Privacy Policy
Last updated July 16, 2026
1. What we collect
- Account data. Your name, e-mail, and avatar from Google sign-in, and your workspace membership.
- Workspace content. The sites, keywords, briefs, articles, and campaigns you or your agent create.
- Connected services. OAuth tokens for Google Search Console and credentials for the CMS integrations you connect. Credentials and tokens are encrypted at rest and never shown again after setup.
- Outreach data. Prospect contact details gathered from public sources for campaigns you approve, plus reply threads on the dedicated sending inbox.
- Usage data. API activity, feature usage, and per-call cost metering that powers your usage dashboard. Session cookies keep you signed in; we set no third-party advertising cookies.
2. How we use it
Only to run the product: researching keywords, drafting and publishing your content, tracking rankings, sending the digests you opt into, running the outreach you approve, billing, and keeping the service safe. We don’t sell personal data, and we don’t use your content to train models.
3. Google Search Console data
If you connect Search Console, we read search-performance and indexing data for your verified sites to show trends and suggest keywords. Use of this data complies with the Google API Services User Data Policy, including its Limited Use requirements: it is shown to you, powers your workspace’s suggestions, and is never sold or used for advertising. Disconnecting removes our access and deletes the stored tokens.
4. Outreach recipients
When you run a link-building campaign, we process professional contact information (name, role, work e-mail) about the site owners and editors being pitched, sourced from public pages and contact discovery providers. Every message identifies the sender, includes a working unsubscribe, and opt-outs go on a global suppression list that all future campaigns honor. If your details reached this list and you want them removed entirely, write to us at the address below.
5. Processors we rely on
We share data with the vendors that operate parts of the service, and only what each needs: Google (sign-in, Search Console), Stripe (payments; we never store card numbers), Anthropic (article drafting and reply classification), DataForSEO and similar search-data providers (keywords and rankings), AgentMail (outreach inboxes), Resend (product e-mail), and our hosting providers (AWS, Neon) for infrastructure. Each processes data under its own contractual safeguards.
6. Retention and deletion
We keep workspace data while your account is active. When you delete your account, or on request, we delete personal data within 30 days, except records we must keep for legal or billing reasons. Suppression entries are kept so opt-outs stay honored.
7. Your rights
You can access, correct, export, or delete your personal data. Where GDPR or similar laws apply, you also have the rights to restrict or object to processing and to lodge a complaint with your supervisory authority. E-mail support@uprank.so and we’ll respond within 30 days.
8. Security
Credentials and tokens are encrypted at rest, API keys are stored only as hashes, transport is TLS everywhere, and access to production data is limited and logged. No system is perfectly secure; if a breach affects you, we’ll notify you without undue delay.
9. Children and changes
Uprank is a business tool and not directed at anyone under 16. If this policy changes materially, we’ll tell you by e-mail or in the dashboard before the change takes effect.