RankRaft AI

Privacy policy

RankRaft AI analyses traffic to our customers' websites. This page explains what we collect, why, and how long we keep it.

Last updated 2 October 2026

The short version

  • We set no cookies on our customers’ websites, and none on this one.
  • We never store a raw IP address or a raw User-Agent. Both are replaced by a salted hash before they are written, and the salt changes every day, so the same visitor cannot be followed from one day to the next.
  • Ordinary human traffic is counted, not recorded. We keep a daily total, not a row per visitor.
  • We do not sell data, and we do not use it to train AI models.

Who we are

RankRaft AI is operated by Zain Ur Rehman, trading as RankRaft AI. For questions about this policy or your data, write to privacy@rankraft.ai.

Two different kinds of data

This distinction runs through everything below, so it is worth stating first.

If you are a RankRaft AI customer

We collect only what is needed to run an account:

Our lawful basis is performance of our contract with you, and our legitimate interest in keeping the service secure and working.

If you are a visitor to a site that uses RankRaft AI

Our customers install RankRaft AI on their own websites. For each request to those sites we receive the time, hostname, path, HTTP method, response status and size, the referrer, the query string with sensitive parameters removed, a coarse country, the User-Agent and the IP address.

How that data reaches us

There are three ways, and a customer chooses which to use:

What happens to the IP address and User-Agent

Neither is stored. Both are combined with a secret salt and replaced by a SHA-256 hash before anything is written; there is no column in our database that could hold the original value. The salt is regenerated every day, so a hash from Monday and a hash from Tuesday do not match even for the same visitor. That is deliberate: it is enough to recognise a repeat visit within a day and to verify that a self-declared crawler really comes from its provider’s published address ranges, and not enough to build a profile of a person over time.

If the salt is ever unavailable, our ingest service refuses to accept data at all and returns an error, rather than falling back to storing addresses.

What is not collected

Most human visits are counted, not stored

We keep an individual record only for AI crawlers, search engine bots and visits arriving from an AI assistant, the traffic the product exists to analyse. Ordinary human traffic is added to a daily total per site, so a share-of-traffic figure still works without keeping a row per person.

This website

rankraft.ai is a set of static files. It sets no cookies, runs no analytics and loads no third-party trackers. The dashboard at app.rankraft.ai sets one essential cookie to keep you signed in; it carries an opaque random token, of which only a hash is stored, and nothing else.

Who else processes data

ProcessorWhat for
CloudflareHosting, the edge network, the ingest service, the database connection, bot protection on our sign-in forms, and outbound email
PlanetScaleThe database
Anthropic, OpenAI and GoogleWe send the questions being measured to these AI platforms and record their answers. We do not send them your account data or any visitor data
DataForSEOWe send the questions being measured, and the market you chose, to retrieve the Google AI Overview and AI Mode results a searcher in that market would see. We do not send them your account data or any visitor data
SlackOperational error alerts, where a customer has connected it
Paddle.comOur Merchant of Record. Paddle sells the subscription to you, takes payment, issues invoices and handles tax and refunds. It receives your billing details directly; we never see your card

We will update this list before adding a new processor. If you need a data processing agreement for your own compliance, ask and we will provide one.

International transfers

Our processors operate globally, so data may be processed outside your country. Where that involves personal data leaving the UK or EEA, transfers are covered by Standard Contractual Clauses or an equivalent safeguard offered by the processor.

How long we keep it

Security

If you believe you have found a security problem, please write to security@rankraft.ai and give us a reasonable chance to fix it before disclosing it publicly.

Your rights

You can ask for a copy of your data, ask us to correct or delete it, ask us to restrict how we use it, or object to our use of it. Write to privacy@rankraft.ai and we will respond within one month.

If you are a visitor to a customer’s website rather than a customer yourself, contact that website’s owner; they decide what is collected and we act on their instructions. If you contact us instead, we will pass your request on.

RankRaft AI is operated from Pakistan, so there is no single regulator we answer to worldwide. If you are in the UK or the EEA, the GDPR rights above still apply to you, and you may complain to your national data protection authority if you are unhappy with how we respond. Where personal data leaves the UK or EEA to reach us, Standard Contractual Clauses apply. If you are in California, you may also ask what personal information we hold and ask us to delete it; we do not sell personal information, so there is nothing to opt out of.

Changes

We will post any change here and update the date at the top. If a change materially affects how we handle your data, we will email you before it takes effect. Related: our terms of service and what our crawler does.