Privacy Policy
On this page
Who we are 01
Sayrank is a service that measures how answer engines — ChatGPT, Claude, Gemini and Perplexity — describe a store and its products, and helps improve what those engines can read and quote.
In this document, we means the operator of Sayrank, and you means the person or company using the service. We are the data controller for the account data described below. Where you upload a product catalog, we act as a processor on your instructions.
Contact for anything in this document: [email protected]. We answer privacy requests within 30 days.
What we collect 02
| Category | What exactly |
|---|---|
| Account | Email address, password hash, workspace name, plan and billing status, the date you signed up. |
| Store | The domain you ask us to scan, the results of that scan, and — if you connect one — the API credentials for Shopify, WooCommerce or Webflow. |
| Catalog | The product data you upload as a file or that the scanner reads from your public product pages: titles, descriptions, prices, images, attributes. |
| Prompts and answers | The questions you choose to track, the replies the engines return, the position of your products in them, and the sources the engines quoted. |
| Agent activity | Your messages to the agent, images you attach, the drafts it produces, what you approved or rejected, and a journal of every change written to your store. |
| Usage | Token consumption per task, so the quota on your plan can be counted and shown to you. |
| Technical | Server logs with IP address, browser type and timestamps, kept for security and debugging. |
We do not collect special categories of personal data, and we ask you not to put any into product cards or agent messages.
Why we use it 03
- To run the service you asked for — scanning the site, scoring cards, sending prompts to engines, storing answers, writing approved changes. Legal basis: performance of a contract.
- To bill correctly — counting tokens against your plan and any packs you bought. Legal basis: performance of a contract.
- To keep the service safe — rate limits, abuse prevention, error logs. Legal basis: legitimate interests.
- To answer you — support correspondence. Legal basis: legitimate interests.
- To improve the product — aggregated, non-identifying statistics such as how long a scan takes. Legal basis: legitimate interests.
We do not sell personal data, and we do not use your catalog or answers to train models of our own.
Answer engines and other processors 04
To do its job, Sayrank has to send some of your data to third parties. Each one receives only what that task needs.
| Who | What they receive and why |
|---|---|
| OpenAI, Anthropic, Google, Perplexity | The prompts you track and, for card work, the product text being scored or rewritten. This is how the answers and drafts are produced. |
| Stripe | Billing identifiers and the amount charged. Card details go directly to Stripe; we never see or store them. |
| Your store platform | Only the change you approved, sent through the API credentials you provided. |
| Hosting and infrastructure | Everything needed to run the application and its database. |
These providers operate in several countries, so your data may be processed outside the country where you are based. Where that involves a transfer out of the European Economic Area or the United Kingdom, it is covered by Standard Contractual Clauses or an equivalent safeguard.
Your store connection 05
If you connect Shopify, WooCommerce or Webflow, we store the credentials you supply so the agent can read and write product data. Those credentials are used for nothing else.
- Nothing is written to your store until you approve the specific change.
- Every applied change is recorded with its previous value, so it can be reverted.
- Disconnecting the platform in Settings deletes the stored credentials immediately.
Cookies and local storage 06
We keep this deliberately small.
| What | Purpose and lifetime |
|---|---|
| Session cookie | Keeps you signed in. Strictly necessary — the application cannot work without it. Cleared when you log out. |
| Local storage | Remembers small interface choices you made yourself: whether the tour is done, whether a read-out is collapsed. Stays in your browser and never reaches us. |
We run no advertising pixels and no third-party analytics. Because of that, there is nothing here that requires a consent banner. If we ever add analytics, we will ask for your consent before it loads and update this page first.
How long we keep data 07
- Account data — while your account exists, then 30 days, then deleted.
- Catalog, scans, prompts and answers — while your account exists. You can delete a catalog or a scan yourself at any time.
- Agent journal — kept as long as the workspace exists, because it is what makes a change revertible.
- Billing records — kept for as long as tax and accounting rules require, even after the account is closed.
- Server logs — 90 days.
Your rights 08
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a copy in a portable format, and withdraw consent where processing relies on it.
You can do much of this in the product: export your catalog, delete cards or scans, close the workspace. For anything else, write to [email protected] and we will act within 30 days.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority. If you are in California, you may request disclosure of the categories of personal information collected and request deletion; we do not sell or share personal information as those terms are defined there.
Security 09
- Traffic is encrypted in transit; credentials and secrets are stored encrypted at rest.
- Passwords are stored as salted hashes and are never recoverable in plain text.
- Access to production data is limited to what is needed to operate and support the service.
- Payment card details never touch our systems — they go straight to Stripe.
No system is perfectly secure. If a breach affects your data, we will notify you and, where required, the relevant authority without undue delay.
Children 10
Sayrank is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, write to [email protected] and we will delete it.
Changes to this policy 11
We update this page when the product changes. The date at the top always shows the current version. If a change materially affects how we handle your data, we will tell you by email before it takes effect.
Contact 12
Privacy questions, data requests and complaints: [email protected].
We reply to every request and do not require a particular form of words — a plain email is enough.