RankVault logoRankVault

Privacy Policy

Last updated: May 23, 2026

1. Who we are

RankVault is operated by MB SRDS, registration code 304146906, VAT LT100010314814, registered in Lithuania. For the purposes of the General Data Protection Regulation (GDPR), MB SRDS is the data controller responsible for your personal data.

Contact email: [email protected]

2. What data we collect

We collect and process the following categories of personal data:

  • Account data: your name, email address, and password when you create an account. You may also sign up using Google OAuth, in which case Google shares your name and email with us.
  • Company data: your business name, website domain, phone number (optional), business email (optional), language, timezone, country, and target location.
  • Website content: we scrape the URL you provide using an automated tool (Firecrawl). This extracts your publicly available page text, branding (colours, fonts, logo), and a screenshot. The scraped content is then analysed by AI to determine your industry, tone of voice, target audience, brand values, and relevant topics.
  • Keyword data: we query keyword research services (DataForSEO) using your domain to retrieve search volume, competition, and related keyword data for your industry.
  • Content plan data: the blog topics, social post angles, and keywords you approve, edit, or block within RankVault.
  • Generated content: blog posts, social media captions, images, and hashtags created by the Service on your behalf.
  • Platform integration data: OAuth access tokens and refresh tokens for Facebook, Instagram, and Google Search Console, stored in encrypted form. WordPress application passwords, also stored encrypted. Page IDs, account names, and profile avatars for connected accounts.
  • Comments and auto-replies: if you enable the auto-reply feature, we receive and process comments left on your Facebook Page and Instagram Business account, including commenter names and comment text, in order to generate AI replies on your behalf.
  • Analytics data: if you connect Google Search Console, we sync and store your site's search performance data (clicks, impressions, CTR, positions, top queries, top pages). If you connect Facebook or Instagram, we sync and store your page and account insights (reach, engagement, follower counts, top posts).
  • Payment data: billing email, name, billing address, and tax information processed through Stripe. We do not store your full card details on our servers.
  • Communication data: emails and messages you send to our support team, including contact form submissions.

3. How we use your data

We process your personal data for the following purposes:

  • To provide the Service: scraping your website, extracting your brand profile, researching keywords, generating content plans, creating blog and social media content, generating images, publishing to your connected platforms, syncing analytics, and providing auto-reply functionality.
  • To manage your account: authentication (including email verification and password reset), account setup, subscription management, and billing via Stripe.
  • To send transactional emails: email verification on signup, password reset emails, password change notifications, and email change verification. We send these through Resend. We do not send marketing emails.
  • To meet legal obligations: complying with applicable laws, regulations, and legal processes in the European Union and Lithuania.

4. Legal basis for processing (GDPR)

We rely on the following lawful bases under Article 6 of the GDPR:

  • Contract performance (Article 6(1)(b)): processing your data to deliver the RankVault service you signed up for, including website scanning, brand analysis, keyword research, content generation, publishing, analytics syncing, and comment auto-reply.
  • Legitimate interest (Article 6(1)(f)): maintaining the security and integrity of our systems, detecting abuse, and communicating with you about your account. Our legitimate interest does not override your fundamental rights.
  • Consent (Article 6(1)(a)): connecting third-party platforms (Facebook, Instagram, Google Search Console, WordPress) requires your explicit authorisation through OAuth or credential entry. You can withdraw consent by disconnecting any platform at any time.
  • Legal obligation (Article 6(1)(c)): retaining billing records and other data as required by Lithuanian tax and accounting law.

5. AI processing and your content

RankVault uses artificial intelligence to power the Service. Specifically:

  • Google Gemini (via Vercel AI SDK): used for brand extraction from your scraped website, social media caption generation, blog post idea generation, full blog article writing, and generating auto-replies to comments on your social posts. Your website content, brand profile, approved topics, and (when auto-reply is enabled) comment text and commenter names are sent to Google's APIs for processing.
  • OpenAI (image generation models): used to generate social media creative images and blog post featured images. Post captions, brand colours, fonts, and reference images from your website are sent to OpenAI's image API.

All AI processing is inference-only. We do not fine-tune models on your data, and we do not use your data to train public or private AI models. Your data is sent as prompts and responses only.

You retain full ownership of all content generated for your account. We do not claim any intellectual property rights over the content we produce for you.

6. Subprocessors

We share data with the following third-party service providers (subprocessors), each processing data on our behalf under appropriate agreements:

Subprocessor Purpose Data accessed Location
Convex (self-hosted) Backend platform, database, serverless functions, scheduling All application data (accounts, companies, posts, integrations, analytics, encrypted tokens) EU
Google (Generative AI / Gemini) AI text generation for brand analysis, content, and auto-replies Scraped website content, brand profile, keywords, social post data, comment text and commenter names EU / US
OpenAI AI image generation for social posts and blog featured images Post captions, brand colours, fonts, reference images US
Firecrawl (Mendable) Website scraping and brand extraction Your public website content (pages, metadata, images) US
DataForSEO Keyword research (search volume, competition, trends) Your domain name EU (Germany)
Stripe Payment processing, subscription management, invoicing Email, name, billing address, tax information, payment method details US / EU
Resend Transactional email delivery (verification, password reset, notifications) Email address, email content US
Cloudflare R2 File and image storage (logos, screenshots, generated images) Uploaded and generated image files EU
Facebook / Meta (Graph API) Social publishing, insights syncing, comment webhooks, auto-reply Page access token, page posts, page insights, page comments, commenter names US / EU
Instagram / Meta (Graph API) Social publishing, insights syncing, comment webhooks, auto-reply Account access token, media, insights, comments, commenter names US / EU
Google (Search Console API) SEO analytics (clicks, impressions, CTR, position) Site analytics data, access/refresh tokens US / EU
Google (OAuth) Sign-in authentication Name, email address US / EU

We do not sell, rent, or trade your personal data to third parties for their own purposes.

7. International data transfers

Your data is stored and processed primarily within the European Union through our self-hosted Convex database and Cloudflare R2 storage. Some of our subprocessors (Google, OpenAI, Firecrawl, Stripe, Resend, Meta) may process data in the United States or other countries outside the EU.

For transfers outside the EU, we ensure appropriate safeguards are in place:

  • Google relies on the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs).
  • OpenAI provides a Data Processing Agreement (DPA) with SCCs.
  • Stripe maintains compliance with the EU-US Data Privacy Framework and provides SCCs.
  • Meta platforms operate under the EU-US Data Privacy Framework and SCCs.
  • Firecrawl and Resend operate under SCCs where applicable.

8. How long we keep your data

  • Account data: kept for as long as your account is active, plus 30 days after deletion to allow recovery.
  • Website scan data: retained while your account is active to maintain brand voice consistency. Deleted within 30 days of account closure.
  • Generated content: blog posts, social posts, and images are retained for the duration of your subscription. Content published to your connected platforms remains there subject to those platforms' own policies.
  • Integration tokens: OAuth tokens and WordPress credentials are stored in encrypted form for as long as the integration is active. Deleted immediately when you disconnect a platform.
  • Analytics data: search and social insights synced from connected platforms are retained while the integration is active and for 30 days after disconnection.
  • Comment and auto-reply logs: comment text, commenter names, and generated replies are retained for 12 months.
  • Billing records: retained for 6 years as required by Lithuanian tax and accounting law.
  • Transactional emails: delivery records retained for 12 months.
  • Support communications: retained for 2 years from the date of last contact.

9. Your rights under GDPR

You have the following rights regarding your personal data:

  • Right of access: you can request a copy of the personal data we hold about you.
  • Right to rectification: you can ask us to correct inaccurate or incomplete data.
  • Right to erasure: you can request deletion of your personal data, subject to legal retention requirements.
  • Right to restriction: you can ask us to limit how we process your data in certain circumstances.
  • Right to data portability: you can request your data in a structured, machine-readable format.
  • Right to object: you can object to processing based on legitimate interest or for direct marketing purposes.
  • Right to withdraw consent: where processing is based on consent (such as platform connections), you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. You can disconnect any platform from your dashboard at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. There is no fee, unless your request is clearly unfounded or excessive.

10. Data security

We take reasonable technical and organisational measures to protect your personal data, including:

  • Encryption of OAuth tokens and WordPress credentials at rest using AES-256-GCM encryption with a server-side encryption key.
  • Encryption of data in transit using TLS for all connections.
  • Encryption of stored files at rest through Cloudflare R2's default encryption.
  • Passwords hashed and managed by the authentication framework (Better Auth), never stored in plaintext.
  • Access controls limiting data access to authorised personnel on a need-to-know basis.
  • HMAC-SHA256 signature verification for all incoming Facebook and Instagram webhook events to prevent spoofing.

No system is completely secure. If you believe your data has been compromised, contact us immediately at [email protected].

11. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk, we will also notify you directly without undue delay.

12. Children's privacy

RankVault is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will take steps to delete that data promptly.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice in the RankVault dashboard. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

14. Supervisory authority

If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija): https://vdai.lrv.lt.

15. Contact

For any questions about this Privacy Policy or our data practices, contact us at: