The 30-second summary
- What we store: account info, project data you create, audit results, AI fix outputs, payment metadata (via Stripe).
- What we never sell or share: any of it.
- What we never train AI on: your private project data.
- Your rights: view, export, correct, or delete everything at any time.
1. Data we collect
When you create an account: full name, email, optional phone, password (hashed), language preference, IP and user-agent (security/fraud detection).
When you use Outerank: websites you add, keywords you research, audit results, content you generate, outreach drafts.
When you pay (via Stripe): card details are stored by Stripe, not us. We see only: country, last 4 digits, subscription status.
2. Why we collect it
- To provide the Service you signed up for.
- To detect abuse and security threats (rate-limiting via IP).
- To send essential account emails (verification, password reset, billing).
- To improve Outerank — but only via anonymized, aggregate analytics.
3. Third parties we use
- Anthropic (Claude API) — generates audit fixes, content, outreach. Prompts are not retained for training by Anthropic.
- Resend — sends our transactional emails (verification, notifications).
- Cloudflare — DNS, CDN, email routing.
- Stripe — handles payments (will be added once payments are live).
Each is bound by data-processing agreements; none of them sell your data.
4. Cookies & tracking
We use essential cookies for login sessions only. We do not use third-party advertising cookies or fingerprinting. When we add analytics (Plausible or similar), it will be cookieless and GDPR-compliant.
5. Your rights (GDPR + CCPA)
- Access — request a full copy of your data anytime.
- Correction — fix any incorrect data from Settings or by emailing us.
- Deletion — delete your account and all associated data permanently from Settings → Account.
- Portability — export your audits, keywords, content as CSV / JSON.
- Objection — opt out of any non-essential email at any time.
To exercise any right, email support@outerank.com. We respond within 30 days.
6. Data retention
- Active accounts: stored as long as your subscription is active.
- Cancelled accounts: deleted within 30 days unless you ask us to keep them.
- Billing records: kept 7 years for tax compliance (legal requirement).
7. Security
Passwords are hashed with bcrypt. All connections are HTTPS-only with TLS 1.3. Database is encrypted at rest. We never see your plaintext password. If you suspect a breach, email support@outerank.com immediately.
8. Children
Outerank is not for users under 16. If you believe a child has registered, email us and we'll delete the account.
9. Changes
If we update this policy in a way that materially affects your rights, we'll email you 30 days before the change.
10. Contact
Privacy questions: support@outerank.com · contact form