Skip to content
Legal

Privacy Policy

RankMeFast collects the minimum data needed to run your audits and rank tracking. This Policy explains what that is, how it is protected, and the choices you have.

Last updated: August 2026

1. Overview

This Privacy Policy explains what RankMeFast collects, why, how it is protected, and the choices you have. It applies to the hosted Service at rankme.fast and to self-hosted instances running the same software.

For self-hosted deployments, RankMeFast the organisation has no access to your data — everything runs on your own infrastructure. The information below describes the hosted Service.

2. Data we collect

Account data. Name, email address, password (scrypt hash only), preferred language, role, and email-verification state. Optional Google OAuth profile if you sign in with Google.

Session data. Session token, IP address, and user agent stored with each session for security and abuse prevention.

Usage data. Per-account monthly counters for tracked keywords, audits, audit pages, backlink rows, AI summaries, and seats. These counters enforce plan limits.

Product data. Domains you add, tracked keywords, rank history, audit reports, backlink rows, competitor sets, and keyword-research results. This is the working data the Service produces for you.

Billing data. Subscription tier, invoices, and credit-ledger entries. Card details are handled by Polar; RankMeFast does not store full card numbers.

Vendor credentials. Google Search Console refresh tokens and DataForSEO credentials, when you configure them. These are encrypted at rest with AES-256-GCM under a master key.

Contact-form messages. If you use the contact form, the message content and your email address are delivered to our support inbox via Resend.

3. How we use your data

We use the data above to:

  • Provision and operate your account, sites, and audits.
  • Enforce plan limits and prevent abuse through rate limiting and cross-account isolation.
  • Process payments through Polar and maintain an invoice and credit-ledger history.
  • Send transactional email: verification, password reset, audit completion, rank-drop alerts, and deletion warnings. Marketing email is opt-out and only sent if the corresponding preference is enabled.
  • Generate AI summaries when the feature is enabled. Only the generated rule copy and site domain are sent to the AI model — never raw HTML, vendor payloads, or your personal data.
  • Maintain audit logs for security. Audit logs never record email addresses, request bodies, headers, or sensitive parameters.

4. Cookies and similar technologies

Session cookie. A single httpOnly, SameSite=Lax cookie (better-auth.session_token) keeps you signed in. It is marked Secure in production.

CSRF cookie. A double-submit token (x-csrf-token by default) protects forms. It is SameSite=Strict and Secure in production.

Language cookie. A lang cookie stores your interface-language preference for one year.

When the hosted site is configured with Google Analytics, Google receives browser and usage information and may set analytics identifiers. RankMeFast does not use advertising cookies.

5. Data sharing and sub-processors

RankMeFast shares data only with the sub-processors required to run the Service:

  • Polar — payment processing and subscription management. Receives product IDs, customer references, and webhook events. Does not receive your audit or rank data.
  • DataForSEO — keyword, rank, backlink, competitor, and Lighthouse lab-speed signals. Receives the domains, keywords, and public audit URLs you submit.
  • Google APIs (OAuth, Search Console, and Analytics; optional PageSpeed Insights and CrUX when configured) receives connected-property data. Search Console URL Inspection sends sampled public site URLs when a property is connected; PageSpeed sends public audit URLs only when Google is selected for page speed. If the hosted site is configured for Google Analytics, Google also receives browser and site-usage events.
  • Firecrawl (Cloud) — public-page crawling for audit, monitoring, and Content Intelligence. Receives only the public URLs you select.
  • AI providers processes AI summaries and Content Intelligence briefs or drafts through the operator-approved provider list: GLM, DeepSeek, Kimi, OpenAI, Gemini, and Anthropic Claude. Only bounded, sanitized page excerpts are sent, and only after your explicit opt-in. Raw HTML is never sent. Provider data-use terms depend on the operator's current agreement and configuration.
  • Resend — transactional and notification email delivery.

If the hosted site is configured for Google Analytics, Google also receives browser and site-usage events.

Each sub-processor is bound by its own data-protection terms. RankMeFast does not sell your data.

6. Content Intelligence and AI processing

Content Intelligence is opt-in per analysis. When you run it we process the following:

  • Firecrawl Cloud crawls the public URLs you select — your owned page and up to three public competitor pages you accept. It never sees authenticated pages or takes screenshots.
  • Sanitized, bounded page excerpts and derived facts are stored to build the scorecard, brief, and citations.
  • If, and only if, you opt in for the AI brief or first draft, sanitized excerpts are sent through the operator-approved provider list: GLM, DeepSeek, Kimi, OpenAI, Gemini, and Anthropic Claude. The list comes from a reviewed legal authority, never from live environment settings.
  • No raw HTML is retained. Sanitized excerpts expire after 7 days. Derived facts, hashes, briefs, drafts, citations, and usage stay under the account retention policy.
  • Public competitor content is used as short, cited evidence and is not substantially republished. Provider data-use terms are governed by the operator's current agreements; this Policy does not make a broader training promise.

Nothing is published automatically. Briefs and drafts live inside RankMeFast as editable working copies; export or delete them at any time.

7. Security safeguards

  • Vendor secrets and refresh tokens are encrypted at rest with AES-256-GCM using a master key.
  • Passwords are hashed with scrypt via Better Auth; plaintext passwords are never stored.
  • Cross-account isolation: every product route verifies ownership and returns 404 (not 403) for foreign resources so existence never leaks.
  • Rate limits on authentication and webhook routes reduce brute-force and volumetric abuse.
  • Two-factor authentication (TOTP + backup codes) is available on all accounts and required for admins.
  • CSRF is enforced via Origin and trusted-origins checks plus the double-submit cookie.

No system is perfectly secure. If you believe you have found a vulnerability, please contact security@rankme.fast before public disclosure.

8. Data retention

Derived facts, hashes, scorecards, briefs, drafts, citations, recommendation history, monitor results, and usage records remain under your account retention policy until export or deletion. Raw HTML is not retained, and sanitized excerpts expire after 7 days.

Billing records (invoices, credit ledger) are retained for the period required by tax law in the operating jurisdiction.

Audit logs that carry security-relevant metadata are retained on a rolling basis and never contain email addresses or request bodies.

9. Your rights (GDPR and similar)

Depending on your jurisdiction (EU/EEA, UK, California, etc.) you may have the right to:

  • Access a copy of your personal data.
  • Correct inaccurate data.
  • Export your account data, including audits, rank history, Content Intelligence analyses, inventory and competitor runs, monitors, recommendation history, outcomes, and related usage events.
  • Delete your account. Deletion enters a 30-day grace period during which you can cancel. A final warning email is sent 24 hours before the purge. A legal hold may delay deletion where required by law.
  • Object to or restrict certain processing, and withdraw consent for marketing email at any time via notification preferences.
  • Lodge a complaint with your supervisory authority if you believe processing violates applicable law.

To exercise any of these rights, use the in-app data-rights endpoints (/api/legal/*) or contact privacy@rankme.fast.

10. International data transfers

Your data may be processed by RankMeFast and its sub-processors in jurisdictions outside your country of residence. Where the EU/EEA is involved, transfers rely on appropriate safeguards such as Standard Contractual Clauses or another lawful transfer mechanism.

Self-hosted deployments keep all data on your own infrastructure; no transfer to RankMeFast occurs.

11. Children’s privacy

The Service is not directed to children under 16. RankMeFast does not knowingly collect personal data from children. If you believe a minor has registered, contact privacy@rankme.fast and the account will be removed.

12. Self-hosted deployments

On a self-hosted instance you control the infrastructure, the encryption keys, and the vendor integrations. RankMeFast the organisation does not receive data from your instance. You are responsible for compliance with this Policy’s obligations (including data-subject requests) for data you process on your own deployment.

13. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email (to verified accounts) or in-app at least 30 days before taking effect. The “Last updated” date below reflects the most recent revision.

14. Contact

Questions about this Privacy Policy or a data-subject request? Contact privacy@rankme.fast.