organization has entered into a separate written agreement with us, that agreement may contain additional privacy or data processing terms. If there is a conflict between that agreement and this Privacy Policy, the written agreement controls for the affected processing.

2. Information We Collect

We collect information you provide directly, information generated when you use the Service, information received from integrations you connect, and limited technical information collected automatically.

2.1 Account and authentication information

When you create an account, sign in, or manage your account, we may collect:

  • Name, email address, profile image, user ID, account settings, and account creation dates.
  • Authentication method, email verification status, social login identifiers, and OAuth account identifiers.
  • Session information such as session tokens, expiration dates, IP address, user agent, active organization, and security metadata.
  • Two-factor authentication status and related security secrets or backup codes if you enable two-factor authentication.
  • Organization membership information, roles, invitations, inviter details, and administrative permissions.

2.2 Organization, website, and SEO workspace information

When you create or manage a workspace, website, or organization in RankGrow, we may collect:

  • Organization name, slug, domain, logo, members, roles, and invitations.
  • Website domains, URLs, sitemaps, target markets, competitors, notes, categories, technology stack, tone, and other profile details you provide.
  • SEO tasks, task titles, descriptions, labels, priorities, status, and related workflow metadata.
  • Website and page data needed to provide SEO features, such as crawled URLs, page metadata, headings, links, robots directives, indexability signals, page content excerpts, schema data, and technical SEO findings.

2.3 Chat, AI, and generated content

When you use RankGrow's chat, AI agents, or AI-assisted SEO tools, we may collect and store:

  • Prompts, messages, instructions, uploaded or pasted content, chat names, pinned chats, shared chat links, and message parts.
  • AI-generated responses, tool outputs, SEO recommendations, task lists, summaries, and analysis results.
  • Model usage metadata, including model name, provider, input tokens, output tokens, reasoning tokens, cached tokens, and related diagnostic metadata.
  • The website, organization, or integration context used to answer your request.

You should not submit sensitive personal data, payment card data, government identifiers, health information, or other highly sensitive information into AI prompts unless it is strictly necessary for your use of the Service.

2.4 Google account and Google Search Console data

If you connect Google Search Console, we use Google OAuth to request access to your Google account for the purpose of providing SEO analysis. We may collect and process:

  • Google account profile information returned through OAuth, such as Google account ID, email address, name, avatar, and granted scopes.
  • OAuth access tokens, refresh tokens, token expiration dates, and scope metadata. We encrypt OAuth tokens before storing them.
  • Search Console property identifiers, connected site URLs, and connection metadata.
  • Search Console performance data, including queries, pages, countries, devices, clicks, impressions, click-through rate, and average position.
  • URL Inspection data, including index coverage, crawl status, canonical information, robots signals, mobile usability, rich results, detected issues, and inspection links.

We use Google Search Console data only to provide and improve user-facing SEO features you request, such as analysis, dashboards, AI answers, URL inspection, and task recommendations. Search Console data may be displayed in your workspace, included in chat context, and stored in chat history or generated outputs when it is part of an answer or task.

RankGrow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train generalized AI models. When an AI feature needs Search Console data to answer your request, we may send the relevant limited excerpts to our AI subprocessors solely to provide that requested feature.

You can revoke RankGrow's access to your Google account at any time from your Google Account security settings or by disconnecting the integration in RankGrow. If you disconnect the integration, we stop fetching new Search Console data and delete or deactivate stored OAuth credentials, subject to backup retention and legal requirements.

2.5 Payment and billing information

If you purchase a paid plan or otherwise make a payment, we process billing information through Stripe. We may store:

  • Stripe customer IDs, subscription IDs, order IDs, plan or variant IDs, subscription status, billing period dates, trial dates, payment status, and payment provider metadata.
  • Billing events needed to maintain access to paid features, issue invoices, handle renewals, prevent fraud, and comply with tax, accounting, and legal obligations.

We do not store full payment card numbers. Payment card details are processed by Stripe according to Stripe's own security and compliance standards.

2.6 Communications and support

When you contact us, respond to emails, submit a contact form, or request support, we may collect your name, email address, organization, message content, attachments, and related correspondence.

2.7 Usage, analytics, logs, and device information

When you use the Service, we may automatically collect:

  • Pages viewed, features used, events triggered, clicks, navigation paths, referrers, and approximate usage timestamps.
  • Browser type, device type, operating system, language, timezone, IP address, and general location inferred from IP address.
  • Error reports, stack traces, performance data, service logs, request metadata, and diagnostic information.
  • Cookie identifiers, session identifiers, and similar technologies as described in this Privacy Policy and any cookie notice or preference tool we provide.

3. How We Use Personal Data

We use personal data for the following purposes:

  • To provide, operate, maintain, secure, and improve the Service.
  • To create and manage accounts, sessions, organizations, roles, invitations, and authentication.
  • To connect and operate integrations, including Google Search Console.
  • To analyze websites, query SEO data, inspect URLs, crawl pages, generate recommendations, create tasks, and answer chat requests.
  • To process payments, manage plans, enforce usage limits, provide credits, and handle billing support.
  • To send transactional emails, such as verification emails, magic links, password or account emails, organization invitations, billing emails, and important service notices.
  • To provide customer support and respond to inquiries.
  • To monitor reliability, debug errors, prevent abuse, detect security incidents, and protect users and the Service.
  • To understand product usage, improve features, measure performance, and develop new functionality.
  • To comply with legal obligations, enforce agreements, resolve disputes, and protect legal rights.
  • To send marketing communications only where permitted by law and, where required, with your consent. You can unsubscribe from marketing emails at any time.

4. Legal Bases for Processing

If GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases:

PurposeLegal basis
Creating and managing your account, workspace, subscriptions, and requested SEO featuresPerformance of a contract, GDPR Art. 6(1)(b)
Connecting integrations and processing Google Search Console data at your requestPerformance of a contract, GDPR Art. 6(1)(b), and consent where required
Sending authentication, security, account, billing, and service emailsPerformance of a contract, GDPR Art. 6(1)(b), and legitimate interests, GDPR Art. 6(1)(f)
Processing payments and keeping financial recordsPerformance of a contract, GDPR Art. 6(1)(b), and legal obligation, GDPR Art. 6(1)(c)
Security, abuse prevention, debugging, logging, and service reliabilityLegitimate interests, GDPR Art. 6(1)(f)
Product analytics and non-essential cookiesConsent, GDPR Art. 6(1)(a), where required; otherwise legitimate interests, GDPR Art. 6(1)(f)
Responding to support requestsPerformance of a contract, GDPR Art. 6(1)(b), or legitimate interests, GDPR Art. 6(1)(f)
Marketing emailsConsent, GDPR Art. 6(1)(a), or legitimate interests where permitted by law
Compliance with law, tax, accounting, and legal claimsLegal obligation, GDPR Art. 6(1)(c), and legitimate interests, GDPR Art. 6(1)(f)

Where we rely on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

5. AI Processing

RankGrow uses AI models and AI infrastructure providers to generate SEO analysis, answers, recommendations, task lists, and other outputs. To provide these features, we may send prompts, conversation context, relevant website data, Search Console excerpts, tool results, and related metadata to AI subprocessors.

We use these providers only to process your request and return an output to you. We do not use your personal data or Google user data to train generalized AI models. AI outputs may be inaccurate, incomplete, or based on limited data, and should be reviewed before you rely on them for business decisions.

RankGrow does not make decisions based solely on automated processing that produce legal or similarly significant effects about you. AI features generate recommendations and analysis for your review.

6. Cookies and Similar Technologies

We use cookies and similar technologies for:

  • Essential functionality, including authentication, session management, security, OAuth state, user preferences, and fraud prevention.
  • Analytics and product improvement, such as understanding which pages and features are used.
  • Performance, diagnostics, and error monitoring.

Essential cookies are necessary to provide the Service. Non-essential analytics cookies are used only where permitted by law and, where required, after you provide consent. You can manage cookies through your browser settings and, where available, through our cookie preference tool.

Disabling certain cookies may prevent parts of the Service, such as login, integrations, or account security features, from working properly.

7. How We Share Personal Data

We do not sell your personal data. We also do not share personal data for cross-context behavioral advertising as those terms are defined under applicable US privacy laws.

We may disclose personal data in the following circumstances:

  • Service providers and subprocessors. We share data with vendors that host, secure, operate, analyze, support, or improve the Service.
  • AI and SEO providers. We share limited request data with AI, search, crawling, and SEO data providers when needed to perform the feature you request.
  • Payment processors. We share billing and transaction data with Stripe for payment processing, subscriptions, fraud prevention, and tax or accounting support.
  • Google APIs. If you connect Google Search Console, we exchange data with Google to authenticate your account and retrieve Search Console data.
  • Your organization. Content and data you create in an organization workspace may be visible to other members of that organization according to their roles and permissions.
  • User-directed sharing. If you share a chat, report, link, or workspace item, the data included in that shared item may be available to people with access to the link or workspace.
  • Legal and safety reasons. We may disclose data if required by law, court order, legal process, or to protect rights, safety, security, and integrity.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.

8. Subprocessors

We use subprocessors to provide the Service. The subprocessors may change over time as the Service evolves.

Subprocessor or categoryPurposeData processed
Vercel or other hosting providersApplication hosting, deployment, edge/network servicesAccount, usage, request, and technical data
Managed PostgreSQL database provider, such as NeonPrimary application databaseAccount, organization, chat, task, integration, and billing metadata
StripePayment processing, subscriptions, invoices, fraud preventionBilling identifiers, transaction metadata, subscription status, contact and payment data
Resend or email delivery providersTransactional and service emailsEmail address, name, email content, delivery metadata
Google APIsGoogle OAuth and Search Console integrationGoogle profile data, OAuth tokens, Search Console data
AnthropicAI model routing and generationPrompts, messages, relevant context, tool results, model usage metadata
DataForSEOSEO metrics, keyword data, SERP data, backlink data, competitor dataPublic domain, URL, keyword, and SEO query data
Firecrawl, Jina AI, Exa, Serper, or similar web data providersWeb search, page reading, crawling, and public web data retrievalURLs, public page content, search queries, crawl metadata
PostHogProduct analytics, usage analytics, event tracking, feature analysisUsage events, device data, identifiers, session metadata
Sentry or monitoring providersError monitoring, logs, performance diagnosticsError reports, stack traces, technical metadata, IP address
Object storage providersFile or asset storage where applicableUploaded or generated files and metadata

Each subprocessor is authorized to process personal data only as needed to provide its services to us and is required to protect personal data under contractual obligations.

9. International Data Transfers

We may process and transfer personal data outside your country of residence, including to the United States and other countries where our subprocessors operate.

Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to countries that have not been found to provide an adequate level of protection, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, the EU-US Data Privacy Framework where applicable, and supplementary measures where required.

10. Data Retention

We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Data categoryTypical retention
Account and organization dataFor as long as your account or organization is active, then deleted or anonymized within a reasonable period after deletion, unless retention is required by law
Session and authentication dataFor the duration needed to operate sessions, security, and account access
Google OAuth credentialsUntil you disconnect the integration, delete your account, or the credentials expire or are revoked, subject to backup retention
Google Search Console dataFetched as needed; stored only where included in connection metadata, chats, generated outputs, tasks, logs, or other user-requested features
Chat messages, AI outputs, tasks, and workspace contentUntil you delete them, delete the relevant workspace or account, or request deletion, subject to legal and backup retention
Billing, subscription, invoice, and payment recordsAs long as needed for billing and customer support, and generally up to 7 years where required for tax and accounting compliance
Support communicationsAs long as needed to handle the request and maintain business records, typically up to 2 years after the last interaction
Analytics eventsTypically up to 24 months, unless aggregated or anonymized earlier
Logs, security records, and error reportsTypically up to 12 months, unless longer retention is needed for security, fraud prevention, debugging, or legal claims
BackupsRetained for a limited period, typically up to 90 days, before being overwritten or deleted

When deletion is requested, some data may remain temporarily in encrypted backups, logs, or archives until those systems are rotated or deleted. We may also retain data where necessary to comply with law, prevent fraud, resolve disputes, enforce agreements, or protect legal rights.

11. Your Rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Delete personal data.
  • Restrict or object to certain processing.
  • Receive a copy of your data in a portable format.
  • Withdraw consent where processing is based on consent.
  • Opt out of marketing communications.
  • Lodge a complaint with a data protection authority.

To exercise your rights, contact us at hello@rankgrow.io. We may need to verify your identity before completing your request. We will respond within the time required by applicable law, generally within 30 days for GDPR requests.

If you are located in the European Union, you may also contact your local data protection authority. If our establishment in Poland is relevant to your request, the supervisory authority is the Polish Data Protection Office (UODO).

12. US State Privacy Rights

If you are a resident of a US state with a comprehensive privacy law, such as California, Colorado, Connecticut, Utah, Virginia, or similar jurisdictions, you may have additional rights, including the right to know, access, correct, delete, obtain a portable copy of your data, and opt out of certain types of processing.

We do not sell personal information and do not share personal information for cross-context behavioral advertising. We do not knowingly process sensitive personal information for the purpose of inferring characteristics about you.

You may exercise applicable rights by contacting hello@rankgrow.io. You may also designate an authorized agent where permitted by law, subject to identity and authorization verification.

13. Security

We use reasonable technical and organizational measures designed to protect personal data, including encryption in transit, encrypted storage for sensitive OAuth credentials, access controls, least-privilege practices, logging, monitoring, and vendor security review.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect the Service and respond appropriately to security risks.

If we become aware of a personal data breach that requires notification, we will notify affected users and regulators as required by applicable law.

14. Children's Privacy

The Service is not directed to children under 16 years old, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, contact us at hello@rankgrow.io, and we will take appropriate steps to delete it.

15. Third-Party Links and Services

The Service may link to third-party websites, apps, integrations, or services. Their privacy practices are governed by their own policies. We are not responsible for the privacy practices of third parties that we do not control.

When you connect a third-party integration, such as Google Search Console, your use of that integration remains subject to the third party's terms and privacy policies.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above. If changes are material, we will take reasonable steps to notify you, such as by email, in-app notice, or prominent notice on the Service.

Your continued use of the Service after an updated Privacy Policy becomes effective means you acknowledge the updated policy, to the extent permitted by law.

17. Contact

For questions, requests, or concerns about this Privacy Policy or our data practices, contact:

RankGrow
Bartosz Zagrodzki
Email: hello@rankgrow.io