Privacy Policy

How Oberrank collects, uses, shares, and protects personal data, and the choices you have.


Last updated: September 30, 2026

This policy explains how [COMPANY NAME] ("Oberrank", "we", "us") handles personal data when you visit oberrank.com, use the hosted Oberrank app at app.oberrank.com, its MCP server, or its API (together, the "Service"), or contact us. Read it together with our Terms of Service.

Summary

TopicWhat we do
What we collectAccount details, the workspace content you add, usage and device data, and data from the accounts you connect, such as Google Search Console.
PaymentsStripe processes payments. We never see or store your full card number. You can start a free trial without giving us any payment details.
Google dataOberrank's software only reads it, uses it only to provide and troubleshoot the features you request, does not use it for advertising, and does not use it to train AI models.
Selling dataWe do not sell personal data, and we do not share it for cross-context behavioral advertising.
Your choicesTurn off product analytics in Settings, unsubscribe from marketing email, disconnect integrations, and ask us for access, correction, export, or deletion at any time.

1. Who we are and what this policy covers

[COMPANY NAME], [COMPANY ADDRESS], operates the Service. You can reach us at anonymous@oberrank.com.

We act in two roles:

  • Controller. We decide how and why your account, billing, website, and usage data are processed, as described in this policy.
  • Processor (service provider). We process the content you and your team put into a workspace, such as projects, keywords, drafts, reports, and data from connected accounts, on your instructions and only to provide the Service. If you are a business customer and need a data processing agreement, email us and we will provide one.

If you are in the EEA, UK, or Switzerland and we are required to have a local representative, it is [EU/UK REPRESENTATIVE NAME AND ADDRESS, OR DELETE THIS SENTENCE].

What this policy does not cover. This policy covers the hosted Service and the oberrank.com website. Third-party websites and services we link to, including your own website and the AI clients you connect, have their own policies.

2. Information we collect

Information you give us

  • Account details. Your name, email address, and password (stored hashed). If you sign in with Google, we receive your Google name, email address, and profile picture instead of a password.
  • Workspace and team details. Your workspace name, the email addresses of people you invite or email a share link to, roles and project access, and the API keys you create.
  • Onboarding answers. Optional answers about which features interest you, who you work for, how many client sites you manage, how you found us, and whether you plan to connect an AI agent.
  • Workspace content. Projects and domains, keywords and tags, rank-tracking setups and results, site audit results, backlink snapshots, content briefs, documents and comments, reports, project notes, and your conversations with the in-app assistant.
  • Billing details. Your name, business name, billing address, tax ID, and payment method, entered on Stripe's checkout page.
  • Communications. Messages you send to support, feedback you share, and your email address if you join our newsletter.

Information collected automatically

  • Sign-in and security data. Session tokens, IP address, browser and device type (user agent), and sign-in times. Cloudflare Turnstile checks that sign-ups and free-tool requests come from a person and not a bot.
  • Usage data. Pages and features you use, actions such as starting a checkout or running an audit, errors, and performance data. In the app at app.oberrank.com, including the sign-in and sign-up pages, this is collected with PostHog. We may derive approximate location from your IP address.
  • Session replay. In the app at app.oberrank.com, including the sign-in and sign-up pages, PostHog may record your session, including clicks, scrolling, and what is displayed on screen, so we can find and fix bugs. Form fields and some designated sensitive text, such as email addresses in menus and team lists, are masked before recording. Other on-screen content, such as SEO data or assistant conversations, is not masked.
  • Website analytics. The public website uses Plausible Analytics, configured without cookies and proxied through our domain.
  • Referral data. If you arrive through a partner referral link, Dub sets a cookie holding a click identifier so we can credit the partner when you sign up or buy.
  • Free tools. If you use a free tool on our website, we process the domains, keywords, or URLs you submit and a daily hashed identifier derived from your IP address to enforce usage limits.

Information from other sources

  • Google. Data from the Google accounts you choose to connect. See "Google user data" below.
  • Stripe. Payment status, subscription status, and invoice details for your purchases.
  • SEO data providers. When you look up keywords, domains, or URLs, providers such as DataForSEO return SEO metrics about them. This is data about websites, not about you.
  • Websites you audit. When you run a site audit, we fetch pages from the site you specify and store the results (for example page titles, links, headers, and performance findings). If those pages contain personal data, it becomes part of your workspace content.
PurposeExamplesLegal basis (EEA and UK)
Provide the ServiceCreate and secure accounts, run research, audits, and rank tracking, connect integrations, give supportContract
Payments and billingProcess subscriptions and top-ups, manage credits, issue invoices, keep tax recordsContract; legal obligation
Security and abuse preventionBot checks, rate limits, spotting repeated free trials and credit farming, investigating misuseLegitimate interests
Product analytics and improvementUnderstand which features are used, diagnose errors, replay sessions to fix bugsLegitimate interests
CommunicationsVerification, password reset, invitation, security, and billing emails; product updates and newsletterContract for service emails; consent or legitimate interests for marketing
Referral attributionCredit partners for sign-ups and purchases they referLegitimate interests
Legal compliance and rightsRespond to lawful requests, enforce our Terms, handle disputesLegal obligation; legitimate interests

We do not use automated decision-making that has legal or similarly significant effects on you.

4. Google user data

You can sign in with Google and connect Google Search Console, Google Analytics, and Google Ads to a project. Each connection is optional, and each asks for its own permission on Google's consent screen. This section describes how we handle that data in addition to the rest of this policy.

What we access

ConnectionGoogle permissionData we read
Sign in with GoogleBasic profile (openid, email, profile)Name, email address, profile picture
Google Search ConsoleRead-only Search Console accessSearch performance for sites you authorize (queries, pages, clicks, impressions, average position) and URL inspection results
Google AnalyticsRead-only Analytics accessReport data for the property you select (traffic, acquisition, landing pages, key events, ecommerce outcomes, site search terms, device and country breakdowns) and property settings such as data streams
Google AdsGoogle Ads accessThe ad accounts your Google login can reach (ID, name, currency, time zone, manager hierarchy), campaign settings (name, status, channel, bidding strategy, budget), campaign and account performance (impressions, clicks, cost, conversions, conversion value), and keyword ideas from Keyword Planner

For each connection we also keep the email address of the connected Google account so we can show you which account is linked.

About the Google Ads permission. Google offers a single permission for its Ads API, and that permission technically allows editing and deleting Google Ads data. Oberrank's software does not use it that way: it can only read the data listed above and cannot create, edit, pause, or delete campaigns, ads, budgets, or bids. The Search Console and Analytics permissions are read-only.

How we use it

We use Google user data only to provide the features you ask for: showing connection status, generating SEO reports and insights, syncing search performance for your content, and returning data you request through the app, the in-app assistant, or an AI client you connect. We also use session replay to find and fix bugs in these features, and it can record Google data that is displayed on screen (see "Session replay" above). We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized AI or machine learning models.

What we store

  • Stored while connected: the OAuth tokens (encrypted at rest) and the connection details (selected site, property, or ad account, and the connected account email). Disconnecting removes them.
  • Stored until you delete the content or project: for Search Console, weekly aggregate snapshots (clicks, impressions, click-through rate, and average position) for the content items in your project that match a published URL, so you can see trends. These snapshots stay after you disconnect Search Console, until the content item or project is deleted. Email us if you want them deleted sooner.
  • Not stored: Analytics report data, Google Ads campaign and performance data, Keyword Planner results, and other Search Console query data are retrieved when you ask for them and are not saved in our databases, except where you, the in-app assistant, or an AI client you connect saves them into your workspace, for example in a saved report or note. We treat that saved content as your workspace content.
  • Conversations: if you ask the in-app assistant about your Google data, the results appear in the conversation, and the conversation is stored as described in "AI features and connected AI clients".

How we share it

We do not sell Google user data, and we do not transfer it to data brokers or advertisers. Google user data leaves our systems only when:

  • you ask the in-app assistant to work with it, in which case the relevant data is sent to the AI model provider that generates the response (see below);
  • you connect an AI client through MCP or an API key and request the data through it, in which case the results go to that client and its own terms apply;
  • our infrastructure providers, such as Cloudflare, host the systems that process it on our behalf;
  • the app is being recorded by session replay, which can capture data displayed on screen (see "Session replay" above and the opt-out in "Your choices and rights"); or
  • we are required to disclose it to comply with the law, for security purposes such as investigating abuse, or as part of a merger or sale of our assets with your consent where the Google policy requires it.

Who can read it

Our people do not read your Google user data, except where you give us your affirmative agreement, where it is necessary for security purposes (for example, investigating abuse or a bug), where the law requires it, or when the data is aggregated and used for internal operations.

How we protect it

OAuth tokens are encrypted at rest, and data moves over encrypted connections (TLS). Access to a project's data is limited by roles you control.

Disconnecting and deleting

You can disconnect an integration in your project settings. Removing a connected Google account in Settings deletes its stored tokens and any connections that depended on them. To also remove Oberrank's access on Google's side, visit myaccount.google.com/permissions. If your Oberrank account is deleted, we revoke Google access and delete the stored tokens.

Limited Use

Oberrank's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If we change how we use Google user data, we will update this section and ask for your consent before the new use begins.

5. AI features and connected AI clients

In-app assistant. When you chat with the assistant, we send your messages and the workspace data it retrieves to answer them (for example keyword data or connected Google data) to OpenRouter, which routes the request to an AI model provider. Our default model is from OpenAI, and we may change models or providers. These providers process the data under their own terms. We do not use your workspace content or Google user data to train AI models.

What we store. We store your conversations with the assistant, including tool results, as part of your workspace so you can return to them. Archiving a conversation hides it from your list but does not delete it. You can ask us to delete conversations, or delete your whole account, at any time.

What PostHog receives. For assistant usage, our analytics records the model, token counts, cost, and the names of tools called. It does not receive the text of your messages or the assistant's replies, although session replay can record what is shown on your screen.

MCP and API keys. You can connect AI clients, such as Claude, ChatGPT, or Cursor, to your workspace through our MCP server or an API key. When you do, the data you request is sent to that client, and its provider's privacy terms apply to what happens next. You are responsible for the clients you connect. To disconnect a client, delete its API key in Settings, or email us to revoke an MCP connection.

6. Cookies and similar technologies

Name or typePurposeDurationCategory
better-auth.session_token (may carry a __Secure- prefix)Keeps you signed inUp to 7 days, extended while you use the appEssential
better-auth.session_dataSpeeds up session checks5 minutesEssential
OAuth state cookieProtects the Google sign-in and connection flow10 minutesEssential
Cloudflare Turnstile widgetBot checks on sign-up and free tools; runs in your browser and analyzes limited browser signalsEach checkEssential (security)
Browser local storageRemembers interface preferences such as filters, sidebar state, and preferred locationUntil you clear itFunctional
dub_id cookie on .oberrank.comPartner referral attribution; set only when you arrive through a referral link90 daysReferral tracking
PostHog cookie and local storage (ph_..._posthog)Product analytics: a random identifier and session state; used in the app at app.oberrank.com, not on the public websiteUp to 1 yearAnalytics

The public website's Plausible analytics does not use cookies.

You can control cookies and local storage in your browser settings. Blocking essential cookies will stop sign-in from working. In the app, PostHog respects your browser's "Do Not Track" setting, and once you are signed in you can switch product analytics and session replay off under Settings.

7. Who we share information with

We do not sell your personal data. We share it with the service providers below, who process it on our behalf under their own terms, and in the other situations listed after the table.

ProviderWhat it does for usData involved
CloudflareHosting, network and storage, background jobs, security, and Turnstile bot checksService data in transit and at rest; IP address and request metadata
[DATABASE PROVIDER AND REGION]Managed PostgreSQL databaseAccount, workspace, and billing-status data
StripePayments, subscriptions, invoices, and tax ID collectionName, email, business name, billing address, tax ID, payment method, transaction data
AutumnSubscription and usage-credit management on top of StripeWorkspace ID, plan, credit balances, usage events, billing status
Loops (or Resend)Verification, password-reset, invitation, and share emails; product updates and newsletterName, email address, plan status
PostHogProduct analytics, error tracking, session replay, and AI usage metricsPseudonymous user and workspace IDs, usage events, device data, IP-derived location, session recordings
PlausibleCookieless website analyticsIP address and browser data, processed to count visits
DubPartner referral tracking and commissionsClick identifier, pseudonymous user ID, and paid amounts; no name or email
DataForSEOSEO data such as keyword, SERP, backlink, and ranking dataKeywords, domains, URLs, and locations you look up
OpenRouter and its model providers (OpenAI by default)Generate in-app assistant responsesYour messages and the workspace data the assistant retrieves
GoogleSign-in and the Google services you connectAs described in "Google user data"

Stripe processes payment data on our behalf and, for fraud prevention, legal compliance, and other purposes described in its privacy policy, as an independent controller.

We also share information:

  • Within your workspace. Teammates you invite can see workspace content according to the roles and project access you assign, and members of a workspace can see each other's names and email addresses.
  • Through share links. When you create a share link for content or a report, anyone who has the link can view it until it expires or you revoke it.
  • For legal and safety reasons. When we believe disclosure is required by law or legal process, or necessary to enforce our Terms, prevent fraud or abuse, or protect people or property.
  • In a business transfer. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred. We will tell you before it becomes subject to a different privacy policy.
  • With your consent. When you ask us to share information or approve a specific disclosure.
  • De-identified. We may use aggregated or de-identified data that cannot reasonably identify you, for example to report usage trends.

8. International transfers

We operate from [COUNTRY], and our providers process data in the United States and other countries, which may have different data protection laws from your own. When we transfer personal data from the EEA, UK, or Switzerland, we rely on safeguards such as the European Commission's Standard Contractual Clauses (and the UK addendum), or the EU-US Data Privacy Framework where a provider participates. Contact us for a copy of the safeguards that apply.

9. How long we keep information

We keep personal data only as long as we need it for the purposes above.

DataHow long
Account details and workspace contentUntil you delete them or your account is deleted
Sign-in sessionsUp to 7 days, extended while you use the app; removed when you sign out or they expire
Google connections and tokensUntil you disconnect or remove the Google account, or your account is deleted
Search Console performance snapshotsUntil the content item or project is deleted, even if you disconnect Search Console
Assistant conversationsUntil your account is deleted or you ask us to delete them
InvitationsExpire after 7 days
Free-tool usage identifiersDeleted after 3 days
Free-tool result cache24 hours
Cached data-provider responsesShort-lived; expires automatically
Referral attribution recordsUp to 90 days for a sign-up and up to 400 days for the workspace record used to attribute purchases
Billing and tax recordsAs long as tax, accounting, and fraud-prevention rules require
Support conversationsAs long as needed to help you and for a reasonable period afterward
Marketing contact recordUntil you unsubscribe or ask us to delete it
Analytics events and session recordingsA limited period set in our analytics settings, then deleted or aggregated
Backups and logsOn our providers' rolling schedules, then overwritten

Account deletion. There is no self-serve delete button yet. Email us from the address on your account and we will delete it, typically within 30 days. We delete your workspace data, remove you from our email and analytics tools, revoke Google access, and ask Stripe to delete the customer record. Some information may remain for a limited time or by law: backups until they age out, billing and tax records we must keep, and analytics deletions that our provider processes asynchronously. If your workspace has other members, we will ask you to transfer or remove them first, because deleting the workspace would erase their data. Work you did in someone else's workspace stays with that workspace, with your name removed where we can, and we revoke any public share links to reports you created.

10. Your choices and rights

Choices you can make now

  • Product analytics and session replay. Turn them off under Settings once you are signed in. Before you sign in, PostHog respects your browser's "Do Not Track" setting.
  • Marketing email. Use the unsubscribe link in any marketing email, or email us. We will still send service emails such as verification, security, and billing notices.
  • Integrations. Disconnect Google Search Console, Google Analytics, or Google Ads at any time, as described above.
  • Cookies. Use your browser settings.

Rights you may have. Depending on where you live, you may have the right to access your personal data, correct it, delete it, export it, restrict or object to certain processing, withdraw consent you gave, and not be treated differently for using these rights. To make a request, email anonymous@oberrank.com from the address on your account. We may ask you to confirm your identity and will respond within 30 days, or within the period your local law sets. If we decline a request, we will explain why and, where the law provides, how to appeal.

If you are in the EEA, UK, or Switzerland, you can also complain to your local data protection authority. We would appreciate the chance to fix the problem first.

If you use Oberrank through your employer or a client's workspace. Send your request to the workspace owner. We will help them respond.

11. Additional information for California and other US states

This section supplements the rest of this policy for residents of California, Colorado, Connecticut, Virginia, and other states with similar laws.

  • Categories collected in the last 12 months: identifiers (name, email, IP address, account ID); customer records (billing details entered at checkout); commercial information (plan, purchases, credit usage); internet and network activity (usage data and session replay); approximate location; professional information (onboarding answers); and sensitive personal information limited to account log-in credentials, which we use only to authenticate you.
  • Sources: you, your devices, the accounts you connect, and our service providers.
  • Purposes: the purposes in section 3.
  • Disclosed for a business purpose to: the service providers in section 7.
  • Sale and sharing. We do not sell personal information or share it for cross-context behavioral advertising, and we do not knowingly sell or share the personal information of anyone under 18.
  • Your rights: to know, access, delete, and correct your personal information, and to be free from discrimination for exercising them. Email us to make a request. An authorized agent may submit a request for you with your written permission. If we deny a request, you may appeal by replying to our decision, and you may contact your state attorney general if you are not satisfied.

12. Security

We use safeguards intended to protect your information, including encryption in transit (TLS), encryption of stored OAuth tokens, hashed passwords, role-based access controls for workspaces and projects, and bot and abuse protection. No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, or altered without authorization. Please use a strong, unique password and keep API keys secret. If you find a security problem, email us. Where the law requires, we will notify affected people and regulators of a breach.

13. Children

The Service is for people 18 and older and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new date. For material changes, we will notify you by email or in the app at least 30 days before they take effect, and where the law requires your consent, we will ask for it. Minor corrections and clarifications take effect when posted.

15. Contact

Questions, requests, or complaints about privacy: anonymous@oberrank.com

[COMPANY NAME], [COMPANY ADDRESS]