Privacy Policy
Last updated: September 10, 2026
Rank Monster ("we", "our", "us") respects your privacy. This policy explains what information we collect when you use rankmonster.ai, how we use it, and the choices you have.
Information we collect
- Account information — when you sign up we collect your name, email address, and a hashed password (or a Google account identifier if you sign in with Google).
- Website information — the URL you submit for analysis and content we fetch from that URL's publicly accessible pages.
- Usage data — test runs, prompts, results, and recommendations you generate in the app.
- Payment information — processed by Stripe. We never see or store your full card details.
- Google account data — only if you choose to connect Google Search Console or Google Analytics. See Google user data below.
How we use your information
- To provide and improve the Rank Monster service.
- To run AI visibility tests against third-party AI providers (OpenAI, Anthropic, Google) on your behalf.
- To send service emails such as weekly reports (which you can disable in settings).
- To process subscription payments via Stripe.
Third-party services
We share data with the following subprocessors only as necessary to operate the service:
- Neon — database hosting
- Vercel — application hosting
- Stripe — payment processing
- OpenAI, Anthropic, Google — AI provider APIs (your prompts are sent to these providers to run tests)
- Google — optional sign-in via Google OAuth, plus the optional Search Console and Analytics integrations described below
- Resend — transactional email delivery
Google user data
Connecting Google Search Console or Google Analytics is entirely optional — Rank Monster works without it. If you do connect, you grant access through Google's standard OAuth consent screen, and we request the narrowest read-only permissions that let the feature work:
- Search Console (
webmasters.readonly) — we read the list of properties you own and their search analytics (queries, clicks, impressions, CTR, average position) so we can show which search terms your site already ranks for and compare that against how AI assistants describe you. - Google Analytics (
analytics.readonly) — we read the list of GA4 properties you have access to and aggregate traffic reports so we can identify referral visits arriving from AI assistants such as ChatGPT, Claude, Perplexity, and Gemini, and report that traffic back to you in your dashboard.
Both permissions are read-only. Rank Monster cannot publish, modify, or delete anything in your Search Console or Analytics accounts. We do not request access to Gmail, Drive, Contacts, Calendar, or any other Google service.
How this data is handled. Your OAuth access and refresh tokens are used solely to make API calls on your behalf. The metrics we retrieve are stored against your account and shown only to you and any teammates you have invited into your workspace. We do not sell Google user data, we do not use it for advertising or ad targeting, we do not use it to train machine-learning or AI models, and we do not transfer it to third parties except as strictly necessary to provide the service, comply with applicable law, or as part of a merger or acquisition. No human at Rank Monster reads your Google user data except where you have given explicit consent (for example, when you ask our support team to investigate a problem), where it is necessary for security purposes such as investigating abuse, or where we are required to by law.
Revoking access and deletion. You can disconnect the integration at any time from your Rank Monster settings page, or revoke it directly at myaccount.google.com/permissions. Disconnecting deletes the stored tokens immediately. Any metrics previously retrieved are deleted when you delete your account, or sooner on request to the address below.
How we protect Google user data
We apply the following safeguards to OAuth tokens and any data retrieved from Google APIs:
- Encryption in transit — all communication with Google APIs and between users and Rank Monster uses TLS 1.2 or higher.
- Encryption at rest — OAuth access and refresh tokens are stored encrypted at rest; database volumes and backups are encrypted using AES-256.
- Access controls — production database access is restricted to authorized engineers with a business need, protected by role-based permissions and multi-factor authentication. Tokens are never exposed to client-side code or logs.
- Isolation — Google user data is scoped to the account that connected it and is never visible to other customers.
- Monitoring — we maintain audit logs of production access and monitor for unauthorized access attempts.
- Incident response — in the event of a security incident affecting Google user data, we will notify affected users and Google without undue delay.
- Minimization — we request only read-only scopes and retrieve only aggregated report data required for the feature.
Google Analytics integration
Rank Monster's Google Analytics integration requests read-only access to your Google Analytics 4 property (analytics.readonly scope) so you can connect your GA4 data to Rank Monster.
Data we access. Aggregated traffic, session, referral source, and conversion metrics from the GA4 properties you choose to connect. We do not access your Google account password, email contents, or any Google service other than Analytics.
How we use it. Solely to attribute website visits originating from AI search engines and display AI traffic analytics in your Rank Monster dashboard. We do not use Google user data for advertising, to train AI or machine learning models, or for any purpose unrelated to providing the service.
Sharing. We do not sell, rent, or transfer Google user data to third parties, except to subprocessors that host our infrastructure (e.g. cloud hosting providers) under confidentiality obligations, or when required by law.
Protection. OAuth access and refresh tokens are encrypted at rest using AES-256 and transmitted only over TLS 1.2 or higher. Analytics data is stored in access-controlled databases limited to authorized personnel with a business need. We maintain audit logging, least-privilege access controls, and regular security reviews.
Retention and deletion. Tokens and GA4 data are retained only while your integration is connected. You can disconnect at any time from your Rank Monster settings or by revoking access at myaccount.google.com/permissions; we delete the associated tokens immediately and cached analytics data within 30 days. You may also request deletion by emailing [email protected].
Limited Use. Rank Monster's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention
We retain your account data for as long as your account is active. You can request deletion of your data at any time by emailing us at the address below. After deletion, some information may remain in backups for up to 30 days before being permanently removed.
Public audit reports
If you choose to share your AEO audit, we publish a permanent, public-facing snapshot of that audit at rankmonster.ai/ai-visibility/<slug>. The page shows your domain, visibility scores, and entity-presence results — no other account data or personal information is included.
- Public reports are permanent by default so the URL you share remains valid indefinitely.
- You can take a report private at any time from your dashboard — this returns a 404 to anyone with the link.
- Reports can only be modified by re-running the audit after signing up for a paid plan; the original snapshot is immutable.
Your rights
You may request access to, correction of, or deletion of your personal information at any time. You may also opt out of marketing and digest emails from your settings page.
Contact
Questions about this policy? Email [email protected].