Privacy
Last updated: 29 July 2026
The short version: RankGoat collects what it needs to publish blog posts on your site and build backlinks to it, and nothing else. We don't sell your data, we don't run ads, and we don't train AI models on it.
What we collect
- Your account. Your email address, and your name and profile picture if you sign in with Google. Optionally your X handle, if you give us one at signup.
- Your sites. The domains you add, plus whatever we can read from their public pages: your niche, your keywords, your brand name, your product angles, page titles and meta descriptions. That's the same content any visitor or search engine crawler can see.
- Your content. The briefs, posts, images and translations we generate for you, and any edits you make to them.
- Search Console data, if you connect it: the queries, clicks, impressions and positions for the property you pick. We use it to choose keywords worth writing about.
- Billing status from Stripe: which plan you're on, whether it's paid, when it renews. We never see or store your card number.
- Publishing credentials, if you use them: your webhook URL and secret, or your WordPress URL, username and application password. Stored so we can publish on your behalf.
- Logs. Request and error logs, and a record of every AI call we make for you, kept for debugging and for showing you what happened.
Cookies
Four, all functional, none for advertising:
bb-sessionkeeps you signed in.bb-siteremembers which of your sites you're looking at.g-oauth-stateandgsc-oauth-stateare short-lived security tokens used during Google sign-in and Search Console connection. They're deleted as soon as the flow finishes.
Analytics
Two tools run on the public site and in the app, both in production only:
- Plausible, self-hosted on our own server. Cookie-free, no personal data, no cross-site tracking.
- Microsoft Clarity, which records anonymised session replays and heatmaps so we can see where the app confuses people. If you're signed in, we tag your session with your email so we can connect a bug report to what actually happened on screen. Clarity masks text input by default. You can opt out of Clarity with your browser's Do Not Track setting or by blocking
clarity.ms.
Google Search Console data
If you connect Search Console, we ask for read-only access to your search analytics and the list of properties you own. We use it for one thing: picking keywords and measuring how your posts perform. We don't use it for anything else, we don't train models on it, and we don't pass it to anyone. RankGoat's use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Revoke access any time at myaccount.google.com/permissions, or disconnect from the GSC page in the app.
How long we keep it
For as long as your account is open. Ask us to delete it and we delete your account, your sites, your posts and your credentials. Two things survive: posts already published on other members' sites (they belong to those site owners now), and billing records we're required to keep for tax purposes.
Your rights
You can ask us to show you your data, correct it, export it, or delete it. You can object to how we use it. We'll do it, and we won't make you fill in a form.
Security
Everything runs over HTTPS. Publishing credentials and OAuth tokens are stored on our server with access limited to the code that needs them. We're a small operation, not a bank - we've done the sensible things, and we'd rather tell you that plainly than claim a certification we don't have.
Children
RankGoat is a business tool and isn't intended for anyone under 16.
Changes
If we change something that matters, we'll update the date at the top and tell members by email.
Questions
Message @woocassh on X, or just reply to any email RankGoat has sent you. Both reach the same person.