Updated October 3, 2026
Privacy policy
How Rankrook handles account information, Google and Bing search data, research providers and website changes.
Rankrook is a product of Untitled Folder Labs. This policy describes the development service and the customer workflow being prepared. Customer sign-up is not yet open. When customer access launches, this policy applies to the information you provide and authorize us to collect.
What we collect and why
Account information includes your email address and sign-in identifiers. Connected-site information includes the site's address, ownership proof, selected repository, access grants and settings. Search data may include page performance, queries, clicks, impressions, positions, indexing signals and Bing data.
We use that information to authenticate you, check site ownership, collect evidence, propose reviewable improvements and measure outcomes. Public site pages and permitted repository files may be processed to understand the site. Run records contain evidence references, actions, outcomes and actual spend.
We do not sell Google user data or use it for advertising. Private Search Console queries are visible only to the site's authorized owner and that owner's authenticated agents. They are excluded from public pull requests, customer repositories, the editing agent, notifications and logs.
Services involved
- Search Console, sign-in for search access, site verification and authorized property operations.
- Microsoft Bing
- Bing Webmaster access, verification, sitemaps and indexing signals. IndexNow submissions share changed public URLs with participating engines.
- DataForSEO
- Search-result and keyword research. Query research is described below.
- Cloudflare
- Application hosting, storage, queues, workflow execution and AI processing for bounded edits.
- Clerk
- Email-code authentication, account identifiers and authenticated agent access.
- GitHub
- Optional selected-repository access, draft pull requests, review events and change tracking.
A customer's own assistant provider also receives information when the customer asks that assistant to read Rankrook data. Your assistant's terms govern its handling of that information.
Google user data and Limited Use
Rankrook's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
We use authorized Google data only to provide or improve the user-facing search-analysis and website-improvement features you request. We do not use it to train a general-purpose AI model, build advertising profiles or determine creditworthiness. Transfers are limited to providing these features, security, legal requirements or a business transfer with the required consent.
Human access to Google user data is limited to your explicit agreement for a specific purpose, investigating abuse, complying with law, or permitted internal operations on aggregated, anonymized data. Access grants are tenant-scoped; secrets are stored separately from customer repositories.
Search queries sent for research
When query research is enabled, top Search Console queries are sent to DataForSEO to retrieve search-result evidence. Those query strings leave Rankrook for that research; they are not merely kept inside the dashboard. Calls stay within the site's data-provider cap and their cost is recorded.
The customer launch includes a per-site setting to turn this sharing off before research runs. Turning it off stops sending Search Console query text to DataForSEO. Separate research about the public domain may still run within its own limits. Customer query research must not launch before this setting is available and enforced.
Retention, access and disconnection
The current ledger retains page-level observations for up to 16 months and webhook delivery identifiers for seven days, with scheduled pruning. Durable change summaries are kept for measurement history. Private raw search imports and their deletion controls are being completed for customer launch; no broader retention promise is made here.
You can revoke the Google connection in your Google account's third-party access settings. Search-engine ownership handoff is separate from revoking a read-only grant. Read the handoff guide before deleting verification files or records.
Account export and deletion controls are part of customer onboarding and are not available on this public prelaunch site. A verified support and privacy contact must be published before customer enrollment. This prelaunch page does not accept private data requests. Never post private queries, credentials or personal data publicly.
Policy updates
We will update the date on this page when this policy changes. Material changes to customer data use must be communicated before they take effect. Provider setup, OAuth app verification and customer readiness are still pending.