Privacy Policy
Last updated: 25 September 2026
This policy explains what personal data RankFlow collects through rankflow.works and the application at app.rankflow.works, why we collect it, who receives it, how long we keep it and what you can do about it. It describes how the product actually handles data today.
1.Who we are
RankFlow provides the RankFlow SEO content platform. For data about our customers, their team members, people who contact us and visitors to rankflow.works, RankFlow is the controller.
When you use RankFlow to handle data about your own website visitors or customers, for example conversations and contact details collected by the Chat AI widget, or contacts synced from GoHighLevel, you are the controller of that data and RankFlow processes it on your behalf and on your instructions.
For any privacy question or request, write to hello@rankflow.works.
2.Data we collect
Depending on the features you use, we collect:
- Account data: your name, email address, password (stored only as a one-way hash), an optional profile picture, your plan and your account status.
- Team data: invitations (the invitee's email address and role), roles and section permissions, and messages in team chat.
- Billing data: invoices with the plan, billing period, amount, due date, status and payment notes.
- Site and content data: the websites you add and their settings, briefs, keywords, strategies, articles, landing pages, generated sites, forms, and the images and files you upload. If you use that feature, also product data synced from WooCommerce.
- Credentials for connected services: WordPress Application Passwords, REST API keys, FTP or FTPS logins, SMTP or Brevo keys for sending form emails, GoHighLevel tokens and Google OAuth tokens.
- Data from connected services, depending on what you connect: Search Console performance, URL inspection and sitemap data; Business Profile locations, reviews (including reviewers' names), posts, photos and performance data; GoHighLevel contacts, opportunities, conversations, and social and ad statistics.
- Usage and AI metering: which AI features were used, for which site, with which model, and the calls, tokens and cost involved.
- Audit log: for actions that change data in a site, who performed them, when and what changed (with secrets redacted), plus the IP address and browser user agent of the request.
- Email and notification data: a log of the emails we send (type, recipient, subject, status), the extra notification recipients you add, and your notification preferences.
- Support data: support tickets and messages, and feature requests you send from the app.
- The quote form on rankflow.works: your name, email address and website address, and optionally the plan you are interested in and a message. The form is sent to our team by email and is not stored in the RankFlow app.
We also process data about your website's visitors on your behalf, as described below under “Visitor data we process for you”.
3.How we use data
- To create and run your account, review registrations and provide the features you use.
- To generate content, analysis and replies with AI, publish to the sites you connect, sync data from connected services, and run the checks you start or schedule.
- To measure usage against your plan's limits, issue invoices, and suspend or restore access depending on whether invoices are paid.
- To send service emails, such as registration and approval messages, team invitations, account suspension notices and the notifications you choose to receive.
- To keep the service secure: rate limiting, preventing abuse, investigating problems and keeping the audit log.
- To answer support tickets, feature requests and quote requests.
- To troubleshoot and improve RankFlow, including checking logs of AI requests when output or costs look wrong.
We do not sell personal data and do not use it for advertising. Neither the app nor rankflow.works uses third-party analytics or advertising trackers.
Where the law requires a legal basis, we rely on performing our contract with you, our legitimate interest in running and securing the service, your consent (for example when you send the quote form) and our legal obligations.
4.AI providers and other recipients
To generate output, RankFlow sends the data a feature needs to AI providers through their APIs. Depending on the feature, this can include your site details and content, article drafts, keywords, web pages fetched for research, Search Console queries, Google reviews you want to answer, and messages from visitors to your Chat AI widget.
- Anthropic: Claude models, including its web search and web fetch tools for research features.
- OpenAI: GPT models, image generation, and text embeddings for the Chat AI knowledge base.
- DeepSeek: DeepSeek models, when RankFlow assigns them to a feature.
RankFlow decides which provider and model handles each feature and may change this. Each provider processes the data under its own API terms, and may do so outside your country.
We keep logs of AI requests (the prompt sent and the output received) on our servers to troubleshoot quality and cost. Requests that extract contact details from a visitor's chat messages are left out of these logs.
Other recipients:
- The infrastructure provider that hosts our servers and database, and the email service we use to send email.
- The public OSV vulnerability database (osv.dev), which receives only the names and versions of public software libraries that a Site Health check finds on your site.
- The services you connect, such as your WordPress site, your hosting, GoHighLevel, Google, Brevo or a webhook you set up, which receive data because you instruct us to send it.
- Your team members, according to the roles and permissions you give them.
- Authorities, where the law requires it, or a successor if RankFlow's business is transferred, in which case this policy continues to apply to your data.
5.Google user data
If you connect Google Search Console or Google Business Profile, you sign in with Google and approve access on Google's consent screen.
- Search Console (webmasters scope): we read your properties, search performance (queries, pages, clicks, impressions, positions), URL inspection results and sitemaps, and manage sitemaps when you ask us to.
- Indexing API (indexing scope): we notify Google about URLs you publish or choose to submit.
- Business Profile (business.manage scope): we read and manage your locations, profile information, reviews and replies, posts, photos and performance data, and publish the changes and replies you make or approve, including automatic review replies if you turn them on.
We use Google user data only to provide the RankFlow features you use. We do not sell it, use it for advertising or use it to train AI models. When you use an AI feature that needs Google data, such as keyword research with Search Console queries or a reply to a review, only the data needed for that output is sent to our AI provider.
People at RankFlow do not read your Google data unless you ask us to for support, it is necessary for security, or the law requires it.
RankFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google tokens are stored encrypted. You can disconnect at any time in the app; disconnecting Business Profile also revokes our access at Google and deletes the synced profile data from RankFlow. You can also remove RankFlow's access in your Google Account settings (myaccount.google.com/permissions).
6.Visitor data we process for you
Some RankFlow features run on your website and handle data about your visitors. For this data you are the controller and RankFlow is your processor.
- Chat AI widget: we store each conversation (messages, a random visitor ID, browser language and times) for your site. Visitors' messages are sent to an AI provider to generate replies. Your team can read conversations, take over a chat and delete conversations.
- Contact capture: off by default. If you turn it on, details a visitor shares in the chat, such as name, email, phone, company, address and custom fields you define, are saved to your site's Contacts, which your team can edit, export and delete.
- The widget sets no cookies. When chat history is enabled, it keeps the random visitor ID in the visitor's browser localStorage (key __rf_vid) so that a returning visitor can continue the conversation.
- Landing page and RFW site analytics: pages you publish with RankFlow report page views, scroll depth, time on page and clicks. They set no cookies, use a random session ID kept in sessionStorage that ends when the tab is closed, and we do not store visitors' IP addresses. For RFW sites we keep only the referring domain and the device type; raw events are deleted after 30 days and daily totals are kept.
- Forms: submissions from landing page forms are forwarded to the destination you choose (an email sent by RankFlow, your Brevo account or your webhook) and are not stored in RankFlow; emailed submissions include the sender's IP address, browser and page address. Forms on RFW sites are handled by a script on your own hosting and do not pass through RankFlow at all.
- Pages RankFlow generates can load fonts from Google Fonts, which means visitors' browsers connect to Google.
You are responsible for having a legal basis for this processing, for telling your visitors about it in your own privacy notice, and for answering their requests. We will help you with requests about data we hold for you.
7.How long we keep data
- Account, site and content data: while your account is active. Deleting a site deletes it and the data stored with it from our database. Deleting an account also deletes the sites it owns.
- Suspended accounts: blocked, not deleted; their data is kept.
- Audit log: 90 days in our database, after which entries move to compressed monthly archive files; archive files older than six months are deleted.
- Chat conversations and contacts: until your team deletes them or the site is deleted.
- RFW visitor analytics: raw events for 30 days; daily totals for as long as the site exists.
- Team invitations: the invitation link expires after seven days.
- Sign-in sessions: an access token is valid for 15 minutes and a session for up to 7 days, unless you sign out earlier.
- Logs of AI requests and other technical logs: kept on our servers for troubleshooting.
- Quote requests from rankflow.works: kept in our email for as long as we need them to answer you and follow up.
8.Security
- Account passwords are stored only as bcrypt hashes.
- Passwords, API keys and OAuth tokens for connected services are encrypted at rest with AES-256-GCM.
- Sign-in uses short-lived access tokens kept only in the page's memory, and a refresh token in an HttpOnly cookie that we store only as a hash. Requests are protected against cross-site request forgery, and a suspended account can no longer sign in or renew a session.
- Inside a site, access depends on each member's role and section permissions. In the app, only the site owner can view the audit log, and passwords, tokens and keys are redacted from it.
- The API applies rate limits and standard security headers.
- When you connect WordPress through the RankFlow plugin, the Application Password is exchanged directly between the servers and never appears in a URL.
- Authorised RankFlow staff can access an account when needed for account approval, support, billing or security. Actions staff take inside an account are recorded in the audit log as staff actions.
Files you upload to the media library are stored on our servers under random file names and served from public web addresses, so that they can appear on your published pages. Anyone who has a file's address can open it.
No system is completely secure. If a breach affects your personal data, we will inform you as the law requires.
9.Your rights and choices
Depending on where you live, you may have the right to access, correct or delete your personal data or receive a copy of it, to object to or restrict some processing, and to withdraw consent at any time.
Much of this you can do yourself in the app: edit your profile, turn off notification emails by type for each site, disconnect integrations, remove team members, delete chat conversations and contacts, export contacts and, as a site owner, delete a site.
For anything else, including deleting your account or getting a copy of your data, email hello@rankflow.works from the address on your account. We may need to confirm your identity, and we aim to reply within 30 days.
If you are a visitor to a website that uses RankFlow, contact that website's owner, who controls your data. If you write to us instead, we will pass your request on to them and help them respond.
You also have the right to complain to your data protection authority.
11.Children
RankFlow is a service for businesses and professionals and is not intended for children. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
12.Changes to this policy
We update this policy when the way we handle data changes. The date at the top shows the current version. We will tell account owners about material changes by email or in the app before they take effect.
13.Contact
Privacy questions and requests: hello@rankflow.works.
Service emails are sent from noreply@rankflow.works. To reach us, write to hello@rankflow.works rather than replying to them.