Updated October 3, 2026

Privacy policy

How Rankrook handles account information, Google and Bing search data, research providers and website changes.

Rankrook is a product of Untitled Folder Labs. This policy describes the development service and the customer workflow being prepared. Customer sign-up is not yet open. When customer access launches, this policy applies to the information you provide and authorize us to collect.

What we collect and why

Account information includes your email address and sign-in identifiers. Connected-site information includes the site's address, ownership proof, selected repository, access grants and settings. Search data may include page performance, queries, clicks, impressions, positions, indexing signals and Bing data.

We use that information to authenticate you, check site ownership, collect evidence, propose reviewable improvements and measure outcomes. Public site pages and permitted repository files may be processed to understand the site. Run records contain evidence references, actions, outcomes and actual spend.

We do not sell Google user data or use it for advertising. Private Search Console queries are visible only to the site's authorized owner and that owner's authenticated agents. They are excluded from public pull requests, customer repositories, the editing agent, notifications and logs.

Services involved

Google
Search Console, sign-in for search access, site verification and authorized property operations.
Microsoft Bing
Bing Webmaster access, verification, sitemaps and indexing signals. IndexNow submissions share changed public URLs with participating engines.
DataForSEO
Search-result and keyword research. Query research is described below.
Cloudflare
Application hosting, storage, queues, workflow execution and AI processing for bounded edits.
Clerk
Email-code authentication, account identifiers and authenticated agent access.
GitHub
Optional selected-repository access, draft pull requests, review events and change tracking.

A customer's own assistant provider also receives information when the customer asks that assistant to read Rankrook data. Your assistant's terms govern its handling of that information.

Google user data and Limited Use

Rankrook's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

We use authorized Google data only to provide or improve the user-facing search-analysis and website-improvement features you request. We do not use it to train a general-purpose AI model, build advertising profiles or determine creditworthiness. Transfers are limited to providing these features, security, legal requirements or a business transfer with the required consent.

Human access to Google user data is limited to your explicit agreement for a specific purpose, investigating abuse, complying with law, or permitted internal operations on aggregated, anonymized data. Access grants are tenant-scoped; secrets are stored separately from customer repositories.

Search queries sent for research

When query research is enabled, top Search Console queries are sent to DataForSEO to retrieve search-result evidence. Those query strings leave Rankrook for that research; they are not merely kept inside the dashboard. Calls stay within the site's data-provider cap and their cost is recorded.

The customer launch includes a per-site setting to turn this sharing off before research runs. Turning it off stops sending Search Console query text to DataForSEO. Separate research about the public domain may still run within its own limits. Customer query research must not launch before this setting is available and enforced.

Retention, access and disconnection

The current ledger retains page-level observations for up to 16 months and webhook delivery identifiers for seven days, with scheduled pruning. Durable change summaries are kept for measurement history. Private raw search imports and their deletion controls are being completed for customer launch; no broader retention promise is made here.

You can revoke the Google connection in your Google account's third-party access settings. Search-engine ownership handoff is separate from revoking a read-only grant. Read the handoff guide before deleting verification files or records.

Account export and deletion controls are part of customer onboarding and are not available on this public prelaunch site. A verified support and privacy contact must be published before customer enrollment. This prelaunch page does not accept private data requests. Never post private queries, credentials or personal data publicly.

Policy updates

We will update the date on this page when this policy changes. Material changes to customer data use must be communicated before they take effect. Provider setup, OAuth app verification and customer readiness are still pending.