How Oberrank collects, uses, shares, and protects personal data, and the choices you have.
Last updated: September 30, 2026
This policy explains how [COMPANY NAME] ("Oberrank", "we", "us") handles personal data when you visit oberrank.com, use the hosted Oberrank app at app.oberrank.com, its MCP server, or its API (together, the "Service"), or contact us. Read it together with our Terms of Service.
| Topic | What we do |
|---|---|
| What we collect | Account details, the workspace content you add, usage and device data, and data from the accounts you connect, such as Google Search Console. |
| Payments | Stripe processes payments. We never see or store your full card number. You can start a free trial without giving us any payment details. |
| Google data | Oberrank's software only reads it, uses it only to provide and troubleshoot the features you request, does not use it for advertising, and does not use it to train AI models. |
| Selling data | We do not sell personal data, and we do not share it for cross-context behavioral advertising. |
| Your choices | Turn off product analytics in Settings, unsubscribe from marketing email, disconnect integrations, and ask us for access, correction, export, or deletion at any time. |
[COMPANY NAME], [COMPANY ADDRESS], operates the Service. You can reach us at anonymous@oberrank.com.
We act in two roles:
If you are in the EEA, UK, or Switzerland and we are required to have a local representative, it is [EU/UK REPRESENTATIVE NAME AND ADDRESS, OR DELETE THIS SENTENCE].
What this policy does not cover. This policy covers the hosted Service and the oberrank.com website. Third-party websites and services we link to, including your own website and the AI clients you connect, have their own policies.
| Purpose | Examples | Legal basis (EEA and UK) |
|---|---|---|
| Provide the Service | Create and secure accounts, run research, audits, and rank tracking, connect integrations, give support | Contract |
| Payments and billing | Process subscriptions and top-ups, manage credits, issue invoices, keep tax records | Contract; legal obligation |
| Security and abuse prevention | Bot checks, rate limits, spotting repeated free trials and credit farming, investigating misuse | Legitimate interests |
| Product analytics and improvement | Understand which features are used, diagnose errors, replay sessions to fix bugs | Legitimate interests |
| Communications | Verification, password reset, invitation, security, and billing emails; product updates and newsletter | Contract for service emails; consent or legitimate interests for marketing |
| Referral attribution | Credit partners for sign-ups and purchases they refer | Legitimate interests |
| Legal compliance and rights | Respond to lawful requests, enforce our Terms, handle disputes | Legal obligation; legitimate interests |
We do not use automated decision-making that has legal or similarly significant effects on you.
You can sign in with Google and connect Google Search Console, Google Analytics, and Google Ads to a project. Each connection is optional, and each asks for its own permission on Google's consent screen. This section describes how we handle that data in addition to the rest of this policy.
| Connection | Google permission | Data we read |
|---|---|---|
| Sign in with Google | Basic profile (openid, email, profile) | Name, email address, profile picture |
| Google Search Console | Read-only Search Console access | Search performance for sites you authorize (queries, pages, clicks, impressions, average position) and URL inspection results |
| Google Analytics | Read-only Analytics access | Report data for the property you select (traffic, acquisition, landing pages, key events, ecommerce outcomes, site search terms, device and country breakdowns) and property settings such as data streams |
| Google Ads | Google Ads access | The ad accounts your Google login can reach (ID, name, currency, time zone, manager hierarchy), campaign settings (name, status, channel, bidding strategy, budget), campaign and account performance (impressions, clicks, cost, conversions, conversion value), and keyword ideas from Keyword Planner |
For each connection we also keep the email address of the connected Google account so we can show you which account is linked.
About the Google Ads permission. Google offers a single permission for its Ads API, and that permission technically allows editing and deleting Google Ads data. Oberrank's software does not use it that way: it can only read the data listed above and cannot create, edit, pause, or delete campaigns, ads, budgets, or bids. The Search Console and Analytics permissions are read-only.
We use Google user data only to provide the features you ask for: showing connection status, generating SEO reports and insights, syncing search performance for your content, and returning data you request through the app, the in-app assistant, or an AI client you connect. We also use session replay to find and fix bugs in these features, and it can record Google data that is displayed on screen (see "Session replay" above). We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized AI or machine learning models.
We do not sell Google user data, and we do not transfer it to data brokers or advertisers. Google user data leaves our systems only when:
Our people do not read your Google user data, except where you give us your affirmative agreement, where it is necessary for security purposes (for example, investigating abuse or a bug), where the law requires it, or when the data is aggregated and used for internal operations.
OAuth tokens are encrypted at rest, and data moves over encrypted connections (TLS). Access to a project's data is limited by roles you control.
You can disconnect an integration in your project settings. Removing a connected Google account in Settings deletes its stored tokens and any connections that depended on them. To also remove Oberrank's access on Google's side, visit myaccount.google.com/permissions. If your Oberrank account is deleted, we revoke Google access and delete the stored tokens.
Oberrank's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If we change how we use Google user data, we will update this section and ask for your consent before the new use begins.
In-app assistant. When you chat with the assistant, we send your messages and the workspace data it retrieves to answer them (for example keyword data or connected Google data) to OpenRouter, which routes the request to an AI model provider. Our default model is from OpenAI, and we may change models or providers. These providers process the data under their own terms. We do not use your workspace content or Google user data to train AI models.
What we store. We store your conversations with the assistant, including tool results, as part of your workspace so you can return to them. Archiving a conversation hides it from your list but does not delete it. You can ask us to delete conversations, or delete your whole account, at any time.
What PostHog receives. For assistant usage, our analytics records the model, token counts, cost, and the names of tools called. It does not receive the text of your messages or the assistant's replies, although session replay can record what is shown on your screen.
MCP and API keys. You can connect AI clients, such as Claude, ChatGPT, or Cursor, to your workspace through our MCP server or an API key. When you do, the data you request is sent to that client, and its provider's privacy terms apply to what happens next. You are responsible for the clients you connect. To disconnect a client, delete its API key in Settings, or email us to revoke an MCP connection.
| Name or type | Purpose | Duration | Category |
|---|---|---|---|
| better-auth.session_token (may carry a __Secure- prefix) | Keeps you signed in | Up to 7 days, extended while you use the app | Essential |
| better-auth.session_data | Speeds up session checks | 5 minutes | Essential |
| OAuth state cookie | Protects the Google sign-in and connection flow | 10 minutes | Essential |
| Cloudflare Turnstile widget | Bot checks on sign-up and free tools; runs in your browser and analyzes limited browser signals | Each check | Essential (security) |
| Browser local storage | Remembers interface preferences such as filters, sidebar state, and preferred location | Until you clear it | Functional |
| dub_id cookie on .oberrank.com | Partner referral attribution; set only when you arrive through a referral link | 90 days | Referral tracking |
| PostHog cookie and local storage (ph_..._posthog) | Product analytics: a random identifier and session state; used in the app at app.oberrank.com, not on the public website | Up to 1 year | Analytics |
The public website's Plausible analytics does not use cookies.
You can control cookies and local storage in your browser settings. Blocking essential cookies will stop sign-in from working. In the app, PostHog respects your browser's "Do Not Track" setting, and once you are signed in you can switch product analytics and session replay off under Settings.
We do not sell your personal data. We share it with the service providers below, who process it on our behalf under their own terms, and in the other situations listed after the table.
| Provider | What it does for us | Data involved |
|---|---|---|
| Cloudflare | Hosting, network and storage, background jobs, security, and Turnstile bot checks | Service data in transit and at rest; IP address and request metadata |
| [DATABASE PROVIDER AND REGION] | Managed PostgreSQL database | Account, workspace, and billing-status data |
| Stripe | Payments, subscriptions, invoices, and tax ID collection | Name, email, business name, billing address, tax ID, payment method, transaction data |
| Autumn | Subscription and usage-credit management on top of Stripe | Workspace ID, plan, credit balances, usage events, billing status |
| Loops (or Resend) | Verification, password-reset, invitation, and share emails; product updates and newsletter | Name, email address, plan status |
| PostHog | Product analytics, error tracking, session replay, and AI usage metrics | Pseudonymous user and workspace IDs, usage events, device data, IP-derived location, session recordings |
| Plausible | Cookieless website analytics | IP address and browser data, processed to count visits |
| Dub | Partner referral tracking and commissions | Click identifier, pseudonymous user ID, and paid amounts; no name or email |
| DataForSEO | SEO data such as keyword, SERP, backlink, and ranking data | Keywords, domains, URLs, and locations you look up |
| OpenRouter and its model providers (OpenAI by default) | Generate in-app assistant responses | Your messages and the workspace data the assistant retrieves |
| Sign-in and the Google services you connect | As described in "Google user data" |
Stripe processes payment data on our behalf and, for fraud prevention, legal compliance, and other purposes described in its privacy policy, as an independent controller.
We also share information:
We operate from [COUNTRY], and our providers process data in the United States and other countries, which may have different data protection laws from your own. When we transfer personal data from the EEA, UK, or Switzerland, we rely on safeguards such as the European Commission's Standard Contractual Clauses (and the UK addendum), or the EU-US Data Privacy Framework where a provider participates. Contact us for a copy of the safeguards that apply.
We keep personal data only as long as we need it for the purposes above.
| Data | How long |
|---|---|
| Account details and workspace content | Until you delete them or your account is deleted |
| Sign-in sessions | Up to 7 days, extended while you use the app; removed when you sign out or they expire |
| Google connections and tokens | Until you disconnect or remove the Google account, or your account is deleted |
| Search Console performance snapshots | Until the content item or project is deleted, even if you disconnect Search Console |
| Assistant conversations | Until your account is deleted or you ask us to delete them |
| Invitations | Expire after 7 days |
| Free-tool usage identifiers | Deleted after 3 days |
| Free-tool result cache | 24 hours |
| Cached data-provider responses | Short-lived; expires automatically |
| Referral attribution records | Up to 90 days for a sign-up and up to 400 days for the workspace record used to attribute purchases |
| Billing and tax records | As long as tax, accounting, and fraud-prevention rules require |
| Support conversations | As long as needed to help you and for a reasonable period afterward |
| Marketing contact record | Until you unsubscribe or ask us to delete it |
| Analytics events and session recordings | A limited period set in our analytics settings, then deleted or aggregated |
| Backups and logs | On our providers' rolling schedules, then overwritten |
Account deletion. There is no self-serve delete button yet. Email us from the address on your account and we will delete it, typically within 30 days. We delete your workspace data, remove you from our email and analytics tools, revoke Google access, and ask Stripe to delete the customer record. Some information may remain for a limited time or by law: backups until they age out, billing and tax records we must keep, and analytics deletions that our provider processes asynchronously. If your workspace has other members, we will ask you to transfer or remove them first, because deleting the workspace would erase their data. Work you did in someone else's workspace stays with that workspace, with your name removed where we can, and we revoke any public share links to reports you created.
Choices you can make now
Rights you may have. Depending on where you live, you may have the right to access your personal data, correct it, delete it, export it, restrict or object to certain processing, withdraw consent you gave, and not be treated differently for using these rights. To make a request, email anonymous@oberrank.com from the address on your account. We may ask you to confirm your identity and will respond within 30 days, or within the period your local law sets. If we decline a request, we will explain why and, where the law provides, how to appeal.
If you are in the EEA, UK, or Switzerland, you can also complain to your local data protection authority. We would appreciate the chance to fix the problem first.
If you use Oberrank through your employer or a client's workspace. Send your request to the workspace owner. We will help them respond.
This section supplements the rest of this policy for residents of California, Colorado, Connecticut, Virginia, and other states with similar laws.
We use safeguards intended to protect your information, including encryption in transit (TLS), encryption of stored OAuth tokens, hashed passwords, role-based access controls for workspaces and projects, and bot and abuse protection. No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, or altered without authorization. Please use a strong, unique password and keep API keys secret. If you find a security problem, email us. Where the law requires, we will notify affected people and regulators of a breach.
The Service is for people 18 and older and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email us and we will delete it.
We may update this policy from time to time. We will post the new version here with a new date. For material changes, we will notify you by email or in the app at least 30 days before they take effect, and where the law requires your consent, we will ask for it. Minor corrections and clarifications take effect when posted.
Questions, requests, or complaints about privacy: anonymous@oberrank.com
[COMPANY NAME], [COMPANY ADDRESS]