Privacy Policy

Last updated: April 7, 2026

1. Introduction

RankOrca ("we", "us", or "our") operates the RankOrca platform accessible at rankorca.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using RankOrca, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.

2. Information We Collect

2.1 Information You Provide

  • Account information: When you register, we collect your email address and password (stored as a secure hash).
  • Profile data: Optional name, username, and avatar.
  • Payment information: Billing details are collected and processed by Stripe. We do not store full credit card numbers.
  • Content: Articles, keywords, website URLs, and WordPress credentials you enter into the platform.

2.2 Information Collected Automatically

  • Usage data: Pages visited, features used, timestamps, and session duration.
  • Device data: Browser type, operating system, IP address, and referring URLs.
  • Cookies: Authentication tokens stored in secure HTTP-only cookies; session and preference cookies.

2.3 Third-Party Data

If you sign in with Google, we receive your Google profile email and name as provided by Google's OAuth service.

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate your identity.
  • Provide, operate, and improve the Service (including AI content generation and keyword research).
  • Process payments and manage your subscription via Stripe.
  • Publish content to WordPress on your behalf when you enable auto-publish.
  • Send transactional emails (account confirmation, password resets, billing receipts).
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

We do not sell your personal data to third parties.

4. Cookies

RankOrca uses the following types of cookies:

  • Essential cookies: Required for authentication and security. These cannot be disabled.
  • Preference cookies: Remember your settings (e.g., theme, language).
  • Analytics cookies: Help us understand how visitors use the Service so we can improve it.

You can control non-essential cookies through your browser settings. Disabling essential cookies will prevent you from using the Service.

5. Data Sharing & Disclosure

We share your data only in the following circumstances:

  • Service providers: Supabase (database and authentication), Stripe (payments), Google Gemini (AI content generation). Each provider is bound by its own privacy policy.
  • WordPress integration: When you connect your WordPress site, your site URL and API credentials are used solely to publish content on your behalf.
  • Legal requirements: We may disclose information if required by law, regulation, or valid legal process.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your data is transferred.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting us at privacy@rankorca.com. We will process deletion requests within 30 days, subject to legal retention requirements.

7. Security

We implement industry-standard security measures including:

  • TLS encryption for all data in transit.
  • Bcrypt password hashing — we never store plain-text passwords.
  • HTTP-only, Secure cookies to protect authentication tokens.
  • Row-Level Security (RLS) on our database to enforce data isolation per user.

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using commercially reasonable means.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten").
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to certain processing activities.

To exercise any of these rights, contact us at privacy@rankorca.com.

9. Children's Privacy

RankOrca is not directed at children under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal data, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us: