Legal
Privacy policy
What we collect, why, who else sees it, and how to make us delete it.
Last updated 30 September 2026
The short version
- We collect what we need to run your account and nothing for resale.
- We never sell your data and never train AI models on your projects.
- Analytics record what was clicked, not what was typed.
- Ask us to delete your account and we delete it.
Who is responsible
Nextrank is operated by its founder, an individual, until a company is formed to run it (see the terms). That operator is the controller of the personal data described here. When a company takes over, it becomes the controller under this same policy and we will tell you by email. Contact: support@trynextrank.com.
What we collect
| Data | Why (legal basis) |
|---|---|
| Email address, name, profile image (from Google sign-in, if you use it) | To sign you in and address you correctly (contract) |
| Organisation, members, projects, keywords, tags, trackers, project briefs | They are the service (contract) |
| Hashed API keys and the time each was last used | To authenticate API and MCP requests (contract) |
| Credit ledger and subscription state | Billing, and so you can audit what you were charged (contract, legal obligation) |
| Server logs with a request id, organisation id and user id | Security and diagnosing failures (legitimate interest) |
| Product analytics events, error reports, masked session replays | Working out what is confusing or broken (legitimate interest; see Cookies) |
| Support emails you send us | To answer you (contract, legitimate interest) |
| Product emails: sign-in links, rank reports, and a small number of onboarding and account messages. Optional reminders carry an unsubscribe link and can be switched off in Settings → Notifications | Delivering the service (contract, legitimate interest) |
What we deliberately do not collect
Analytics events never carry keyword phrases, project domains or email addresses. Session replay masks every input and all text content. The keyword you researched is your business intelligence, and it stays in your account rather than in an analytics product.
We do not process card details or store them. Payment happens on Polar’s systems, not ours.
Google user data and Search Console
You can sign in with Google, which gives us your email address, name and profile image. If you connect Google Search Console, we additionally request read-only access (the webmasters.readonly scope) to the properties you choose. We use that data only to show your clicks, impressions, queries and pages inside Nextrank and to surface quick-win keyword opportunities for your organisation’s members. We never request write access and never modify your Search Console settings.
Nextrank’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train generalised AI or machine-learning models, and do not allow humans to read it except with your permission, for security or abuse investigation, or where the law requires. We do not send it to DataForSEO, PostHog or any other party listed below, apart from the hosting and database infrastructure that stores it. You can disconnect at any time from your project settings, which revokes our access immediately, or from your Google account permissions.
Website audits
When you run a site audit, our crawler (NextrankAuditBot) fetches pages from the site you specify, obeys its robots.txt and rate-limits itself. We store what we find (URLs, status codes, titles, headings, links and similar page metadata) in your account. Anyone who wants us to stop crawling a site can disallow NextrankAuditBot in robots.txt or email us; see about the crawler.
Using the API and MCP server
If you connect the service to an AI assistant, it sends requests using your API key and receives the results. What that assistant’s provider does with those results is governed by that provider’s terms. We never see the prompts you write to your assistant. We record when a key was last used and, for a few events such as hitting a credit or plan limit, a product analytics event without your keywords.
Who else sees it
These providers process data for us. Each is bound by contract to use it only to provide its service.
| Provider | What for | What it receives |
|---|---|---|
| DataForSEO | Search data | The keyword and market of each query. Not your identity or account. |
| Polar (United States) | Merchant of record, payments, receipts, tax | Your billing details and email |
| Resend (United States) | Sign-in links and email delivery | Your email address and message content |
| PostHog (United States) | Product analytics and masked session replay | Usage events tied to a pseudonymous id, plus your user id once signed in |
| Sentry (United States) | Error tracking | Error details, request and organisation ids |
| Google (United States) | Sign-in and Search Console access, when you choose them | As described above |
| Our hosting provider (European Union) | Servers and database | Everything stored in your account |
| ImprovMX and Google Workspace/Gmail (United States) | Receiving and answering support email | Emails you send to support@trynextrank.com |
We may also disclose data if the law or a valid legal request requires it, and to a successor if the service is transferred to a company (see the terms). Nobody else, and no advertising networks.
International transfers
Our servers are in the European Union, but several providers above are in the United States. When personal data from the EU, UK or Switzerland is transferred there, we rely on the provider’s certification under the EU-US Data Privacy Framework where it has one, or on standard contractual clauses in its data processing terms.
Cookies and similar storage
- Session cookie (essential) so you stay signed in.
- Theme preference (essential) for light or dark mode.
- Analytics cookie and local storage (PostHog, first-party, shared between this site and the app) so a visit and a later signup are recognised as the same person, and to run masked session replay.
No third-party advertising cookies and no ad networks. If you are in the EU or UK and do not want the analytics cookie or replay, email us and we will exclude you, or block the PostHog domain in your browser; the service works the same without it.
How long we keep things
- Account and project data: until you delete it or close the account
- Ranking history: 30 days to forever, depending on your plan
- Credit ledger: seven years, because it is a financial record; after you delete your account it is kept without your name and email
- Server logs: up to 30 days
- Analytics, replays and error reports: for the retention period set with each provider
- Support email: as long as needed to help you, then deleted
Your rights
You can export your keyword lists and rankings as CSV from the product at any time. Email support@trynextrank.com to request access, correction, deletion, restriction, objection to processing, or a machine-readable copy of your data, and we will respond within 30 days (extendable by up to two further months for complex requests, and we will tell you if so). We may need to confirm it is you first.
If you are in the UK or EU you also have the right to complain to your data protection authority. If you live in California or another US state with a privacy law, you have similar rights to know, delete and correct, and not to be discriminated against for using them. We do not sell or share personal data for advertising.
Security
Everything travels over TLS. API keys are stored only as hashes, and shown once when you create them. There are no passwords to leak: you sign in with a link emailed to you or with Google. The application runs with a restricted database role that cannot rewrite or delete the credit ledger. Access to production is limited to the people who need it. No system is perfectly secure; if a breach affects your data we will notify you without undue delay, and the authorities where the law requires.
Children
The service is not for anyone under 16. If you believe a child has given us data, email us and we will delete it.
Changes
If we change this policy in a way that matters, we will tell you by email or on the changelog before it takes effect. The date at the top shows when it was last updated.
Contact
support@trynextrank.com — or read the terms of service and refund policy. Business customers who need a data processing agreement can ask for one at the same address.