Privacy Policy
Effective Date: August 2026 | Last Updated: August 20, 2026
At RankRoot (accessible from https://rankroot.app), we respect your privacy and are committed to protecting your personal data and sensitive information. This Privacy Policy explains what information we collect, how we use it, how we protect it, and our strict policies regarding the handling, sharing, and protection of Google user data.
1. Information We Collect
We collect information you provide directly to us when you create an account, connect integrations, or use our tools:
- Account Information: Your name, email address, and authentication credentials when registering via email or OAuth providers.
- Google User Data (Google Search Console): When you explicitly connect your Google account, we access read-only Google Search Console (GSC) data (such as search queries, impressions, clicks, CTR, and average position for your verified web properties) via the Google Search Console API.
- Website & Backlink Data: Website domain URLs, meta tags, page speed metrics, backlink targets, anchor texts, and SEO analysis parameters that you input, import, or audit.
- Bing Webmaster Data: Bing Webmaster API keys and associated query performance metrics if you choose to connect Bing integration.
2. How We Use Google User Data & Other Information
We use the information collected strictly to deliver, maintain, and enhance the RankRoot SEO analysis service:
- To display your organic search performance metrics, impressions, clicks, and keyword rankings in your private RankRoot dashboard.
- To calculate your asset SEO stage and generate tailored 90-day backlink and content opportunity roadmaps.
- To monitor AI citations across Google AI Overviews and search engines.
- To send essential transactional notifications (such as weekly SEO digests or critical link alerts) via secure email providers.
No AI Model Training: Google user data and Search Console information obtained through Google APIs are never used to develop, improve, or train generalized Artificial Intelligence (AI) or Machine Learning (ML) models.
3. Sharing, Transfer, and Disclosure of Google User Data
RankRoot does not sell, rent, trade, or monetize Google user data under any circumstances.
We do not share, transfer, or disclose Google user data with any third parties, advertising networks, data brokers, or external partners, except in the following limited technical circumstances:
- Essential Hosting & Infrastructure Subprocessors: We utilize Cloudflare (Cloudflare Workers, D1 SQL Database, and KV Storage) strictly for hosting, serverless compute, and encrypted database storage. These infrastructure providers process data strictly on our behalf under confidentiality agreements and do not use the data for any independent purposes.
- Legal Requirements: We may disclose information only if required to do so by applicable law, regulation, or valid legal process.
We do not permit human review of your private Google Search Console data unless you provide explicit consent to our technical team to troubleshoot a specific support issue, or where required for system security audits.
4. Google API Services User Data Policy Compliance
RankRoot's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Data Protection & Security Mechanisms for Sensitive Data
We take the security of your sensitive information and Google user data seriously and enforce industry-standard administrative, physical, and technical safeguards:
- Encryption in Transit: All communications between your browser, RankRoot servers, and Google API endpoints are encrypted using strong Transport Layer Security (TLS 1.2 / TLS 1.3 / HTTPS).
- Encryption at Rest: Sensitive credentials, OAuth access tokens, and refresh tokens are encrypted at rest using industry-standard AES-256 encryption before being stored in our Cloudflare D1 distributed database.
- Access Control & Least Privilege: Application access to Google APIs requests the minimum necessary read-only scopes (e.g.,
webmasters.readonly). Access to database records is restricted to authenticated user sessions verified with secure HTTP-only cookies and cryptographically signed session tokens. - Token Revocation & Lifecycle Management: OAuth tokens are automatically refreshed via secure server-to-server calls and can be immediately revoked by the user at any time.
6. Data Retention, Disconnection, and Deletion
We retain your Google Search Console performance metrics and account data only for as long as your account remains active and connected to our service.
- Disconnecting Google Account: You can disconnect your Google Search Console account at any time from your Project Settings or Dashboard. Upon disconnection, your Google OAuth access and refresh tokens are permanently purged from our database immediately.
- Revoking Access via Google: You can also revoke RankRoot's permissions at any time directly through your Google Security Settings (Third-party apps with account access).
- Account Deletion: Deleting a project or your RankRoot account permanently erases all associated data, including search metrics, cached queries, and connection tokens, within 24 hours.
7. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your data protection rights, please contact us at: