Privacy Policy

Last Updated: September 28, 2026

This privacy notice describes how Rankability, Inc. collects, uses, and protects your personal data in compliance with GDPR, UK GDPR, and applicable privacy laws.

Introduction

This privacy notice for Rankability, Inc. ("we," "us," or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:

  • Visit our website at https://www.rankability.com
  • Use our AI search visibility software and tools
  • Engage with us through contact forms, support requests, or email
  • Participate in Gotch Inner Circle, membership communities, coaching sessions, programs, or events.

Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. For questions, contact us at privacy@rankability.com.

1. What Information Do We Collect?

Personal Information You Provide

We collect personal information that you voluntarily provide to us, including:

  • Contact Information: Name, email address, company name
  • Account Data: Username, password (hashed), account preferences
  • Payment Information: Billing address, payment method details (processed by Stripe)
  • Communication Data: Messages, support requests, feedback
  • Profile Information: Job title, industry, company size (optional)
  • Membership Information: Program enrollment, membership tier, access status, start and expiration dates, and participation history.
  • Community and Coaching Information: Information you choose to provide through membership communities, coaching sessions, forms, messages, posts, comments, questions, or uploaded materials.
  • Program Communications: Messages concerning coaching schedules, program access, resources, support, billing, upcoming renewals, non-renewal requests, and membership administration.

Automatically Collected Information

When you visit our website, we automatically collect certain information through cookies and similar technologies, as described in our Cookie Policy and subject to applicable law. You can manage applicable preferences through Cookie Settings. This information includes:

  • Device Information: Browser type, operating system, device type
  • Usage Data: Pages viewed, time spent, click patterns, feature usage
  • Location Data: Approximate geographic location (IP-based, anonymized)
  • Cookies & Tracking: Analytics cookies, session cookies, marketing and attribution cookies (see our Cookie Policy)

2. Lawful Basis for Processing (GDPR/UK GDPR)

We process your personal data under the following lawful bases:

Consent (Article 6(1)(a) GDPR)

Where applicable law requires consent, we rely on your consent for:

  • Analytics cookies (Google Analytics, Microsoft Clarity, PostHog)
  • Marketing communications and newsletters
  • Marketing and attribution tracking (Google Ads, Meta Pixel, OpenAI OAIQ)

Analytics and marketing cookies are described in our Cookie Policy. You can opt out or change your preferences at any time via Cookie Settings, and you can unsubscribe from marketing communications or withdraw consent by emailing us.

Contract (Article 6(1)(b) GDPR)

We process data to fulfill our contract with you:

  • Account creation and management
  • Providing Rankability software, membership programs, community access, educational resources, coaching services, and customer support.
  • Administering program enrollment and providing access through third-party community or coaching platforms.
  • Processing payments and administering billing, renewals, and non-renewal requests

Legitimate Interest (Article 6(1)(f) GDPR)

We process data for our legitimate business interests:

  • Fraud prevention and security monitoring
  • Service improvement and optimization
  • Internal analytics and business intelligence

We balance our interests against your rights and only process where our interests do not override your fundamental rights.

Legal Obligation (Article 6(1)(c) GDPR)

We process data to comply with legal obligations such as tax reporting, fraud prevention, and responding to lawful requests from authorities.

3. Third-Party Data Processors

We use the following third-party service providers and data processors to operate and deliver our Services:

Processor Purpose Location Safeguards
Google (Analytics) Website analytics USA SCCs, Data Privacy Framework
Microsoft (Clarity) Session recording, heatmaps USA SCCs, Data Privacy Framework
PostHog Website analytics, Core Web Vitals USA Provider terms and applicable safeguards
Google (Ads) Advertising measurement, conversion attribution USA Provider terms and applicable safeguards
Meta (Pixel) Advertising measurement, campaign attribution USA Provider terms and applicable safeguards
OpenAI AI response generation; marketing and campaign measurement USA Provider terms and applicable safeguards
Slack Technologies Serena for Slack installation, message delivery, and file delivery USA and other locations described by Slack Provider terms and applicable safeguards
SendGrid (Twilio) Transactional emails USA SCCs, Data Privacy Framework
Neon Database Database hosting USA SCCs, encryption at rest
Stripe Payment processing USA SCCs, PCI DSS compliant
Skool Gotch Inner Circle membership, community access, educational content, and program communications USA and other locations described by Skool Provider terms and applicable safeguards

Note: SCCs = Standard Contractual Clauses. Where indicated above, US-based processors operate under EU-approved Standard Contractual Clauses and/or the EU-US Data Privacy Framework.

Gotch Inner Circle and Membership Communities

Eligible customers may receive access to Gotch Inner Circle or other Rankability educational communities. To provide this access, we may share limited membership information with the applicable community platform, such as your name, email address, membership status, and program access period.

Information you voluntarily post or share within a membership community may be visible to other members according to the community’s settings. Third-party community and coaching platforms also process information under their own terms and privacy policies.

We use membership and participation information to provide access, administer the program, deliver resources and coaching, communicate with members, prevent unauthorized access, and improve the program.

4. Connected AI Assistants and the Rankability API (MCP)

Rankability offers a public REST API and a Model Context Protocol (MCP) server. See the MCP setup guide to connect third-party AI assistants — such as Claude Desktop, Cursor, Windsurf, and VS Code Copilot — to your Rankability account.

How access is granted

You can grant access in one of two ways:

  • OAuth 2.0 authorization. When you click "Allow Access" on the Rankability consent screen, we issue a scoped, time-limited access token (1-hour expiry) and a refresh token (30-day expiry) bound to the organization that was active at the time of consent. The connected assistant uses these tokens to call our API on your behalf.
  • API key. You may also generate a long-lived rk_live_ API key from Settings → API keys and configure your assistant to use it.

What the assistant can access

The connected assistant can read and act on data inside the organization that authorized it, limited to the scopes you approved (for example: list and view clients, read content projects and rank-tracking results, create new content briefs, trigger ranking scans, score pages). The assistant cannot access organizations you have not explicitly connected, cannot access another customer's data, and cannot exceed the scopes shown on the consent screen.

What we do with the data exchanged

Data accessed by an authorized assistant is governed by the same retention, processing, and security terms as the rest of the Rankability product, described elsewhere in this policy. We do not train models on your data, do not sell it, and do not share it with the assistant's vendor (e.g., Anthropic, Cursor) except insofar as the assistant itself sends responses back to that vendor's infrastructure to render them to you. The terms of that vendor's own privacy policy govern how the vendor handles those interactions.

Logging

Every API call made by a connected assistant is recorded in our internal audit log (organization, scope, endpoint, timestamp, status) for security, abuse detection, and customer support. These logs are retained for the same period as other application logs.

Revoking access

You can revoke a connected assistant's access at any time:

  • OAuth-connected assistants — Settings → Connected apps → Revoke. The next API call from that assistant will fail with a 401 Unauthorized.
  • API-key-connected assistants — Settings → API keys → Delete. Revocation is immediate.

If you have questions about how an authorized assistant has used your data, contact us at privacy@rankability.com.

YouTube API Services

Rankability uses YouTube API Services. Google's handling of your information is described in the Google Privacy Policy. Use of our YouTube features is also subject to the YouTube Terms of Service.

Data we access and how we use it

When you connect YouTube through Google's authorization screen, Rankability requests read-only access to your YouTube account and YouTube Analytics. This can include channel identifiers and names, channel statistics, video identifiers, titles, publication dates, thumbnails, views, likes and comment counts, and channel analytics such as watch time and subscriber changes. We store authorization tokens and selected-channel details to maintain the connection. You enter your Google credentials with Google, not Rankability.

We use this information to display channel information and reports, identify changes in channel performance, and provide relevant workspace analysis. YouTube information can be included in Serena's workspace context and processed by our contracted AI providers to generate responses. Reports, alerts, and conversations may contain YouTube information and be available to people with access to the relevant workspace. Our service providers process data to operate these features, subject to the purposes and safeguards described in this policy. Connecting YouTube does not authorize Rankability to upload, edit, or delete your YouTube videos.

Revoke Google access or disconnect a workspace

To revoke Rankability's authorization at Google, visit Google Account permissions, select Rankability, and remove access. This can affect other Google services you connected through the same authorization. You can also remove the YouTube connection in Rankability under Workspace settings → Connections → YouTube. Removing a workspace connection and revoking authorization at Google are separate controls.

Request deletion of YouTube data

To request deletion of YouTube data stored by Rankability, including information in saved reports, alerts, or conversations, email privacy@rankability.com or use our privacy request form. Identify your Rankability workspace and connected channel so we can locate the records; do not send passwords or access tokens. Removing data from Rankability does not delete videos or other information held by YouTube. Manage that information directly through YouTube.

YouTube API data is subject to YouTube's specific storage, refresh, and deletion requirements, rather than an unrestricted right to retain it for the general account-retention period below. See the YouTube Developer Policies. Disconnecting alone should not be treated as confirmation that every saved report or conversation has been erased; contact us for a data-deletion request and confirmation.

Serena for Slack

If a workspace administrator installs Serena for Slack and a Rankability organization administrator confirms the pairing, Rankability processes Slack data only to provide, secure, meter, and support that integration.

Slack data we collect

  • Workspace, app, bot, installer, channel, thread, and sender identifiers needed to install, pair, route, and audit the integration.
  • Messages sent directly to Serena, messages that directly mention Serena in a channel where the app is present, and replies within the resulting Serena thread.
  • Images that a user deliberately attaches to a Serena direct message or mention.
  • The relevant data from the paired Rankability organization needed to answer the user's request, plus Serena's response.
  • An encrypted Slack bot token and authorization metadata. The plaintext token is not stored in application records.

How Serena behaves in Slack

Serena responds to direct messages, direct @mentions, and follow-up replies in its threads. Serena does not monitor ordinary channel conversation, search public or private channel history, or enumerate workspace users. Proactive Slack digests and alerts are disabled by default.

AI processing and retention

Rankability sends the user-requested message, permitted attachments, and relevant Rankability context to our contracted AI service providers to generate Serena's response. Rankability does not use Slack data to train models or sell Slack data. Thread context is bounded in the active product, and Slack conversation and connection records follow the Account Data retention period below, subject to security, legal, backup, and deletion obligations.

Control and deletion

An organization administrator can disconnect Serena from Rankability Settings → Connected apps. Slack workspace administrators can also remove the app in Slack. To request access or deletion, use our Data Subject Rights Portal or email privacy@rankability.com.

5. International Data Transfers

Rankability, Inc. is based in the United States. If you are accessing our services from the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States.

We ensure appropriate safeguards are in place for all international transfers:

  • Standard Contractual Clauses (SCCs): EU Commission-approved clauses with US-based processors where applicable
  • EU-US Data Privacy Framework: Processors certified under the adequacy decision
  • Technical Safeguards: Encryption in transit (TLS 1.2 or later) and at rest (AES-256)
  • Access Controls: Role-based access, multi-factor authentication, audit logs

6. Data Retention Periods

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Account Data Active account + 3 years after closure
Payment Records 7 years (tax/legal requirements)
Analytics Cookies Up to 2 years
Marketing Cookies 90 days
Support Requests 3 years after resolution
Marketing Communications Until unsubscribe + 30 days
Membership and Program Records Active membership plus three years after membership closure, unless a longer period is required for payment, tax, dispute, or legal purposes

After retention periods expire, we securely delete or anonymize your data. You can request early deletion at any time (subject to legal requirements).

7. Your Data Protection Rights

If you are located in the EEA, UK, or Switzerland, you have the following rights under GDPR/UK GDPR:

Right to Access (Article 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Article 16)

Correct inaccurate or incomplete personal data.

Right to Erasure / "Right to be Forgotten" (Article 17)

Request deletion of your personal data (subject to legal obligations).

Right to Restriction (Article 18)

Request restriction of processing in certain circumstances.

Right to Data Portability (Article 20)

Receive your data in a structured, machine-readable format (CSV/JSON).

Right to Object (Article 21)

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw any consent you have given, and opt out of analytics or marketing cookies at any time via Cookie Settings.

Right to Lodge a Complaint

File a complaint with your local data protection authority if you believe your rights have been violated.

How to Exercise Your Rights: Visit our Data Subject Rights Portal or email privacy@rankability.com. We will respond within 30 days.

8. How We Protect Your Data

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption: TLS 1.2 or later for data in transit, AES-256 for data at rest
  • Access Controls: Role-based access, multi-factor authentication, least privilege principle
  • Regular Audits: Security assessments, penetration testing, vulnerability scanning
  • Staff Training: Regular data protection and security awareness training
  • Incident Response: Documented breach notification procedures (within 72 hours to authorities)
  • Vendor Management: DPAs or provider terms with processors as applicable, regular compliance reviews

While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

9. Children's Privacy

Our Services are not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@rankability.com.

10. Updates to This Policy

We may update this privacy policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by email (if you have an account) or by posting a prominent notice on our website. The "Last Updated" date at the top indicates when the policy was last revised.

11. Contact Information

For privacy-related questions, data subject rights requests, or complaints:

Privacy Contact

Email: privacy@rankability.com

Company Information

Rankability, Inc., a Delaware corporation

6 Cardinal Way, Suite 900

St. Louis, MO 63102

United States

EU Representative

We are currently a small business and do not have a dedicated EU representative. EU residents can contact us directly at the address above or at privacy@rankability.com.

Supervisory Authority

EU/EEA residents have the right to lodge a complaint with their local data protection authority. UK residents can contact the Information Commissioner's Office (ICO).