Privacy Policy
Last Updated: September 28, 2026
This privacy notice describes how Rankability, Inc. collects, uses, and protects your personal data in compliance with GDPR, UK GDPR, and applicable privacy laws.
Introduction
This privacy notice for Rankability, Inc. ("we," "us," or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
- Visit our website at https://www.rankability.com
- Use our AI search visibility software and tools
- Engage with us through contact forms, support requests, or email
- Participate in Gotch Inner Circle, membership communities, coaching sessions, programs, or events.
Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. For questions, contact us at privacy@rankability.com.
1. What Information Do We Collect?
Personal Information You Provide
We collect personal information that you voluntarily provide to us, including:
- Contact Information: Name, email address, company name
- Account Data: Username, password (hashed), account preferences
- Payment Information: Billing address, payment method details (processed by Stripe)
- Communication Data: Messages, support requests, feedback
- Profile Information: Job title, industry, company size (optional)
- Membership Information: Program enrollment, membership tier, access status, start and expiration dates, and participation history.
- Community and Coaching Information: Information you choose to provide through membership communities, coaching sessions, forms, messages, posts, comments, questions, or uploaded materials.
- Program Communications: Messages concerning coaching schedules, program access, resources, support, billing, upcoming renewals, non-renewal requests, and membership administration.
Automatically Collected Information
When you visit our website, we automatically collect certain information through cookies and similar technologies, as described in our Cookie Policy and subject to applicable law. You can manage applicable preferences through Cookie Settings. This information includes:
- Device Information: Browser type, operating system, device type
- Usage Data: Pages viewed, time spent, click patterns, feature usage
- Location Data: Approximate geographic location (IP-based, anonymized)
- Cookies & Tracking: Analytics cookies, session cookies, marketing and attribution cookies (see our Cookie Policy)
2. Lawful Basis for Processing (GDPR/UK GDPR)
We process your personal data under the following lawful bases:
Consent (Article 6(1)(a) GDPR)
Where applicable law requires consent, we rely on your consent for:
- Analytics cookies (Google Analytics, Microsoft Clarity, PostHog)
- Marketing communications and newsletters
- Marketing and attribution tracking (Google Ads, Meta Pixel, OpenAI OAIQ)
Analytics and marketing cookies are described in our Cookie Policy. You can opt out or change your preferences at any time via Cookie Settings, and you can unsubscribe from marketing communications or withdraw consent by emailing us.
Contract (Article 6(1)(b) GDPR)
We process data to fulfill our contract with you:
- Account creation and management
- Providing Rankability software, membership programs, community access, educational resources, coaching services, and customer support.
- Administering program enrollment and providing access through third-party community or coaching platforms.
- Processing payments and administering billing, renewals, and non-renewal requests
Legitimate Interest (Article 6(1)(f) GDPR)
We process data for our legitimate business interests:
- Fraud prevention and security monitoring
- Service improvement and optimization
- Internal analytics and business intelligence
We balance our interests against your rights and only process where our interests do not override your fundamental rights.
Legal Obligation (Article 6(1)(c) GDPR)
We process data to comply with legal obligations such as tax reporting, fraud prevention, and responding to lawful requests from authorities.
3. Third-Party Data Processors
We use the following third-party service providers and data processors to operate and deliver our Services:
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google (Analytics) | Website analytics | USA | SCCs, Data Privacy Framework |
| Microsoft (Clarity) | Session recording, heatmaps | USA | SCCs, Data Privacy Framework |
| PostHog | Website analytics, Core Web Vitals | USA | Provider terms and applicable safeguards |
| Google (Ads) | Advertising measurement, conversion attribution | USA | Provider terms and applicable safeguards |
| Meta (Pixel) | Advertising measurement, campaign attribution | USA | Provider terms and applicable safeguards |
| OpenAI | AI response generation; marketing and campaign measurement | USA | Provider terms and applicable safeguards |
| Slack Technologies | Serena for Slack installation, message delivery, and file delivery | USA and other locations described by Slack | Provider terms and applicable safeguards |
| SendGrid (Twilio) | Transactional emails | USA | SCCs, Data Privacy Framework |
| Neon Database | Database hosting | USA | SCCs, encryption at rest |
| Stripe | Payment processing | USA | SCCs, PCI DSS compliant |
| Skool | Gotch Inner Circle membership, community access, educational content, and program communications | USA and other locations described by Skool | Provider terms and applicable safeguards |
Note: SCCs = Standard Contractual Clauses. Where indicated above, US-based processors operate under EU-approved Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
Gotch Inner Circle and Membership Communities
Eligible customers may receive access to Gotch Inner Circle or other Rankability educational communities. To provide this access, we may share limited membership information with the applicable community platform, such as your name, email address, membership status, and program access period.
Information you voluntarily post or share within a membership community may be visible to other members according to the community’s settings. Third-party community and coaching platforms also process information under their own terms and privacy policies.
We use membership and participation information to provide access, administer the program, deliver resources and coaching, communicate with members, prevent unauthorized access, and improve the program.
4. Connected AI Assistants and the Rankability API (MCP)
Rankability offers a public REST API and a Model Context Protocol (MCP) server. See the MCP setup guide to connect third-party AI assistants — such as Claude Desktop, Cursor, Windsurf, and VS Code Copilot — to your Rankability account.
How access is granted
You can grant access in one of two ways:
- OAuth 2.0 authorization. When you click "Allow Access" on the Rankability consent screen, we issue a scoped, time-limited access token (1-hour expiry) and a refresh token (30-day expiry) bound to the organization that was active at the time of consent. The connected assistant uses these tokens to call our API on your behalf.
- API key. You may also generate a long-lived
rk_live_API key from Settings → API keys and configure your assistant to use it.
What the assistant can access
The connected assistant can read and act on data inside the organization that authorized it, limited to the scopes you approved (for example: list and view clients, read content projects and rank-tracking results, create new content briefs, trigger ranking scans, score pages). The assistant cannot access organizations you have not explicitly connected, cannot access another customer's data, and cannot exceed the scopes shown on the consent screen.
What we do with the data exchanged
Data accessed by an authorized assistant is governed by the same retention, processing, and security terms as the rest of the Rankability product, described elsewhere in this policy. We do not train models on your data, do not sell it, and do not share it with the assistant's vendor (e.g., Anthropic, Cursor) except insofar as the assistant itself sends responses back to that vendor's infrastructure to render them to you. The terms of that vendor's own privacy policy govern how the vendor handles those interactions.
Logging
Every API call made by a connected assistant is recorded in our internal audit log (organization, scope, endpoint, timestamp, status) for security, abuse detection, and customer support. These logs are retained for the same period as other application logs.
Revoking access
You can revoke a connected assistant's access at any time:
- OAuth-connected assistants — Settings → Connected apps → Revoke. The next API call from that assistant will fail with a 401 Unauthorized.
- API-key-connected assistants — Settings → API keys → Delete. Revocation is immediate.
If you have questions about how an authorized assistant has used your data, contact us at privacy@rankability.com.
YouTube API Services
Rankability uses YouTube API Services. Google's handling of your information is described in the Google Privacy Policy. Use of our YouTube features is also subject to the YouTube Terms of Service.
Data we access and how we use it
When you connect YouTube through Google's authorization screen, Rankability requests read-only access to your YouTube account and YouTube Analytics. This can include channel identifiers and names, channel statistics, video identifiers, titles, publication dates, thumbnails, views, likes and comment counts, and channel analytics such as watch time and subscriber changes. We store authorization tokens and selected-channel details to maintain the connection. You enter your Google credentials with Google, not Rankability.
We use this information to display channel information and reports, identify changes in channel performance, and provide relevant workspace analysis. YouTube information can be included in Serena's workspace context and processed by our contracted AI providers to generate responses. Reports, alerts, and conversations may contain YouTube information and be available to people with access to the relevant workspace. Our service providers process data to operate these features, subject to the purposes and safeguards described in this policy. Connecting YouTube does not authorize Rankability to upload, edit, or delete your YouTube videos.
Revoke Google access or disconnect a workspace
To revoke Rankability's authorization at Google, visit Google Account permissions, select Rankability, and remove access. This can affect other Google services you connected through the same authorization. You can also remove the YouTube connection in Rankability under Workspace settings → Connections → YouTube. Removing a workspace connection and revoking authorization at Google are separate controls.
Request deletion of YouTube data
To request deletion of YouTube data stored by Rankability, including information in saved reports, alerts, or conversations, email privacy@rankability.com or use our privacy request form. Identify your Rankability workspace and connected channel so we can locate the records; do not send passwords or access tokens. Removing data from Rankability does not delete videos or other information held by YouTube. Manage that information directly through YouTube.
YouTube API data is subject to YouTube's specific storage, refresh, and deletion requirements, rather than an unrestricted right to retain it for the general account-retention period below. See the YouTube Developer Policies. Disconnecting alone should not be treated as confirmation that every saved report or conversation has been erased; contact us for a data-deletion request and confirmation.
Serena for Slack
If a workspace administrator installs Serena for Slack and a Rankability organization administrator confirms the pairing, Rankability processes Slack data only to provide, secure, meter, and support that integration.
Slack data we collect
- Workspace, app, bot, installer, channel, thread, and sender identifiers needed to install, pair, route, and audit the integration.
- Messages sent directly to Serena, messages that directly mention Serena in a channel where the app is present, and replies within the resulting Serena thread.
- Images that a user deliberately attaches to a Serena direct message or mention.
- The relevant data from the paired Rankability organization needed to answer the user's request, plus Serena's response.
- An encrypted Slack bot token and authorization metadata. The plaintext token is not stored in application records.
How Serena behaves in Slack
Serena responds to direct messages, direct @mentions, and follow-up replies in its threads. Serena does not monitor ordinary channel conversation, search public or private channel history, or enumerate workspace users. Proactive Slack digests and alerts are disabled by default.
AI processing and retention
Rankability sends the user-requested message, permitted attachments, and relevant Rankability context to our contracted AI service providers to generate Serena's response. Rankability does not use Slack data to train models or sell Slack data. Thread context is bounded in the active product, and Slack conversation and connection records follow the Account Data retention period below, subject to security, legal, backup, and deletion obligations.
Control and deletion
An organization administrator can disconnect Serena from Rankability Settings → Connected apps. Slack workspace administrators can also remove the app in Slack. To request access or deletion, use our Data Subject Rights Portal or email privacy@rankability.com.
5. International Data Transfers
Rankability, Inc. is based in the United States. If you are accessing our services from the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States.
We ensure appropriate safeguards are in place for all international transfers:
- Standard Contractual Clauses (SCCs): EU Commission-approved clauses with US-based processors where applicable
- EU-US Data Privacy Framework: Processors certified under the adequacy decision
- Technical Safeguards: Encryption in transit (TLS 1.2 or later) and at rest (AES-256)
- Access Controls: Role-based access, multi-factor authentication, audit logs
6. Data Retention Periods
We retain your personal data only as long as necessary for the purposes outlined in this policy:
After retention periods expire, we securely delete or anonymize your data. You can request early deletion at any time (subject to legal requirements).
7. Your Data Protection Rights
If you are located in the EEA, UK, or Switzerland, you have the following rights under GDPR/UK GDPR:
Right to Access (Article 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Article 16)
Correct inaccurate or incomplete personal data.
Right to Erasure / "Right to be Forgotten" (Article 17)
Request deletion of your personal data (subject to legal obligations).
Right to Restriction (Article 18)
Request restriction of processing in certain circumstances.
Right to Data Portability (Article 20)
Receive your data in a structured, machine-readable format (CSV/JSON).
Right to Object (Article 21)
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent
Withdraw any consent you have given, and opt out of analytics or marketing cookies at any time via Cookie Settings.
Right to Lodge a Complaint
File a complaint with your local data protection authority if you believe your rights have been violated.
How to Exercise Your Rights: Visit our Data Subject Rights Portal or email privacy@rankability.com. We will respond within 30 days.
8. How We Protect Your Data
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: TLS 1.2 or later for data in transit, AES-256 for data at rest
- Access Controls: Role-based access, multi-factor authentication, least privilege principle
- Regular Audits: Security assessments, penetration testing, vulnerability scanning
- Staff Training: Regular data protection and security awareness training
- Incident Response: Documented breach notification procedures (within 72 hours to authorities)
- Vendor Management: DPAs or provider terms with processors as applicable, regular compliance reviews
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
Our Services are not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@rankability.com.
10. Updates to This Policy
We may update this privacy policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by email (if you have an account) or by posting a prominent notice on our website. The "Last Updated" date at the top indicates when the policy was last revised.
11. Contact Information
For privacy-related questions, data subject rights requests, or complaints:
Privacy Contact
Email: privacy@rankability.com
Company Information
Rankability, Inc., a Delaware corporation
6 Cardinal Way, Suite 900
St. Louis, MO 63102
United States
EU Representative
We are currently a small business and do not have a dedicated EU representative. EU residents can contact us directly at the address above or at privacy@rankability.com.
Supervisory Authority
EU/EEA residents have the right to lodge a complaint with their local data protection authority. UK residents can contact the Information Commissioner's Office (ICO).