Privacy policy
What we collect, why we need it, who else touches it, and how to get it back or deleted.
01What this covers
This policy explains what ScaleRank Ltd does with personal data when you use ScaleRank, including the free site analysis you can run without an account. It is written to be read, not to be survived.
Two different sets of data are involved and it is worth separating them early. There is data about you, the customer, such as your email address and billing details. And there is data about the website you connect, which is mostly public page content and search performance statistics. Where the difference matters below, we say so.
02What we collect
Only what the product needs to work. Specifically:
- Account details: your name, email address, hashed password or the identifier from your single sign-on provider, and the organisation you belong to.
- Billing details: your plan, billing country and invoice history. Card numbers go straight to our payment processor and never reach our servers.
- Sites you connect: the URL, the pages we crawl, the platform we detect, and the business information we extract from your own pages such as products, services and locations.
- Search performance data: impressions, clicks, average position and query data from Google Search Console, once you authorise it.
- Content we produce for you: plans, drafts, edits, approvals and rejections, including who approved what and when.
- Product usage: pages visited inside the app, features used, and error reports. We keep this for debugging and for deciding what to build, not for advertising.
We do not buy data about you from anyone, and we do not run advertising or behavioural tracking on this site.
03Accounts you connect
Search Console is connected through Google OAuth with read-only scope. We can read performance and index status for the properties you select. We cannot change your settings, submit removals, or see any other Google service. You can revoke that access from your Google account at any time and the connection stops working immediately.
CMS connections are different, because publishing requires write access. We request the narrowest permission the platform offers, which usually means creating and updating posts and nothing else. We store the access token encrypted, use it only when you approve an article, and delete it when you disconnect the site.
04What our crawler reads
When you analyse a site, ScaleRankBot fetches pages the same way a search engine would, and stores the HTML, the response headers and a set of derived scores. It obeys robots.txt and it does not attempt to reach anything behind a login.
If a page you have published happens to contain personal data, that data is already public and we hold a copy of it as part of the crawl. Tell us and we will purge it from our store. The full behaviour of the crawler is documented in our bot and crawler policy.
05What we use it for
- Running the service you asked for: analysing the site, planning topics, drafting content, publishing it and measuring what happened.
- Keeping your account secure and investigating abuse, including rate limiting and fraud checks.
- Billing you and meeting our tax and accounting obligations.
- Sending service messages such as a failed publish, a finished audit or a change to these terms. These are not marketing and you cannot unsubscribe from them while you have an account.
- Improving the product in aggregate. That means looking at patterns across many sites, never at one customer's content to benefit another.
We do not use your content to train models, and we do not licence it or sell it to anyone. Full stop.
06Model providers
Drafting content means sending your page content, business details and topic briefs to third-party model providers. We use them under enterprise API terms that prohibit training on submitted data and set a short retention window for abuse monitoring only.
If your industry or your own contracts make that unacceptable, say so before you connect a site. We would rather have that conversation early than have you discover it in a policy page.
08How long we keep things
- Free audit reports: 90 days from the day they were generated, then deleted.
- Account and site data: for as long as the account is open, then 30 days after you close it so that an accidental deletion can be undone.
- Content we wrote for you: yours to export at any time, and deleted with the account on the same 30 day schedule.
- Invoices and tax records: seven years, because we are required to keep them.
- Backups: rolling 35 days, after which deleted data is gone from those too.
09Your rights
Depending on where you live you may have the right to access your data, correct it, export it in a portable format, delete it, restrict how we use it, or object to a particular use. We apply these rights to everyone regardless of location, because operating two standards is more work than doing it properly once.
Email privacy@scalerank.io from the address on your account. We aim to respond within a few days and are required to respond within 30. If you are unhappy with how we handled it, you can complain to your local data protection authority.
11How we protect it
Encryption in transit and at rest, credentials for connected platforms encrypted with separate keys, access to production limited to the engineers who need it and logged when used, and automatic dependency patching. Passwords are hashed and cannot be read by us or recovered for you.
If a breach affects your data we will tell you within 72 hours of becoming aware of it, along with what happened and what we did. Report a vulnerability to security@scalerank.io.
12Age
This is a business tool and it is not intended for anyone under 16. We do not knowingly collect data from children, and if we learn we have, we delete it.
13Changes to this policy
When something material changes we will email account holders at least 14 days before it takes effect, and the date at the top of this page will move. Minor corrections such as fixing a typo or clarifying wording happen without notice.
14Contact
ScaleRank Ltd, registered in England and Wales. For anything in this policy, write to privacy@scalerank.io. For everything else, the contact page lists the right inbox.