RRankGrep

Privacy Policy

Last updated: 12 August 2026

Information we collect

  • Account info — your email and name, from Google Sign-In.
  • Websites you add — the URL, name, target country/language, and description you provide.
  • Crawl data — publicly visible page content (titles, meta descriptions, headings, links, word counts) from sites you choose to audit.
  • WordPress connections (optional) — the site URL, username, and an encrypted WordPress Application Password. We never see or store your actual WordPress account password — Application Passwords are a separate, revocable credential WordPress generates for this purpose.
  • Google Search Console / Analytics (optional) — if you connect them, read-only performance data (clicks, impressions, sessions, and similar metrics) accessed via an encrypted OAuth refresh token.

How we use it

To run audits, detect issues with real evidence, prepare and — once you approve — apply fixes, and show you real search and traffic performance for websites you've connected.

AI processing

Crawled page content and issue evidence may be sent to a third-party AI provider (Anthropic, OpenAI, or Google Gemini, depending on configuration) to generate analysis and suggested fixes. We never send your Google account password or WordPress password to these providers — we don't have them to send.

Google user data

RankGrep's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data sharing

We don't sell your data. Information is only shared with the third-party services needed to provide the feature you used — Google's APIs (sign-in, Search Console, Analytics), an AI provider for repair analysis, and Google PageSpeed Insights for performance scores.

Data retention

Data is kept while your account is active. Removing a website deletes its crawl, issue, and repair history. Contact us to delete your account and all associated data.

Security

WordPress Application Passwords and Google refresh tokens are encrypted at rest. External sign-in uses OAuth or scoped application credentials only — RankGrep never asks for or stores your Google or WordPress password.

Your choices

Disconnect a WordPress or Google connection anytime from Connections. Sign out anytime. Email us to request account deletion.

Changes

As a preview product, this policy may change. Material changes will update the date above.

Contact

Questions about this policy: support@rankgrep.com