Privacy policy
RankRaft AI analyses traffic to our customers' websites. This page explains what we collect, why, and how long we keep it.
Last updated 2 October 2026
The short version
- We set no cookies on our customers’ websites, and none on this one.
- We never store a raw IP address or a raw User-Agent. Both are replaced by a salted hash before they are written, and the salt changes every day, so the same visitor cannot be followed from one day to the next.
- Ordinary human traffic is counted, not recorded. We keep a daily total, not a row per visitor.
- We do not sell data, and we do not use it to train AI models.
Who we are
RankRaft AI is operated by Zain Ur Rehman, trading as RankRaft AI. For questions about this policy or your data, write to privacy@rankraft.ai.
Two different kinds of data
This distinction runs through everything below, so it is worth stating first.
- Your account data. Information about you as a RankRaft AI customer. We decide how this is used, so for this we are the data controller.
- Your visitors’ data. Information about people who visit the websites you track. You decide what is collected and why; we act on your instructions, so for this we are a data processor and you are the controller.
If you are a RankRaft AI customer
We collect only what is needed to run an account:
- Your name, email address and, optionally, your role. Your password is stored only as a PBKDF2-SHA256 hash; we never hold the password itself and cannot recover it.
- The domains you add and the settings you choose for them.
- Sessions: a hash of the session token, your IP address, your browser’s User-Agent and the time it was last used, so you can review and sign out your own devices from your profile. These are kept in full, unlike visitor data, precisely so you can recognise your own sign-ins.
- Billing status. Card details are handled by our payment provider and never reach our servers.
- Emails we send you: verification, password resets and invitations.
Our lawful basis is performance of our contract with you, and our legitimate interest in keeping the service secure and working.
If you are a visitor to a site that uses RankRaft AI
Our customers install RankRaft AI on their own websites. For each request to those sites we receive the time, hostname, path, HTTP method, response status and size, the referrer, the query string with sensitive parameters removed, a coarse country, the User-Agent and the IP address.
How that data reaches us
There are three ways, and a customer chooses which to use:
- The RankRaft AI Analytics plugin for WordPress. It records public front-end requests on the server and sends them in batches. It is inert until a site key is entered and logging is switched on, and it never logs admin pages, logins, the REST API, AJAX, cron or XML-RPC. Query parameters whose names look sensitive (
password,token,key,secret,card,emailand similar) are replaced with[REDACTED]before anything leaves the customer’s server. The plugin keeps a short queue table on the customer’s own database until each batch is sent, and removes that table, its settings and its scheduled jobs when it is uninstalled. - A Cloudflare Worker the customer deploys on their own zone, which reports the same fields.
- A browser script, which only reports visits that arrived from an AI assistant. It sets no cookies, stores nothing on the device and sends its request with credentials omitted.
What happens to the IP address and User-Agent
Neither is stored. Both are combined with a secret salt and replaced by a SHA-256 hash before anything is written; there is no column in our database that could hold the original value. The salt is regenerated every day, so a hash from Monday and a hash from Tuesday do not match even for the same visitor. That is deliberate: it is enough to recognise a repeat visit within a day and to verify that a self-declared crawler really comes from its provider’s published address ranges, and not enough to build a profile of a person over time.
If the salt is ever unavailable, our ingest service refuses to accept data at all and returns an error, rather than falling back to storing addresses.
What is not collected
- No cookies, no
localStorage, no device fingerprinting. Our browser script sends its request with credentials omitted and stores nothing on the device. - No form data, no page content, and nothing about logged-in users of our customers’ sites.
- No cross-site tracking. Data from one customer’s site is never combined with another’s.
Most human visits are counted, not stored
We keep an individual record only for AI crawlers, search engine bots and visits arriving from an AI assistant, the traffic the product exists to analyse. Ordinary human traffic is added to a daily total per site, so a share-of-traffic figure still works without keeping a row per person.
This website
rankraft.ai is a set of static files. It sets no cookies, runs no analytics and loads no third-party trackers. The dashboard at app.rankraft.ai sets one essential cookie to keep you signed in; it carries an opaque random token, of which only a hash is stored, and nothing else.
Who else processes data
| Processor | What for |
|---|---|
| Cloudflare | Hosting, the edge network, the ingest service, the database connection, bot protection on our sign-in forms, and outbound email |
| PlanetScale | The database |
| Anthropic, OpenAI and Google | We send the questions being measured to these AI platforms and record their answers. We do not send them your account data or any visitor data |
| DataForSEO | We send the questions being measured, and the market you chose, to retrieve the Google AI Overview and AI Mode results a searcher in that market would see. We do not send them your account data or any visitor data |
| Slack | Operational error alerts, where a customer has connected it |
| Paddle.com | Our Merchant of Record. Paddle sells the subscription to you, takes payment, issues invoices and handles tax and refunds. It receives your billing details directly; we never see your card |
We will update this list before adding a new processor. If you need a data processing agreement for your own compliance, ask and we will provide one.
International transfers
Our processors operate globally, so data may be processed outside your country. Where that involves personal data leaving the UK or EEA, transfers are covered by Standard Contractual Clauses or an equivalent safeguard offered by the processor.
How long we keep it
- Individual request records: 13 months. Older ones are dropped automatically, as whole monthly partitions.
- Daily totals and visibility results: for the life of the account, because they are the history the product reports on.
- Account data: until you delete your account, then removed within 30 days, except where we must keep records to meet a legal or tax obligation.
- Sessions: expire after 30 days, sooner if you sign out, and all of them immediately when you change your password.
Security
- Everything is served over HTTPS.
- Passwords use PBKDF2-SHA256; session tokens and API keys are stored only as SHA-256 hashes, never in a form we could read back.
- An API key is shown once, when it is created. If it is lost it has to be rotated, because we cannot display it again.
- Access to production systems is limited to those who need it.
If you believe you have found a security problem, please write to security@rankraft.ai and give us a reasonable chance to fix it before disclosing it publicly.
Your rights
You can ask for a copy of your data, ask us to correct or delete it, ask us to restrict how we use it, or object to our use of it. Write to privacy@rankraft.ai and we will respond within one month.
If you are a visitor to a customer’s website rather than a customer yourself, contact that website’s owner; they decide what is collected and we act on their instructions. If you contact us instead, we will pass your request on.
RankRaft AI is operated from Pakistan, so there is no single regulator we answer to worldwide. If you are in the UK or the EEA, the GDPR rights above still apply to you, and you may complain to your national data protection authority if you are unhappy with how we respond. Where personal data leaves the UK or EEA to reach us, Standard Contractual Clauses apply. If you are in California, you may also ask what personal information we hold and ask us to delete it; we do not sell personal information, so there is nothing to opt out of.
Changes
We will post any change here and update the date at the top. If a change materially affects how we handle your data, we will email you before it takes effect. Related: our terms of service and what our crawler does.