Privacy Policy
1. Controller Information
If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please contact us using the details above.
1.1 Data Protection Officer (DPO)
Rankscale GmbH has assessed its obligation to appoint a Data Protection Officer under Article 37 GDPR. While Rankscale operates an AI search monitoring platform, the service analyses the visibility of brands and products in AI-generated responses, it does not process personal data of end users or data subjects at scale. The data processed relates to brand terms, URLs, and search queries rather than to identifiable individuals. On this basis, the conditions for a mandatory DPO appointment are currently not met.
Responsibility for all data protection matters therefore lies with the managing director, Mathias Ptacek, who can be reached at info@rankscale.ai
2. Data Processing When You Use Our Service
You can browse our landing page without providing personal data. However, to use our web app or subscribe to our newsletter, certain data is required.
2.1 Data Processing to Enable Website Use (Connection Data)
When you access our Service, your browser transmits connection data to our server. This includes:
- Your IP address
- Date and time of the request
- Referring URL
- Browser type, version, and operating system
- Device information
This data is processed to deliver and display the website correctly and ensure its stability and security. It is not used to identify you personally. The legal basis for this processing is our legitimate interest (Article 6(1)(f) GDPR) in operating a secure and functional website.
2.2 Account Registration and Use
To use the Rankscale web app, you must register for an account. We collect the following data:
- Data Collected: Name, email address, company name, and payment information (processed by our payment provider).
- Purpose: To create and manage your user account, provide our services, handle billing, and communicate with you about your account.
- Legal Basis: The processing is necessary for the performance of a contract with you (Article 6(1)(b) GDPR).
2.3 Newsletter Subscription
- Data Collected: Email address.
- Purpose: To send you updates about our company, products, and services, or to provide free analysis reports you request.
- Legal Basis: Your consent (Article 6(1)(a) GDPR). You can withdraw your consent at any time by clicking the "unsubscribe" link in any newsletter.
3. Cookies and Tracking Technologies
We use cookies and similar technologies to ensure our Service functions correctly and, where you consent, to analyze user behavior and measure advertising. Your choice is stored for up to one year and is shared across Rankscale subdomains.
3.1 Types of Cookies
- Essential Cookies: These are necessary for the core functionality of our website (e.g., managing your session, authentication). They rely on the strictly-necessary storage exemption under applicable ePrivacy law; the related personal-data processing is necessary to perform the service and protect it (Articles 6(1)(b) and 6(1)(f) GDPR).
- Analytics & Marketing Cookies: These help us understand how you use our Service and measure advertising. Cookies and storage in these categories are used only with your explicit consent (Article 6(1)(a) GDPR and applicable ePrivacy law). Analytics and Marketing can be selected independently. The limited, session-only affiliate referral handling described in Section 4.4 is separate from Rewardful cookies and uses the legal basis stated there.
3.2 Managing Your Preferences
You can manage your cookie preferences at any time. Blocking certain cookies may reduce analytics, attribution, and personalization, but does not prevent use of the core Service. Withdrawing a category sends a denied signal, clears known first-party vendor cookies, unloads Rewardful when Marketing is withdrawn, and reloads the page to stop tags already running.
3.3 Consent Records
When you are signed in, Rankscale records your cookie-consent choices to document and demonstrate compliance. The record may contain your user ID, selected categories, decision context, policy version, timestamp, and a shortened browser user-agent. For newly created accounts, an existing landing-site preference may be imported once; that record reflects the import time rather than the original selection time. The legal basis is Article 6(1)(c) in conjunction with Article 7(1) GDPR. We retain these records for four years from creation, unless longer retention is necessary for an ongoing legal or regulatory matter.
4. Use of Third-Party Services
4.1 Google Cloud Platform (GCP) / Firebase
Our Service is hosted entirely on the Google Cloud Platform (GCP), with the primary data center in Iowa, USA (region us-central1). We use several services from Google Firebase, which operates as part of GCP, for core functionalities:
- Firebase Hosting: To securely host and deliver the content of our website. When you visit our site, your browser connects to Firebase servers, which logs your IP address for security and operational purposes. The legal basis is our legitimate interest in the secure and efficient provision of our Service (Article 6(1)(f) GDPR).
- Firebase Authentication: To manage user logins securely via email/password, magic link, or Google Sign-In. This processing is necessary to provide you with access to your account. The legal basis is the performance of a contract (Article 6(1)(b) GDPR).
- Firestore (Database): To store user account data and application data necessary for the Service to function. The legal basis is the performance of a contract (Article 6(1)(b) GDPR).
- Transfer Safeguard: EU Standard Contractual Clauses (SCCs) pursuant to the European Commission's decision of June 2021 (Article 46(2)(c) GDPR), supplemented by Google's certification under the EU-U.S. Data Privacy Framework. Google Cloud Platform is certified under ISO 27001, ISO 27017, ISO 27018, and is SOC 2 Type II audited.
4.2 Google Analytics, Google Ads, and Consent Mode
We use Google Analytics 4 to understand website usage and Google Ads to measure advertising conversions. Their storage is controlled separately: Analytics requires Analytics consent; advertising storage, user data, and personalization require Marketing consent.
- Purpose: To analyze user behavior, measure performance, and optimize our Service.
- Legal Basis: Your consent (Article 6(1)(a) GDPR) for cookies, identifiers, and full measurement.
- Denied state: We use Google's Advanced Consent Mode. Before consent and after a refusal, Google tags may send cookieless measurement pings containing the consent state and ordinary connection information such as IP address, user agent, page URL, and screen information; Google states that Analytics does not store or log the IP address from these pings. No Google Analytics or advertising cookies are read or written in the denied category. The purpose is aggregated behavioral and conversion modelling. The legal basis asserted by Rankscale for this limited connection-level processing is legitimate interests (Article 6(1)(f) GDPR).
- Transfer Safeguard: EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses (SCCs).
See Google's Consent Mode explanation.
4.3 Microsoft Clarity, LinkedIn, Reddit, and Lemlist
These non-Google tags are blocked until the corresponding category is granted. Microsoft Clarity is an Analytics provider used for aggregated interaction and usability analysis. LinkedIn Insight Tag, Reddit Pixel, and Lemlist are Marketing providers used for campaign, visit, lead, and conversion measurement.
- Data Processed: Page and event data, referring/campaign information, browser/device information, IP address, and pseudonymous cookie or pixel identifiers when consented. We do not intentionally send form contents, passwords, payment details, or plain-text account email addresses through GTM.
- Legal Basis: Your consent (Article 6(1)(a) GDPR). Clarity requires Analytics consent. LinkedIn, Reddit, and Lemlist require Marketing consent.
- Withdrawal: Their tags are blocked on the next page load after withdrawal. Known first-party cookies for these providers, including Clarity, LinkedIn, Reddit, and Lemlist cookies, are expired where technically accessible; third-party storage must be managed through the provider or browser.
Provider information: Microsoft Clarity cookies, LinkedIn cookie table, Reddit conversion events, and Lemlist GDPR information.
4.4 Rewardful and Affiliate Attribution
Rewardful's browser script and first-party referral cookie are used only after Marketing consent. The durable cookie/local-storage referral window is 60 days. Rewardful helps connect an affiliate referral with a later signup or purchase so the referring affiliate can receive commission.
- Before Marketing consent: If you arrive with a valid affiliate parameter, Rankscale keeps the bounded referral token in session storage for the current browser session only. The Rewardful script is not loaded and no durable Rewardful cookie is set.
- Account-linked attribution: At signup or successful checkout, Rankscale may store the referral token, capture/expiry timestamps, source, user ID, and whether it was passed to Stripe in a separate first-party record for up to 60 days. This can occur even if Marketing cookies are declined so we can administer affiliate commissions, investigate attribution disputes, and prevent duplicate or incorrect credit. The asserted legal basis is our legitimate interest (Article 6(1)(f) GDPR). You may object under Article 21.
- Withdrawal: Declining or withdrawing Marketing removes Rewardful's durable browser state and unloads its script. It does not retroactively remove a short-lived account-linked attribution or a referral already included in a Stripe checkout request; contact us to object or request erasure where applicable.
See Rewardful's first-party cookie explanation and 60-day default referral window.
4.5 Twilio / SendGrid
We use SendGrid (a Twilio company) for transactional email delivery.
- Data Processed: Email address, message metadata.
- Purpose: To send account-related communications such as registration confirmations, password resets, and service notifications.
- Legal Basis: Performance of a contract (Article 6(1)(b) GDPR) and legitimate interest (Article 6(1)(f) GDPR).
- Transfer Safeguard: EU Standard Contractual Clauses (SCCs).
4.6 Stripe
We use Stripe to process payments and manage billing.
- Data Processed: Payment information (e.g., credit card details, billing address), name, email address.
- Purpose: To handle subscriptions, process payments, and manage invoicing. Rankscale does not store full payment details on its own servers.
- Legal Basis: Performance of a contract (Article 6(1)(b) GDPR).
- Transfer Safeguard: EU Standard Contractual Clauses (SCCs).
4.7 PostHog
We use PostHog for product analytics to understand how users interact with the Rankscale application.
- Data Processed: Pseudonymous usage data, session information, IP address.
- Purpose: To analyse product usage patterns and improve the user experience.
- Legal Basis and controls: On the landing site, Analytics consent enables persistent PostHog analytics; after refusal, landing measurement is cookieless and does not use browser storage or identify you. In the authenticated app, Rankscale currently processes limited product analytics under legitimate interests/clickwrap while no preference has been recorded and stops browser capture after an explicit Analytics refusal. Some UID-keyed operational events are sent server-side independently of the browser cookie setting. We are reviewing a unified client/server consent strategy.
- Transfer Safeguard: EU Standard Contractual Clauses (SCCs).
4.8 Rankscale Data Studio Connector and Google API Data
Rankscale offers a Data Studio Community Connector that allows users to visualize their Rankscale data within Google Data Studio. The connector is published and maintained by Rankscale. It authenticates to Rankscale using a user-issued Rankscale API key (obtained from Settings → Integrations). On the Google side it uses only the https://www.googleapis.com/auth/script.external_request OAuth scope, which solely permits outbound HTTPS requests to Rankscale's public BI endpoints. No other Google APIs, Google user data, or Google account information is accessed.
- Data Flow: The connector operates on a one-directional, read-only basis. It retrieves data stored within the user's Rankscale account (such as AI search visibility metrics, brand scores, sentiment, citations, and tracking results) and makes it available for display in the user's own Data Studio dashboard. No data from Google APIs, Google Drive, Google Sheets, Gmail, Google Calendar, Google Contacts, or any other Google service is transferred back to Rankscale or to any third party.
- No Sharing or Disclosure: Data accessed through the Rankscale Data Studio connector is not shared with, transferred to, or disclosed to any third party, including any AI engine, large language model, or machine learning service (such as OpenAI, Anthropic, Google Gemini, Perplexity, DeepSeek, xAI Grok, Mistral, or any other provider). No data obtained from Google APIs is used to serve advertising, nor is it used for training or improving AI or machine learning models.
- Separation from AI/LLM Querying: Rankscale's core service queries various AI engines to assess brand visibility in AI-generated responses. These queries are performed using only user-configured search terms and brand names, never using data obtained from Google APIs. The Data Studio connector and the AI/LLM querying functionality operate on completely separate, isolated data pipelines with no shared data pathways.
- Data Storage: The connector does not independently store or cache Google user data. Rankscale API responses may be held briefly (up to 10 minutes) in Google Apps Script's per-user script cache solely to reduce redundant API calls during a single user's session; this cache is scoped to the user's own Apps Script deployment and is not accessible to Rankscale.
- Legal Basis: Performance of a contract (Article 6(1)(b) GDPR).
Rankscale's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.9 Rankscale MCP Server (AI Assistant Connections)
Rankscale offers a Model Context Protocol (MCP) server at https://mcp.rankscale.ai/mcp. It lets you connect an AI assistant that you choose, such as Claude (by Anthropic), ChatGPT (by OpenAI), or Cursor, to your Rankscale account. You start each connection yourself, sign in with your Rankscale account, and choose its permissions on a consent screen. See our MCP documentation for the full list of tools.
- What the assistant can access: Only data that the signed-in Rankscale user is already allowed to see in the Rankscale dashboard, such as brands, search terms, topics, tracking results, analytics, and saved dashboard views. Reading is always included. Creating or changing search terms, topics, and dashboard views, and running tracking that spends credits, are separate permissions that stay off unless you turn them on.
- Data we process for MCP: Records needed to run the connection: the registered client application (for example its name and redirect address), your consent decision and granted permissions, and OAuth access and refresh tokens linked to your account. When your assistant uses a tool, we process the request to return the result. When it changes data, we also keep: an audit record of the change (who made it, through which connection, which fields changed, and shortened before and after values); the outcome of the action, so a repeated request is not carried out twice; records of run requests and their progress; and daily usage counters that enforce limits.
- Usage analytics and security: For each tool call we record technical metadata, such as the tool name, the client application, timing, success or failure, and a one-way hash of the request arguments, using PostHog (see section 4.7). We do not send the raw contents of your requests or of the results to PostHog. We use this data to operate, secure, and improve the MCP server, for example to apply rate limits and to detect misuse of tokens.
- Sharing with your AI assistant: The results your assistant requests are sent to the assistant application you connected. That provider (for example Anthropic for Claude or OpenAI for ChatGPT) processes the data under its own terms and privacy policy, which you agreed to when you started using that assistant. Apart from the service providers described in this policy that process data on our behalf, such as Google Cloud (hosting) and PostHog (usage analytics, see above), we do not share your MCP data with other third parties, and we do not use it to train AI models.
- Retention: Access tokens expire after one hour and refresh tokens after 30 days of non-use. A connection lasts at most one year before you must approve it again. Action outcomes are deleted automatically after 24 hours, and run requests after 30 days. Audit records of changes, usage counters, consent records, and expired tokens are not yet deleted automatically; they are kept for as long as needed to operate, secure, and support the MCP connection.
- Your control: You can see and revoke every connected assistant in Rankscale under Settings, Connections, MCP. Revoking ends access for that connection immediately. Data already sent to your assistant is held by that assistant's provider; manage or delete it in that application.
- Legal Basis: Performance of a contract (Article 6(1)(b) GDPR) for providing the MCP connection you request, and our legitimate interest (Article 6(1)(f) GDPR) in operating and securing the service for usage analytics and misuse detection.
- Contact: Questions about MCP and your data can be sent to support@rankscale.ai. For data protection requests, contact our managing director as described in section 1.1.
5. Data Transfer to Third Countries
When using third-party services such as Google, Microsoft, LinkedIn, Reddit, Lemlist, Rewardful, Stripe, Twilio/SendGrid, and PostHog, personal data may be transferred to and processed outside the EEA, including in the United States. The European Commission's EU-U.S. Data Privacy Framework adequacy decision covers transfers to participating U.S. organisations where their certification covers the data concerned; it does not cover U.S. recipients generally. For transfers covered by that decision, we rely on it as the adequacy basis. Where no applicable adequacy decision covers a transfer, we rely on appropriate safeguards, such as EU Standard Contractual Clauses (SCCs).
6. Data Retention
We store your personal data only as long as necessary for the purposes for which it was collected, or as required by statutory retention obligations.
- Account Data: Retained for the duration of your contract with us and thereafter as required by law (e.g., for accounting purposes).
- Newsletter Data: Retained until you unsubscribe.
- Connection Data: Stored for a short period for security analysis and then deleted or anonymized.
- Cookie preference: Up to one year, unless you change it or clear site data earlier.
- Consent records: Four years from creation, unless longer retention is necessary for an ongoing legal or regulatory matter.
- Affiliate referral: Session-only before Marketing consent; Rewardful durable browser attribution and Rankscale's separate account-linked attribution are limited to 60 days unless an attribution is incorporated into records we must retain for contractual, dispute, or legal obligations.
- MCP connections: Access tokens one hour, refresh tokens 30 days of non-use, connections at most one year or until you revoke them; action outcomes deleted after 24 hours and run requests after 30 days; change audit records, usage counters, consent records, and expired tokens not yet deleted automatically (see section 4.9).
7. Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- The right to access your data (Article 15 GDPR).
- The right to rectification of inaccurate data (Article 16 GDPR).
- The right to erasure ("right to be forgotten") of your data (Article 17 GDPR).
- The right to restriction of processing (Article 18 GDPR).
- The right to data portability (Article 20 GDPR).
- The right to withdraw consent at any time (Article 7(3) GDPR).
- The right to lodge a complaint with a supervisory authority (in Austria, the Datenschutzbehörde) (Article 77 GDPR).
8. Right to Object
Under Article 21 GDPR, you have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data which is based on legitimate interests (Article 6(1)(f) GDPR). If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. However, no data transmission over the internet can be guaranteed to be 100% secure.
10. Changes to This Policy
We reserve the right to update this Privacy Policy to reflect changes in our practices or for legal reasons. The latest version will always be available on our website.
Last Updated: 21.09.2026
By using our Service, you acknowledge that you have read and understood this Privacy Policy.