Skip to main content

Privacy Policy

Last updated

RankVitals is an independent, self-funded product. This policy describes what the service actually does today — not what a larger company's template would say. We hold no third-party audit certifications (no SOC 2, no ISO 27001); what we do instead is described here and on our security page.

What we collect

Account data — your email address, your name if you provide one, your team memberships, and your plan and subscription state from Stripe (never card numbers).

Testing data— the URLs you test and everything the test produces: scores, Core Web Vitals, network waterfalls, screenshots and filmstrips of the tested page, crawl findings, and SEO issues. A tested page is fetched as a visitor would fetch it. If a page is behind a login, you can optionally supply HTTP basic-auth credentials, cookies, or extra request headers; these are saved with that test's configuration, protected by database row-level security and our provider's encryption at rest, and are sent only to the site you are testing. They are never returned to your browser, never included in a shared or exported report, and never sent to a webhook. Application-level encryption for these fields is built and switches on as soon as we provision its key; until then they are not separately encrypted by us, so we recommend using throwaway or read-only credentials for staging environments rather than a real user's login.

Configuration — monitors, schedules, alert rules and their delivery targets (email addresses, webhook URLs), API keys you create, and repository access tokens when you connect a repository. Repository tokens are encrypted with AES-256-GCM and never logged.

Operational data — request logs and rate-limit counters needed to run and secure the service.

We do not ask for, and have no use for, special-category personal data. Please do not put it into URLs, monitor names, or team names.

Analytics and cookies

We use two analytics tools, and we would rather be precise about them than claim to be cookie-free:

  • Umami, a self-hosted, cookieless analytics instance running on our own server and served from our own domain. It sets no cookies, stores no personal identifiers, and sends nothing to anyone else.
  • Google Analytics 4, which does set its own cookies in your browser and processes data in the United States — so we ask first. On your first visit to a public page you get a one-line banner with Accept and Decline. Until you press Accept, no Google script is loaded at all and no _ga cookie is created; pressing Decline keeps it that way. When you do accept, we grant analytics storage only — never advertising storage or ad personalisation. GA4 is never loaded inside the signed-in dashboard, and never in preview or development builds.

Your answer is remembered in your browser's local storage (not in a cookie) under rankvitals-analytics-consent. Clearing site data resets the question. Our own cookies are strictly functional: your sign-in session and your active-team selection. We run no advertising, retargeting, or social-media pixels, we do not build cross-site profiles, and we never sell or rent your data. A browser tracker blocker or Global Privacy Control signal removes GA4 too; the product works exactly the same without it.

Real-user monitoring (RUM)

If you install our RUM snippet on your own site (a paid-plan feature), your visitors' browsers send us Core Web Vitals measurements. Each beacon contains only: the metric name (LCP, INP, CLS, FCP or TTFB), its numeric value, the page path, and a device class of mobile, desktop, or unknown.

It contains no cookie, no advertising identifier, no cross-site or cross-session identifier, and no visitor IP address — we do not store the IP the beacon arrives from. We cannot single out one of your visitors from this data, and neither can you. Beacons from free-plan sites are acknowledged and discarded rather than stored.

You are the controller for your own visitors' data and are responsible for disclosing this collection in your own privacy notice; we process it on your instruction.

MCP server and API access

RankVitals exposes the same data through a REST API and a remote MCP server so AI assistants and CI pipelines can use it. Some things worth knowing:

  • Access requires an API key you create yourself under Dashboard → API & MCP, and every request is scoped to the team that key belongs to. A key can never reach another team's data.
  • Read tools return your existing tests, scores, vitals history, fix plans, credit balance, and monitors. Write tools start tests, spending a credit, and create or change the monitors and threshold alerts on your account. Two tools delete data — delete_monitor and delete_alert — and both are limited to the monitor or alert you name; neither removes historical test results.
  • When you connect an AI assistant, whatever that assistant reads through the tools is handled under itsprovider's privacy policy as well as ours. Connecting an assistant is your decision, and you can revoke a key at any time from the same page, which takes effect immediately.
  • We log API requests for rate limiting, billing, and abuse prevention.

AI fix plans

When you generate a fix plan, the findings of that test — and, if you connected a repository, relevant excerpts of the files implicated by those findings — are sent to the configured model provider (Anthropic or an Ollama-hosted model) to produce the plan. The generated plan is stored on your test; the excerpts are sent transiently and are not stored by us. We do not use your data to train any model of our own.

Why we process data (lawful bases)

Performance of the contract — running the tests, crawls and monitors you ask for, delivering alerts, and billing. Legitimate interest — securing the service, preventing abuse, and understanding aggregate product usage. Consent — connecting a repository, and any non-essential email you opt into. Legal obligation — retaining what tax and accounting law requires for payment records.

Sub-processors

These are the third parties that process data on our behalf. We update this list when it changes.

Sub-processorPurposeProcessing location
SupabaseDatabase, authentication, and file storage — the primary store for your account and test dataEU
VercelHosting and CDN for the web applicationUS / global edge
IONOSServers running our test workers and our self-hosted analytics instanceEU (Germany)
StripePayment processing and subscription management — card details never reach our serversUS / EU
Amazon Web Services (SES)Transactional email: alerts, monitor notifications, team invitesConfigured AWS region / global email transit
Cloudflare TurnstileBot protection on sign-in, password reset, and the free instant-test formUS / global edge
GitHubRepository access when you choose to connect a repository (optional)US
Google Analytics 4Aggregate traffic measurement on public pages, and only after you accept it (see “Analytics and cookies”)US
AnthropicGenerating AI fix plans from your test findings, when Anthropic is the configured model providerUS
Ollama CloudGenerating AI fix plans, when an Ollama-hosted model is the configured providerUS

Anthropic and Ollama Cloud receive data only when an AI fix plan is generated; GitHub only when you connect a repository. Our analytics instance (Umami) runs on our own IONOS server and is not a third-party service.

How long we keep things

Deletion is automatic — a scheduled job enforces these windows; nothing is kept “just in case”.

DataRetention
Test artifacts — screenshots, filmstrips, network waterfalls, raw Lighthouse reportsFree 30 days · Starter 90 days · Growth 180 days · Agency 365 days
Test result rows — scores, grades, metrics, SEO findingsTwice the artifact window: 60 / 180 / 360 / 730 days by plan
Uptime check results30 days on every plan
Alert history90 days
Real-user monitoring (RUM) beacons90 days (dashboards show the most recent 28)
Abandoned anonymous trial accountsDeleted after 30 days, together with their tests
Account data, monitors, and settingsKept while your account exists; removed when you delete it

When artifacts expire, the underlying files are deleted from storage, not merely hidden. Payment records held by Stripe follow Stripe's own legally mandated retention.

Your rights

You can exercise the main ones yourself, immediately, without asking us: use Settings to download a full JSON export of your data, or to permanently delete your account — which removes your profile, teams you solely own, tests, artifacts, and monitors.

If you are in the EU, UK, or another region with comparable law, you also have the rights to rectification, restriction, objection, portability, and to lodge a complaint with your supervisory authority. To exercise anything the dashboard does not cover, email privacy@rankvitals.io. We aim to respond within 30 days.

International transfers

Our primary data location is the EU: the Supabase project and the IONOS servers running our workers are EU-hosted. Some sub-processors listed above (Vercel, Stripe, AWS, Cloudflare, GitHub, Google, Anthropic, Ollama) process data in the United States or at global edge locations, under the standard contractual clauses and equivalent safeguards in their own data-processing terms.

Children

RankVitals is a tool for people who build and run websites. It is not directed at children, and we do not knowingly collect data from anyone under 16.

Changes to this policy

When this policy changes materially we update the date at the top and note it in our changelog. Continued use after a change means the updated policy applies.

Contact

Privacy questions, data requests, and anything else covered here: privacy@rankvitals.io. For security vulnerability reports, see responsible disclosure.