Legal
Privacy policy
Last updated: July 23, 2026
TEMPLATE — review with a qualified lawyer before publishing. This document is a starting point generated from our internal decisions, not legal advice.
1 Who we are
Rank Force ("we", "us") operates rankforce.io, a service that generates SEO/AEO/GEO-optimized articles. This policy explains what we collect, why, and your rights. It covers the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).
2 Information we collect
- Account data: your email address, name, and (optionally) your website URL. Your website URL is stored as context only and is never fetched by our servers.
- Content you create: the keywords you enter, the outlines you approve, and the articles we generate for you.
- Payment data: a Stripe customer identifier and non-sensitive payment metadata. We never see or store your card number — Stripe handles all card data (we maintain PCI SAQ A posture).
- Security and activity data: IP addresses, login history (timestamp, IP, user agent), and audit records of sensitive account actions. These support abuse prevention and support.
We do not collect government IDs, health, biometric, precise-location, or children's data, and the service is for users aged 18 and over.
3 How we use your information
To provide and secure the service, process payments, send transactional email (verification, receipts, "article ready"), prevent abuse and fraud, and meet legal obligations. We do not sell your personal information, and we do not use it for third-party advertising.
4 International transfers
We host in the United States (Hostinger) with backups in the United States (Backblaze B2) and a global CDN (Cloudflare). If you are in the EU/UK, your data is transferred to the United States under appropriate safeguards, including Standard Contractual Clauses with our sub-processors.
5 Sub-processors
We share data only with the service providers needed to run Rank Force:
| Sub-processor | Purpose | Region |
|---|---|---|
| Hostinger | VPS hosting | United States |
| Cloudflare | CDN, WAF, DNS, TLS | Global |
| Stripe | Payment processing | United States / global |
| Anthropic | AI generation (zero-retention) | United States |
| OpenAI | AI generation (zero-retention) | United States |
| Serper | SERP research data | United States |
| Resend | Transactional email | United States |
| Backblaze B2 | Encrypted backups | United States |
| Sentry | Error monitoring (PII scrubbed) | United States |
AI providers process your content on zero-retention / no-training API tiers; we never place your personal or account data in AI prompts.
6 Staff access
Our staff can access account content (for example, to view an article) for support and abuse prevention. Every such access is logged in an append-only audit trail. We access content purposefully, not casually.
7 Retention
We keep active-account data while your account is open. Application logs are kept 30–90 days; audit logs about one year; payment and invoice records about seven years (legal/tax requirement). When you delete your account there is a 30-day recoverable grace window, after which personal data is deleted or anonymized; the append-only credit ledger and audit entries are anonymized rather than hard-deleted.
8 Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and (California) to opt out of "sale/share" — which we do not do. You can export your articles from the workspace and request account deletion in settings. To exercise other rights, contact us below.
10 Contact
Privacy questions: support@rankforce.io. If you are in the EU/UK and believe we have not resolved your concern, you may lodge a complaint with your local supervisory authority.