Privacy Policy
Last updated: 26 August 2026
RankSite ("RankSite", "we", "us") provides an AI website builder and publishing platform at app.ranksite.ai. This policy explains what personal data we process, why, who we share it with, and the rights you have. It applies to our dashboard, our APIs, and the websites we publish on your behalf.
Who is responsible for your data
For your account data, RankSite is the data controller. For the business content you publish through RankSite — including any customer enquiries you collect on your published site — you are the controller and RankSite acts as your processor.
Privacy contact: support@wordrocket.ai.
Data we process
- Account data — email address, name (if provided), password hash, sign-in timestamps.
- Billing data — plan tier, purchase date, Stripe customer and payment identifiers. We never see or store your full card number.
- Site and content data — business profile details you enter (business name, address, phone, services, locations), generated pages and blog posts, uploaded images, fonts and logos.
- Integration credentials — API keys you choose to connect (for example OpenRouter or WordRocket). These are stored server-side, are never returned to your browser, and are used only to run the jobs you request.
- Usage data — feature usage counters, publish history, indexing requests, and error logs used to operate and debug the service.
- Visitor data on published sites — if you enable the site chat assistant, visitor questions are stored so you can review them. If you enable analytics or advertising scripts, those third parties process visitor data under their own terms.
Why we process it (legal bases)
- Contract — to create your account, generate and publish your websites, connect domains, and apply plan limits.
- Legitimate interests — security, abuse prevention, rate limiting, product improvement, and support.
- Legal obligation — tax, accounting, and responding to lawful requests.
- Consent — marketing emails, and any optional cookies or tracking on published sites.
AI processing and automated content
RankSite uses third-party large language models to draft website copy, blog posts and images from the inputs you provide. Content is generated automatically and may contain inaccuracies — you are responsible for reviewing anything before it goes live. We do not use your content to train our own models, and the AI providers we use are instructed to process your prompts only to return a result. No automated decision-making with legal or similarly significant effects on you takes place.
Subprocessors
We share the minimum data needed with the following processors:
- Supabase / Lovable Cloud — application hosting, database, authentication, file storage.
- Netlify — hosting and CDN delivery of your published websites.
- Railway — the build service that compiles your site before deployment.
- Stripe — payment processing and receipts.
- OpenRouter — routing to AI text and image models.
- WordRocket — optional AI blog generation engine.
- Google (Indexing / Search Console APIs) — submitting your published URLs for indexing when you request it.
- Email delivery provider — transactional emails such as password resets.
Some processors operate outside the EEA/UK. Where that happens, transfers rely on Standard Contractual Clauses or an equivalent safeguard.
Retention
Account, site and content data is kept for as long as your account is active. If you delete a site, its content is removed from our database and from the next deployment. If you delete your account, we remove your personal data within 30 days, except records we must keep for tax and accounting purposes (typically 7 years) and backups that expire on their own schedule. Chat-assistant visitor questions are kept for up to 12 months.
Security
Data is encrypted in transit (TLS) and at rest. Access to customer data is restricted by row-level database policies so one account cannot read another's sites, media or content. Integration API keys are write-only from the dashboard and are never sent back to the browser. Scheduled and internal endpoints authenticate with dedicated secrets, and public endpoints are rate limited.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. You can delete your account and data from the dashboard at any time, or email us and we will respond within 30 days. You may also lodge a complaint with your local data protection authority.
Cookies
The RankSite dashboard uses only essential cookies and local storage needed to keep you signed in. Websites you publish include a cookie-consent banner by default; if you add analytics or advertising scripts to a published site, you are responsible for configuring consent appropriately for your audience.
Changes
We will update this page when our processing changes and revise the date above. Material changes will be announced by email or in the dashboard. See also our Terms of Service.