Skip to content
RankTwig

Privacy Policy

Your search data should stay under your control.

This Privacy Policy explains how RankTwig accesses, uses, stores, transmits, shares, and deletes information when you use ranktwig.com and the authenticated RankTwig product.

Last updated: August 27, 2026

1. Who we are

RankTwig is an independent SEO software product that helps users understand authorized Google Search Console performance data, Search Score signals, bounded crawl observations, AI Visibility research, page and competitor evidence, and optional AI-assisted workflows. RankTwig is not affiliated with or endorsed by Google, OpenAI, Google Gemini, or other third-party providers referenced in the product.

Google and Google Search Console are trademarks of Google LLC. Other product names and trademarks belong to their respective owners.

2. Information we collect

Account information

When you continue with Google, RankTwig uses the standard openid, email, and profile sign-in scopes. Google may provide your Google account identifier, name, email address, and profile picture if available. RankTwig uses this information to create and authenticate your account and display the identity associated with your workspace.

Google Search Console information

For properties you explicitly connect, RankTwig may store the property identifier and permission information plus Search Analytics data such as dates, pages, search queries, clicks, impressions, average position, and derived metrics or comparisons used by RankTwig's user-facing features.

Authorization credentials

RankTwig stores the Google authorization material required to continue syncing your connected Search Console properties. Sensitive refresh credentials are stored server-side and encrypted at rest. They are not shown back to you in plaintext.

AI Visibility research data

RankTwig may create and store a bounded AI Visibility baseline for a connected site. This can include the site's display name and domain, public homepage or crawl-derived context, a limited set of Search Console query signals used to derive buyer prompts, the generated prompts, provider task identifiers, ChatGPT and Gemini result metadata, answer excerpts, mention and citation flags, cited sources, surfaced competitor names, scores, confidence, timestamps, and provider/model/cost diagnostics.

Optional BYOK AI credentials and actions

If you connect your own supported AI provider, RankTwig stores the credential in encrypted form and records the provider/model selections and user-triggered analysis operations needed to provide that feature.

Crawl and service data

When you request SEO Health or another supported crawl workflow, RankTwig may store observations from publicly reachable pages, such as HTTP status, title, meta description, canonical, headings, schema facts, word count, links, crawl timing, and crawl limitations. We also process ordinary security, session, queue, and operational logs needed to run and protect the service.

Purchase and billing metadata

Purchases may be processed by Paddle or another checkout provider presented at purchase. RankTwig may receive and store transaction, customer, subscription, plan, payment-status, support, and entitlement metadata needed to verify a purchase and activate or maintain your plan. RankTwig does not receive or store your full payment-card number through this integration.

Public website analytics

RankTwig uses Google Analytics on public-facing marketing, sign-in, and demo pages to understand visits, traffic sources, device/browser information, and aggregate interaction patterns. RankTwig also uses Microsoft Clarity on public marketing and demo pages to understand interaction patterns such as clicks, scrolling, navigation flows, and session replays. Microsoft Clarity is not loaded inside the authenticated RankTwig dashboard or sign-in flow. Google Analytics is intentionally excluded from the authenticated dashboard, so connected Search Console data, workspace activity, investigation URLs, and other authenticated product routes are not sent through these website analytics integrations. Advertising personalization and Google signals are disabled in RankTwig's Google Analytics configuration.

Support and communications

If you contact RankTwig, we process the information you provide in the message and any account, site, billing, or diagnostic details reasonably necessary to respond to your request.

GOOGLE API DATA

3. The Google permissions RankTwig requests

For sign-in, RankTwig requests the standard openid, email, and profile scopes so RankTwig can authenticate you and receive the basic account information described above.

Separately, RankTwig requests https://www.googleapis.com/auth/webmasters.readonly. This Search Console permission is read-only. It lets RankTwig list Search Console properties the signed-in user can access and read Search Analytics data for properties the user chooses to connect. RankTwig does not request the Search Console read/write scope and cannot use this permission to modify your Search Console property.

RankTwig uses Google user data only to provide or improve prominent user-facing RankTwig features such as account authentication, site/page/query performance views, Search Score, opportunity detection, investigations, freshness and coverage information, and AI Visibility prompt selection. For AI Visibility prompt selection, RankTwig may send a bounded site profile and a small subset of relevant Search Console query text to a RankTwig-managed AI API solely to generate the prompt baseline described below. RankTwig does not send your complete Search Console history to that model.

RankTwig does not sell Google user data, use it for advertising, build advertising profiles from it, or use it to train a generalized RankTwig AI or machine-learning model.

RankTwig's use and transfer of information received from Google APIs is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.

You can review the Google API Services User Data Policy directly on Google's website.

4. How we use information

  • create and authenticate your account, display your account identity, and keep your workspace isolated from other users;
  • list Search Console properties you are authorized to access and connect only the properties you choose;
  • import and refresh search performance data used in dashboards, Search Score, opportunities, investigations, comparisons, and related workflows;
  • calculate deterministic signals such as declines, striking-distance opportunities, CTR gaps, and other explainable product findings;
  • derive and run bounded AI Visibility baselines and show prompt-level mentions, citations, sources, competitors, and score history;
  • run bounded page crawls that you request and attach those observations to the relevant page;
  • run optional BYOK AI analysis when you deliberately start a supported AI-powered action;
  • verify purchases, activate plans, enforce entitlements, prevent abuse, and answer billing questions;
  • measure aggregate traffic, acquisition performance, and public website interaction patterns;
  • operate, secure, debug, and improve the reliability of the service; and
  • respond to support, privacy, deletion, security, and legal requests.

5. Managed AI Visibility research

Initial baseline: AI Visibility is a RankTwig-managed product feature, separate from BYOK. After you add or begin using a connected site, RankTwig may automatically prepare the site's initial AI Visibility baseline so the result is available in the workspace. Later refreshes may depend on product or plan allowances.

Prompt generation: RankTwig may use a RankTwig-managed OpenAI API model to generate a small set of natural buyer prompts. The bounded input can include the target brand and domain, public homepage or crawl-derived context, and a limited subset of relevant Search Console query text. If the managed model is unavailable or the result is unsuitable, RankTwig can fall back to deterministic site/Search Console-derived prompts.

ChatGPT and Gemini checks: RankTwig submits the generated prompt set to an AI visibility research provider, currently DataForSEO, to obtain structured ChatGPT and Gemini results. The submitted research tasks contain the prompts and technical settings needed for the check; they do not contain your complete Search Console dataset. One baseline may include an explicit branded prompt.

Saved evidence: RankTwig stores the resulting score and the evidence needed to explain it, including bounded answer excerpts, source URLs/domains, mention/citation status, competitor entities, provider task identifiers, prompt-generation metadata, and timestamps. RankTwig keeps a bounded recent history rather than treating every scan as permanent history.

OpenAI, DataForSEO, and any replacement research provider process requests under their own service terms and privacy commitments. Provider-side request or task retention can differ from RankTwig's own retention. RankTwig does not control independent provider retention after data has been transmitted to a provider for the requested feature.

6. BYOK AI and connected AI clients

Built-in BYOK AI: When you explicitly run a supported BYOK AI analysis, RankTwig prepares a scoped evidence pack and sends the information needed for that requested analysis to the provider and model you selected, using the provider credential you supplied. The third-party AI provider processes that request under its own terms and privacy commitments. RankTwig does not silently send all of your Search Console data to a BYOK provider.

MCP and external assistants: Eligible RankTwig workspaces can create revocable MCP keys for compatible AI clients. An authenticated MCP client can request scoped RankTwig evidence only through the key and permissions you configure. A compatible assistant such as ChatGPT, Claude, Cursor, or another MCP client may then receive the specific RankTwig tool response you requested. That third-party client or model provider handles the received response under its own terms. You control the MCP key and can revoke it.

7. When information is shared and which providers may process it

RankTwig does not sell personal information or Google user data. We disclose information only where needed to operate the product, provide a feature you use, process a purchase, protect the service, or comply with law. Categories can include:

  • hosting, infrastructure, database, storage, queue, security, and monitoring providers that process RankTwig data on our behalf;
  • OpenAI API or another managed model provider used for the bounded AI Visibility prompt-generation step described above;
  • DataForSEO or another AI visibility research provider used to execute the ChatGPT/Gemini prompt checks described above;
  • the AI provider you choose when you run a BYOK AI action;
  • a compatible MCP/AI client you authorize when you make an MCP request;
  • Paddle or another checkout/billing provider used to process purchases, taxes, fraud controls, refunds, and transaction verification;
  • Google Analytics and Microsoft Clarity for measurement of RankTwig's public-facing website and demo, not for connected Search Console data or authenticated dashboard activity;
  • security, fraud, or abuse response where access is reasonably necessary to protect RankTwig, providers, or users; and
  • disclosure required by applicable law, regulation, court order, or valid legal process.

RankTwig personnel do not routinely read connected Google user data. Human access is limited to situations such as a support request where you affirmatively ask us to inspect relevant data, a security or abuse investigation, operational troubleshooting where access is necessary, or a legal requirement.

9. Retention and deletion

RankTwig retains workspace information only while reasonably needed to provide the service, preserve account and billing integrity, maintain security and abuse records, comply with applicable obligations, resolve disputes, or until it is removed through available controls or a verified deletion request. Different data types can have different retention periods.

Remove a site

Owners and admins can remove an individual connected property from RankTwig through Connections. This removes that site's active imported metrics, crawl evidence, investigations, AI Visibility snapshots and generated site results, and related site-owned product data while leaving other connected properties intact. Limited audit or deletion-accounting metadata may remain where reasonably necessary.

Delete account-level data

If you want account-level deletion beyond the available in-product controls, email team@ranktwig.com from the address associated with your RankTwig account so we can verify and process the request.

Deleting RankTwig data does not necessarily delete copies already transmitted to an independent third-party provider. Those providers apply their own retention and deletion terms. We will make reasonable efforts to use providers and configurations appropriate for the feature and to honor applicable deletion obligations within our control.

10. Security

RankTwig uses workspace-scoped authorization, server-side secrets, encrypted sensitive provider credentials, secure session handling, least-privilege Google scopes, bounded background jobs, and other technical and organizational safeguards designed to reduce unauthorized access and accidental cross-workspace exposure. No internet service can promise absolute security.

11. Your rights and choices

Depending on where you live, applicable law may give you rights to request access to, correction of, deletion of, restriction of, or portability of personal information; to object to certain processing; to withdraw consent where processing relies on consent; or to complain to a data-protection authority. These rights can be subject to legal exceptions and verification requirements.

  • choose which Search Console property to add to RankTwig;
  • remove an individual site from RankTwig in Connections;
  • choose whether to connect a BYOK AI provider and whether to run supported BYOK AI actions;
  • revoke any MCP key you create;
  • revoke RankTwig's Google authorization through your Google Account's third-party access controls;
  • use browser or consent controls made available for public-site analytics where applicable; and
  • contact us for account-level access, correction, privacy, objection, portability, or deletion requests where applicable.

Revoking Google authorization stops RankTwig from obtaining new Search Console data, but it does not by itself delete information already stored in RankTwig. Use RankTwig's deletion controls or contact us if you also want stored data removed.

12. Children, policy changes, and material new uses

RankTwig is a professional SEO product and is not directed to children. We do not knowingly seek to collect personal information from children in violation of applicable law.

We may update this policy as RankTwig, our providers, or applicable requirements change. The current version and update date will be posted on this page. If our handling of Google user data or another material privacy practice changes in a way that requires additional notice or consent, we will provide that notice or obtain consent before using previously collected information for the materially different purpose where required.

13. Contact

Questions about this policy, Google API data, AI Visibility processing, security, or deletion can be sent to team@ranktwig.com.