OrganicRank

Privacy Policy

Last updated 28 August 2026

We analyse public pages on the domain you give us. Where you connect Google or GitHub, we use the minimum access that makes the product work, and we do not store your Google credentials at all.

Who we are

OrganicRank is an SEO analysis service operated at organicrank.ai. Questions about anything on this page go to hello@organicrank.ai, and we answer them.

What we collect

Three kinds of thing, and it is worth separating them because they carry very different weight.

Public pages on the domain you analyse
We fetch pages the same way a search engine would - titles, headings, meta tags, link structure, response times, page weight. This needs no permission from you and gives us nothing a crawler could not already see. It is what the preview is built from.
The report we produce
The analysis, the findings and the plan, stored against a report identifier so you can come back to it. Reports are held for 90 days unless the domain has an active subscription, in which case they are kept for as long as that subscription runs.
What you connect
If you connect Google Search Console or a GitHub repository, we read what those connections are for and nothing else. Both are covered in their own sections below.

Google user data

When you verify a domain with Google Search Console, we ask Google for one permission: read-only access to Search Console (webmasters.readonly). We do not request write access, and we cannot change anything in your Search Console account.

We use it for two things. First, to confirm the domain is yours - Search Console already made you prove that, so asking Google is stronger evidence than a file we could ask you to place, and less work for you. Second, to read the queries and pages your site already ranks for, so the plan we build is corrected against what is actually happening rather than what we guessed.

Your Google access token is never written to storage. It is used in memory during the connection and discarded when the request ends. That means we cannot read your Search Console data later, in the background, or after you close the tab - if we need it again, you connect again.

What we keep from the connection is the search performance figures relevant to your report, held with the report itself, and a record that the domain was verified and by which Search Console property. Nothing from your Google account is sold, shared, or used for advertising, and nothing is used to train a model.

You can revoke our access at any time from your Google account permissions page, which takes effect immediately and needs nothing from us.

GitHub data

If you connect a repository so we can open pull requests, we store an access token server-side. It is a live credential against your code, so it is worth being exact about what it does.

We use it to read the repository structure, to create a branch, to write changes to that branch, and to open a pull request. We never push to your default branch and we never force-push. Every change arrives as a diff you review and merge, or do not.

Disconnecting deletes the token from our storage. That does not revoke it at GitHub - only you can do that, from your GitHub settings - so if you want it fully dead, revoke it there too. We would rather say this plainly than let you assume otherwise.

Payments

Payments are handled by Stripe. Card details are entered on Stripe's systems and never reach ours - we hold a subscription record and a customer reference, not a card number.

What we do not do

We do not sell your data. We do not share it with advertisers. We do not use your site's content or your Search Console figures to train a model. We do not email you because you ran a free audit - the preview asks nothing of you, and it is meant to stay that way.

How long we keep things

Reports for 90 days, or for the life of a subscription on that domain. Verification records for as long as the domain stays verified, so you do not have to prove it again from a new browser. GitHub tokens until you disconnect. Google access tokens for the length of a single request.

Your rights

Ask us for a copy of what we hold on you, or ask us to delete it, and we will - write to hello@organicrank.ai. If you are in the UK or EU, that is your right under GDPR; if you are not, we will do it anyway, because the alternative is arguing about geography over something we should just do.

Changes

If this policy changes in a way that affects what we do with your data, the date at the top changes and the change is described here rather than quietly absorbed.