Privacy Policy
Effective July 28, 2026
This policy explains what RankTruck collects, why, and who touches it. The short version: we collect what the product needs to do its job for your business, we do not sell it, and we do not use it for advertising.
What we collect
- Your account: name, email address, and a hashed password. We never store the password itself.
- Your business profile: the details you enter during setup, such as services, cities, phone and website.
- Notes you choose to add: writing samples and local knowledge used to draft your content.
- Performance data the service gathers for you: search rankings, reviews and their text, listing details, website health results, backlink counts, and analytics from accounts you connect.
- Operational records: logs of the jobs your instance runs and the service’s own usage costs.
Google account access
If you connect Google services, you do so on Google’s own consent screen and can revoke access at any time at myaccount.google.com. We store the resulting tokens on your instance and use them only for the features you connected: reading Search Console data, reading Analytics data, and managing your Business Profile. Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Where your data lives
Each customer runs on their own isolated instance with their own database, hosted in the United States on encrypted storage. Your data is never mixed with another customer’s. Backups are taken continuously and stored encrypted.
Who processes data for us
We use a small set of providers to run the service. Each receives only what its role requires:
- Fly.io hosts your instance (US regions).
- Cloudflare stores encrypted backups.
- Anthropic processes drafting requests when the service writes content for you.
- Google provides the APIs for the services you connect.
- DataForSEO performs the search-result lookups behind rank tracking.
- Twilio delivers SMS alerts, if you choose SMS alerts.
- Pexels supplies stock photography for posts.
- OpenStreetMap’s geocoder converts your city names to map coordinates once, during setup.
We do not sell your data, share it with advertisers, or use it to train models.
Cookies
The service uses one session cookie to keep you signed in. There are no third-party tracking cookies and no advertising pixels.
How long we keep things
- Raw search-result payloads are pruned after 90 days; the ranking history built from them is kept so your charts stay complete.
- Everything else is kept while your account is active, because it is the working data of your instance.
- Thirty days after your account ends, your instance and its backups are deleted. Before then, ask and we will give you a full export.
Your choices
- Export: request a copy of your data at any time.
- Deletion: cancel and your data is deleted on the schedule above, or ask us to delete sooner.
- Google access: revoke at myaccount.google.com whenever you like; the connected features simply stop.
- Alerts: choose where alerts go, or turn them off.
Changes
If this policy changes in a way that matters, we will email you before the change takes effect.
Contact
Privacy questions: cameronbetz7@gmail.com.