Privacy Policy
Last updated: September 19, 2026
This Privacy Policy explains how Integrallis Software, LLC ("RankCLI," "we," "us") collects, uses, and protects information when you use the RankCLI website, dashboard, command-line tool, GitHub App, and MCP server (collectively, the "Service").
Using RankCLI without an account
You can run rankcli audit and the free, local MCP server (npx @rankcli/mcp-server) without creating an account. In this mode, RankCLI fetches and analyzes whatever URL you point it at, entirely on your own machine - the audit results are not sent to our servers. If you configure your own AI provider key for local use, that key stays on your machine and is used only to call that provider directly.
Information we collect
Once you create an account (email/password, Google, or GitHub sign-in), we collect:
- Account information: your email address, and if you sign in with Google or GitHub, the basic profile information those providers share with us.
- Site and audit data: the URLs you ask RankCLI to audit, the resulting scores and issues, and (if you connect a repository) the repository name and the pull requests RankCLI opens.
- Billing information: if you subscribe to a paid plan, payment is processed by Stripe. We never see or store your full card number - Stripe shares with us only what's needed to manage your subscription (plan, status, and renewal date).
- Your own AI provider keys (optional): if you choose to connect your own OpenAI, Anthropic, or other AI provider key for cloud-based auto-fix PRs, it is encrypted (AES-256-GCM) before storage and is only decrypted server-side, in memory, to make the specific API call you requested.
- Google Search Console data (optional): if you connect Search Console to a project, see “Google Search Console” below.
- Usage data: basic request logs (timestamps, IP address, user agent) used for rate limiting, abuse prevention, and debugging.
How we use this information
- To run audits, generate reports, and open auto-fix pull requests
- To operate your account, subscription, and billing
- To send transactional email (audit results, weekly reports if you opt in, account notices)
- To detect abuse and enforce our rate limits and fair-use terms
- To improve the accuracy and coverage of our SEO checks
We do not sell your personal information, and we do not use your audit data to train AI models.
Third parties we rely on
Running the Service means some data necessarily passes through infrastructure providers we use:
- Supabase - database, authentication, and serverless functions
- Cloudflare - content delivery, DNS, and Web Analytics (cookieless page-view counts; no cookies or cross-site identifiers)
- Fly.io - runs the audit engine that crawls and analyzes URLs
- Stripe - payment processing for paid subscriptions
- Resend - transactional email delivery
- Reddit - conversion measurement for Reddit ads, when a campaign is running (see Cookies below)
- GitHub - OAuth sign-in and the RankCLI GitHub App, if you connect a repository
- Google - sign-in with Google, and the Search Console API if you connect Search Console
Each of these providers processes data only as needed to provide their part of the Service, under their own privacy and security practices.
Google Search Console
If you connect Google Search Console to a project, RankCLI asks Google for read-only access to your Search Console data (the webmasters.readonly scope) and your Google account's email address. We use it only to show that project's search performance in your dashboard: the list of your Search Console properties (so you can pick the right one), and for the chosen property the last 28 days of clicks, impressions, click-through rate, average position, top queries and top pages, refreshed daily.
Your Google tokens are encrypted (AES-256-GCM) at rest and used only server-side; they are never sent to your browser. We don't read other Google data, don't share Search Console data with anyone, and don't use it for advertising or to train AI models. Disconnecting in the project page revokes RankCLI's access at Google and deletes the tokens; you can also remove access at any time at myaccount.google.com/permissions.
RankCLI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
GitHub App permissions
If you install the RankCLI GitHub App, it requests read access to repository contents (to detect your framework and generate accurate fixes) and write access to pull requests and branches (to open auto-fix PRs). It does not access repositories you haven't explicitly installed it on, and you can revoke access at any time from your GitHub account settings.
Cookies
The dashboard uses essential cookies/local storage to keep you signed in. We count page views with Cloudflare Web Analytics, which sets no cookies and doesn't track you across sites.
When we are running ads on Reddit, the marketing pages also carry Reddit's conversion pixel, which is a third-party advertising tracker: it records that a visit or a signup followed a Reddit ad, and it can be used to build a retargeting audience. Reddit requires it on every ad group, so it is the condition of advertising there at all rather than something we added for its own sake. It is never present on a build where it has not been deliberately configured, and it is not loaded in the dashboard. You can check whether it is active on any page by searching the page source for redditstatic.com/ads/pixel.js.
Data retention and deletion
We retain account and audit data for as long as your account is active. You can delete your account at any time from Account settings, which removes your projects, audit history, and any connected AI provider keys. Some records may be retained briefly afterward where required for billing records or fraud prevention.
Children's privacy
The Service is not directed at children under 16, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by updating the date at the top of this page.
Contact
Questions about this policy or your data can be sent to support@rankcli.dev.