Privacy Policy

Last updated: October 8, 2026

Who is responsible

  • Controller: PANDOR LAB, LLC, a limited liability company organized under the laws of the State of Delaware, USA
  • Postal address: [to be completed]
  • Privacy contact: [to be completed]
  • Representative in the European Union (GDPR art. 27): [to be completed]
  • Representative in the United Kingdom (UK GDPR art. 27): [to be completed]

We have not appointed a data protection officer: the thresholds of GDPR art. 37 are not met. The legal notice gives our full details.

What this policy covers

This policy covers the Rankeero website, the dashboard, the MCP endpoints and the page where you authorize an AI app (the consent page).

It does not cover:

  • what your AI client (Claude, ChatGPT, Codex or another) does with the data it receives: its provider processes it under its own policy;
  • what Polar does as the seller of your subscription, described in Polar’s privacy policy;
  • what Google does with your Google account, described in Google’s privacy policy.

Data we process

We process the personal data below. Search Console and Google Analytics data have their own section.

DataSourcePurposeLegal basisRetention
Account: your name, your e-mail address, whether Google verified it, and your Google account id. We do not store the tokens Google issues at sign-in, nor your profile picture.Google, when you sign inIdentify you, and show you to the members of your workspacesContractUntil you delete your account
Sessions: the session token, your IP address, your browser’s user agent, and the session’s times. Rate-limit counters keyed by IP address.Your browserKeep you signed in, and protect sign-in against abuseContract; legitimate interests (security)Sessions: until they expire. Counters: 24 h after the last request.
Google connections: the Google account’s e-mail address and id, the scopes granted, a refresh token sealed with AES-256-GCM, and the connection’s statusGoogle, when you connect a Google accountRead Search Console and Google Analytics for the projects of your workspacesContractUntil you remove the connection or delete your account
Workspaces: the name, the random identifier in its addresses, the members and their roles, the projects (their names, and whether each is enabled), each project’s sources (the product, the source identifier, such as a Search Console or Google Analytics property id, and the Google connection it reads through), and invitations (the invitee’s e-mail address, the role and the inviter)You and the other membersRun the workspace and its projectsContract; for invitees, the inviting workspace’s legitimate interestsUntil the workspace is deleted. Projects and sources: until they are removed. Invitations: 30 days after they expire.
API keys: a hash of the key, its first characters, its name, its dates and its usage countRankeero, when you create a keyAuthenticate the scripts and agents you give a key toContractUntil revoked. Expired keys: 30 days after they expire.
Authorized AI apps: the app’s address and name, your consents (scopes and workspace), and hashed tokensThe AI app, and your consentLet the AI apps you authorize call the toolsContractTokens: 7 days after they expire or are revoked. Consents: until you revoke them or delete your account.
Usage records: who called which tool, with which key or app, for which workspace, provider and project, the status, the duration, the time, and any error text (which can quote Google’s message, or, when Rankeero refuses a Google Analytics request, name some of the property’s dimensions and metrics). Never the tool’s arguments or results, except where an error message repeats an argument (such as a date).Rankeero, when a tool is calledShow the last call, troubleshoot, and detect abuseLegitimate interests (security and support)90 days
Billing records: Polar customer and subscription ids, the plan and its billing interval, the status, the period dates, and the payer of each workspace with its position in that payer’s order. Never card data.Polar, and Rankeero for each workspace’s payer and position, set when the workspace is created or its billing is taken overGrant the plan you pay forContractUntil you delete your account; a workspace’s payer and position, until the workspace is deleted
Request logs: the method, the address without its query string, the status, the timing and the errors of each requestCloudflare, which hosts RankeeroOperate and secure the serviceLegitimate interests (security)[to be completed] days
Support e-mails: your messages and our repliesYouAnswer youContract or legitimate interests24 months after the last exchange

Search Console and Google Analytics data

Rankeero reads, for the properties that your workspaces’ projects use as sources, their Search Console data (performance reports, URL inspection, sitemaps) and their Google Analytics data (reports over the dimensions and metrics the property offers, for example on sessions, users, engagement, key events and revenue, and the property’s settings: its time zone, currency, key events, web streams and the names of its dimensions and metrics). It also reads the list of properties a connected Google account can see in each product:

  • only when an AI client calls a tool, when you list the properties of your own Google accounts (to create a workspace or add projects), when an owner or admin saves a project’s source, or when the dashboard checks the projects’ status;
  • to return the result to the client or the page that asked for it.

Rankeero never writes this data to its database, apart from the identifiers of the properties chosen as sources; for a project created from a Google Analytics property, its display name as the project’s name, which you can change; and, in the usage records, the error text of a refused request, which can name some of a Google Analytics property’s dimensions and metrics. It never keeps report data beyond the request. On our servers, a project’s status and the list of an account’s Search Console properties are kept for 30 seconds, the list of an account’s Google Analytics properties (their names, accounts and website host names) for 5 minutes, and a Google Analytics property’s name, time zone, currency and field names for one hour; none of them holds report data.

Purposes and legal bases

  • Providing the service (sign-in, workspaces and projects, connections, keys, AI apps and tools): the performance of our contract with you, GDPR art. 6(1)(b).
  • Security, rate limits and logs: our legitimate interests in protecting Rankeero and its users against abuse and attacks, art. 6(1)(f).
  • Billing through Polar: the performance of the contract.
  • Support: the performance of the contract, or our legitimate interest in answering you.
  • Legal obligations, such as answering an authority: art. 6(1)(c).

We do no marketing, no advertising and no profiling, and we take no decision about you by automated means. You need a Google account to use Rankeero: without the account data above, we cannot provide the service. Where you give your consent, such as when you authorize an AI app, you may withdraw it at any time by revoking the app.

Google user data

  • Scopes. To sign you in, Rankeero asks Google for openid email profile. To connect a Google account, it asks for openid email, https://www.googleapis.com/auth/webmasters.readonly and https://www.googleapis.com/auth/analytics.readonly, to read Search Console and Google Analytics for the properties that a workspace’s owners and admins choose as its projects’ sources. Google lets you grant either product alone; Rankeero then reads only that one.
  • Use. Google user data is used only for user-facing features: signing you in and showing your name and e-mail address to the members of your workspaces, the tools your AI clients call, the list of your accounts’ properties when you create a workspace or add projects, and the projects’ status.
  • What we never do. We do not sell Google user data, do not use it for advertising, and do not use it to train or improve artificial intelligence or machine learning models. We keep no permanent copy of Search Console data, and Google Analytics data is read on request and never stored, apart from the identifiers of the properties chosen as sources; for a project created from a Google Analytics property, its display name as the project’s name, which you can change; and, in the usage records, the error text of a refused request, which can name some of the property’s dimensions and metrics.
  • Transfers. We transfer Google user data only to the members of your workspaces and the AI clients they authorize, to provide the features above; to our processors, to run the service; for security, or to comply with the law; or in a merger or acquisition, after asking for your prior consent.
  • Human access. No one at Rankeero reads your Google user data, unless you agree (for example, for a support request), for security, or when the law requires it.
  • Revocation. Revoke Rankeero’s access at any time at myaccount.google.com/connections. In the dashboard, you can remove a Google account once no workspace you belong to uses it.

Our statement on Google’s Limited Use requirements:

Rankeero's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Sharing within your workspace

  • Each source of a project reads Search Console or Google Analytics through the Google account of one member: the member whose account was chosen for that source.
  • Every member of the workspace, the API keys they create and the AI clients they authorize can then read that property’s data through that account. The projects of a workspace are not isolated from each other: a member who can use one can use them all.
  • Members see each other’s names and e-mail addresses.
  • The sharing stops when that member leaves or is removed from the workspace, when an owner or admin removes or disables the project or its source or connects another Google account to that source, or when that member revokes Rankeero’s access in their Google Account. Rankeero checks that membership on every request.

Rankeero shows this next to the list of properties, before a property becomes a source.

Your AI clients

When an AI client calls a tool, Rankeero sends the result to that client. Your workspace’s members choose and authorize these clients, and their providers (such as Anthropic or OpenAI) process the results under their own terms and policies, not ours. See also the Terms of Service.

Recipients

  • Cloudflare, Inc. hosts Rankeero and keeps its request logs.
  • Neon, a Databricks, Inc. company, hosts the database. Location: [to be completed].
  • Google signs you in and serves the Search Console and Google Analytics APIs, under its own terms.
  • Polar Software, Inc. sells the subscriptions, as our reseller and merchant of record. Rankeero sends Polar only your user id (external_customer_id). You give your name, e-mail address and payment details to Polar directly, on its checkout page.
  • Authorities, where the law requires it.
  • A successor, in a merger or acquisition; Google user data only with your prior consent.

We do not sell personal data, and do not share it for cross-context behavioral advertising.

International transfers

PANDOR LAB, LLC is a US company: your data is processed in the United States and on Cloudflare’s global network. Where Chapter V of the GDPR applies, transfers rely on the EU-US Data Privacy Framework (Cloudflare is certified, and so are Databricks, Inc. and Neon, LLC: see Databricks’s certification), and on the standard contractual clauses of the Cloudflare and Polar data processing agreements. Write to [to be completed] for a copy of these safeguards.

How long we keep data

  • Account: until you delete it. Deleting your account also deletes your sessions, connections, keys and usage records, and the workspaces where you are the only member.
  • Sessions: a session lasts 7 days and is extended while you use it. It is deleted once expired.
  • Sign-in and connection states: deleted once expired, minutes after they are created.
  • Rate-limit counters: 24 h after the last request.
  • Invitations: 30 days after they expire, whatever their status.
  • API keys: deleted as soon as they are revoked. Expired keys: 30 days after they expire.
  • Authorized AI apps: authorization codes expire after 10 minutes, access tokens after 1 h, and refresh tokens 30 days after their last use. Expired or revoked tokens are deleted 7 days later. Consents last until you revoke them or delete your account.
  • Usage records: 90 days.
  • Google connections, workspaces, projects and sources: until they are removed, or until the account or the workspace is deleted.
  • Billing records: until they are removed, or until the account or the workspace is deleted.
  • Support e-mails: 24 months after the last exchange.
  • Database backups: deleted data leaves the backups within [to be completed] day(s).
  • Request logs: [to be completed] days.

A daily job deletes expired records, so one may stay up to a day longer than stated. Polar keeps its own records, such as invoices, under its policy and tax law.

Cookies and browser storage

Rankeero uses only the cookies and browser storage below. They keep you signed in, secure the sign-in, remember your interface choices, or keep the service you asked for working. There are no analytics, advertising or third-party trackers, so there is no consent banner: these uses are exempt from consent under the ePrivacy rules (art. 5(3) of Directive 2002/58/EC).

NameKindLifetimePurposeCategory
better-auth.session_tokenHttpOnly cookie7 daysKeeps you signed inAuthentication
better-auth.session_dataHttpOnly cookie5 minutesCaches your sessionAuthentication
better-auth.stateSigned cookie5 minutesProtects the Google sign-in against forgerySecurity of authentication
PARAGLIDE_LOCALECookie400 daysRemembers your languageInterface preference
sidebar_stateCookie7 daysRemembers whether the dashboard’s sidebar is openInterface preference
rankeero-themelocalStorageUntil clearedRemembers your light or dark themeInterface preference
rankeero:last-orglocalStorageUntil clearedRemembers the workspace the dashboard shows by defaultInterface preference
tsr-scroll-restoration-v1_3sessionStorageUntil the tab is closedRestores your scroll position when you return to a pageInterface preference
tanstack_router_reload:…sessionStorageUntil the tab is closedReloads the page once when an update of Rankeero has replaced its codeService you asked for

Over HTTPS, the three better-auth cookies carry the __Secure- prefix. Signing out deletes the session cookies. To remove everything, clear this site’s cookies and site data in your browser’s settings: you are then signed out, and your preferences are reset.

Security

  • All traffic uses HTTPS.
  • Google refresh tokens are sealed with AES-256-GCM. API keys and AI app tokens are stored only as hashes.
  • A Content Security Policy blocks third-party scripts and requests.
  • Membership is checked on every MCP request, and requests are rate-limited.

No system is perfectly secure, and we cannot guarantee absolute security. Report vulnerabilities to [to be completed].

Your rights

Depending on where you live, you have the right to access, rectify and erase your data, to restrict or object to its processing, and to receive it in a portable format.

  • In the dashboard: delete your account, remove Google connections, and revoke API keys and authorized AI apps.
  • By e-mail: write to [to be completed]. We check your identity and answer within one month.

You may also complain to your data protection authority; in France, the CNIL.

US privacy rights

  • We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics about you.
  • Residents of US states with privacy laws, such as California, may ask to know, correct or delete their personal information by writing to [to be completed]. We do not treat you differently for exercising these rights.
  • Do Not Track: Rankeero does not track you across other sites, and no third party collects data about you across sites through Rankeero. Do Not Track signals therefore change nothing.

Children

Rankeero is for people aged 18 and over. We do not knowingly collect children’s data. If you believe a child has given us data, write to [to be completed] and we will delete it.

Changes to this policy

We publish every change on this page, with a new date and an entry in its history. We announce material changes at least 30 days before they take effect, by e-mail to your account’s address and in the dashboard. We use Google user data in a new way only after updating this policy and asking for your consent in Rankeero.

Contact

  • Privacy questions and requests: [to be completed]
  • Security reports: [to be completed]
  • Anything else: [to be completed]
  • By post: PANDOR LAB, LLC, [to be completed]

History

  • 2026-10-08: The service is renamed Rankeero (formerly Pithos). Cookies: the two browser storage keys take the new name (rankeero-theme, rankeero:last-org); nothing else changes.
  • 2026-10-08: Billing records: trial dates are no longer listed, since plans no longer include a free trial.
  • 2026-10-07: Billing records: the number of billed workspaces is no longer recorded. They now include the plan’s billing interval and each workspace’s position in its payer’s order; Rankeero records a workspace’s payer and position when the workspace is created or its billing is taken over, and keeps them until the workspace is deleted. The cookies table no longer lists the storage key of a new workspace’s draft, which Rankeero never used.
  • 2026-10-02: Workspaces: the stored data now includes projects and their sources (such as Search Console property ids), and the sharing section covers every project of a workspace. Google Analytics: connecting a Google account can also grant read-only access to Google Analytics, whose data Rankeero reads on request and never stores, apart from the identifiers of the properties chosen as sources and, for a project created from a Google Analytics property, its display name as the project’s name, which you can change, and the error text of a refused request, which can name some of the property’s dimensions and metrics; the list of an account’s Google Analytics properties is kept on our servers for 5 minutes. The billing records are unchanged.
  • 2026-09-30: First version.