Privacy policy
Rankvisit gives your AI assistant read-only access to your search and analytics data. We collect as little as possible and we do not keep copies of your search or analytics data.
Last updated: 1 October 2026
1. Who is responsible
The controller for the processing described here is Halfmage, Gerrit Halfmann, Barbary Kostrzewskiej 39, 52-131 Wrocław, Poland (NIP 8993022263). Contact: [email protected]. See also the imprint.
2. What we process
Your account
When you sign in with Google, we receive your name, email address and profile picture. We use them to identify your account and to show who is signed in.
Google Search Console access
When you connect Search Console, Google gives us an access token and a refresh token with the read-only scope webmasters.readonly. We store these tokens encrypted (AES-256-GCM). We use them only to read Search Console data when your assistant asks for it. We do not store the Search Console data itself.
Analytics API keys
If you connect Fathom Analytics or Simple Analytics, we store your API key (and, for Simple Analytics, your User ID) encrypted. We keep the last four characters of the key in plain text, so that you can recognise it. We use the key only to read statistics when your assistant asks for them. We do not store the statistics.
AI assistants you connect
When you allow an assistant (for example Claude, ChatGPT, Codex or Cursor), we store that permission and the OAuth tokens for that assistant. Access tokens are short-lived. When your assistant calls a Rankvisit tool, we read the requested data from Google or your analytics tool and send it to that assistant. From then on, the assistant provider processes the data under its own terms and privacy policy.
Billing
Payments are handled by Stripe. Stripe processes your payment details; we never see your card number. We store the Stripe customer and subscription IDs, your plan and the subscription status.
Technical data
Like every website, our servers and our network provider receive your IP address, the time of the request and your browser information. We use them to deliver the service, to protect it against abuse (for example rate limits) and to find errors. [TODO: how long server logs are kept, for example 14 days.]
3. Why we process it (legal bases)
- To provide the service you signed up for (Art. 6(1)(b) GDPR): account, connections, tool requests and billing.
- Legitimate interests (Art. 6(1)(f) GDPR): security, abuse prevention and error analysis.
- Legal obligations (Art. 6(1)(c) GDPR): for example tax records for invoices.
4. Google user data
Rankvisit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We request read-only access only.
- We use Google data only to answer the requests you make through your connected assistant.
- We do not sell Google data, do not use it for advertising, and do not use it to train AI models.
- No person at Rankvisit reads your Google data, except with your permission for support or where the law requires it.
5. Who receives data
- Google: sign-in and the Search Console API.
- Fathom Analytics or Simple Analytics: only if you connect them; we call their API with your key.
- The AI assistants you connect: they receive the data your questions ask for.
- Stripe: payments, invoices and tax handling.
- Cloudflare: network delivery and protection of rankvisit.com.
- Our hosting provider: hosting of the application and database on servers in Frankfurt am Main, Germany (EU).
Some of these providers are located outside the EU (for example in the USA). Where this is the case, the transfer is based on an adequacy decision (such as the EU-US Data Privacy Framework) or on standard contractual clauses.
6. Cookies
We use one necessary cookie to keep you signed in. We do not use advertising or tracking cookies, so we do not show a cookie banner.
7. How long we keep data
- Account: until you delete it.
- After your subscription ends: we delete your analytics keys, your assistant permissions and your Google tokens after 14 days. Your account stays, so that you can subscribe again.
- When you delete your account: we cancel your subscription, revoke Google access and delete your account and all connected data at once.
- Invoices: Stripe keeps them as long as tax law requires.
8. Your rights
You can request access to your data, correction, deletion, restriction of processing and a copy of your data (portability), and you can object to processing based on legitimate interests. You can delete your account yourself in the dashboard, or email [email protected]. You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live or work. Our lead authority is the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl).
You can remove Rankvisit's access to Google at any time in your Google account.
9. Security
Connections use TLS. Tokens and API keys are encrypted at rest. Access is read-only, and every assistant needs your explicit permission. You can remove an assistant or a connection at any time in the dashboard.
10. Children
Rankvisit is a business tool and is not intended for people under 16.
11. Changes
When we change this policy, we update the date at the top. For important changes, we inform account holders by email.