Privacy Policy
Last updated: 25 August 2026
Information we collect
- Account info — your email and name, from Google Sign-In.
- Websites you add — the URL, name, target country/language, and description you provide.
- Crawl data — publicly visible page content (titles, meta descriptions, headings, links, word counts) from sites you choose to audit.
- WordPress connections (optional) — the site URL, username, and an encrypted WordPress Application Password. We never see or store your actual WordPress account password — Application Passwords are a separate, revocable credential WordPress generates for this purpose. Applying fixes also relies on the RankGrep connector plugin installed on your own site, which stores the values RankGrep writes in your WordPress database and sends nothing anywhere on its own.
- Google Search Console (optional) — if you connect it, read-only search performance accessed via an encrypted OAuth refresh token. This includes the search terms people typed to reach your site, the pages they landed on, and the country and device they used, alongside clicks, impressions and average position.
- Google Analytics (optional) — if you connect it, read-only traffic figures: sessions, active users, page views, landing pages and traffic channels. RankGrep also stores the names and web addresses of the GA4 and Search Console properties in your Google account, which is how it works out which property belongs to which of your websites.
- AI Assistant conversations — the questions you ask the assistant and its replies are stored, so a conversation can be reopened later.
How we use it
To run audits, detect issues with real evidence, prepare and — once you approve — apply fixes, and show you real search and traffic performance for websites you’ve connected.
AI processing
Crawled page content, issue evidence, the messages you send the AI Assistant, and search performance figures used as context may be sent to a third-party AI provider (Anthropic, OpenAI, or Google Gemini, depending on configuration) to generate analysis and suggested fixes. We never send your Google account password or WordPress password to these providers — we don’t have them to send.
Google user data
RankGrep’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data sharing
We don’t sell your data. Information is only shared with the third-party services needed to provide the feature you used — Google’s APIs (sign-in, Search Console, Analytics), an AI provider for repair analysis, and Google PageSpeed Insights for performance scores.
Where your data is stored
RankGrep runs on Vercel and stores its data in a managed PostgreSQL database provided by Neon. Both may process and store data on servers outside your own country.
Data retention
Data is kept while your account is active. Removing a website deletes its crawl, issue, repair and AI Assistant history, its performance scores, and its WordPress connection. Search Console and Analytics figures already imported are held against the Google property they came from rather than against the website, so removing a website unlinks them but does not delete them. Contact us to delete your account and everything associated with it, including those.
Security
WordPress Application Passwords and Google refresh tokens are encrypted at rest. External sign-in uses OAuth or scoped application credentials only — RankGrep never asks for or stores your Google or WordPress password.
Your choices
Disconnect a WordPress or Google connection anytime from Connections. Sign out anytime. Email us to request account deletion.
Changes
As a preview product, this policy may change. Material changes will update the date above.
Contact
Questions about this policy: uniqueagencies94@gmail.com