Skip to content
rankion.ai

Privacy policy

Transparent information about data processing

The protection of your personal data is of particular concern to us. We process your data on the basis of the statutory provisions (GDPR, TDDDG). In this privacy policy we inform you transparently about the data processing in connection with our website and services.

Important note on data processing

rankion.ai uses US-based AI services (Anthropic Claude, OpenAI GPT-4) for content generation. This means your text prompts are transferred to the USA. Although the USA is classified as a "safe third country" under the EU-US Data Privacy Framework and our partners maintain zero-data-retention policies, access by US authorities remains theoretically possible. This transfer is necessary for the performance of our contract with you (Art. 6(1)(b) GDPR) and is not based on consent. You can find further details in section 4.

1. Controller

The controller for the data processing on this website is:

Rankion GmbH
Weidenweg 12
74321 Bietigheim-Bissingen
Germany

Managing Director: Alexander Weipprecht
Email:info@rankion.ai
Phone: +49 7142 9170511

Data protection officer:datenschutz@rankion.ai

2. What data do we collect?

2.1 Contact and account data

  • Name, email address (on registration)
  • Password (stored encrypted)
  • Profile picture (optional)
  • Language preference
  • Payment information (via Stripe, see 4.2)

2.2 Usage data

  • Created projects, articles and content
  • Keyword research and SEO/GEO scores
  • Style Profiles, Knowledge Base entries
  • Content storylines and publication plans
  • Generated images
  • Chat histories with the AI assistant
  • Feedback submissions (free text, category, resolution status and optionally up to three screenshots you upload yourself): deleted automatically when the submission or your account is deleted, image files included. The screenshots are not publicly accessible, only you and our administrators can retrieve them; on upload they are re-encoded on the server, which removes embedded metadata such as EXIF or GPS data. We also store the page you submitted the report from (path and query string only, without the domain), your browser's identifier (user agent), the project that was selected in your account when you submitted the report, and the area of the application (module) you were in. The sole purpose is troubleshooting: without the page a report such as “the button does nothing” cannot be found again, without browser and operating system it cannot be reproduced, and without project and area it cannot be matched to the work it belongs to. Values of address parameters that may be confidential (token, signature, secret, api_key, password, key) are replaced with *** before we store them. All of these are deleted together with the report and are not passed on to third parties
  • Credit usage and transaction history
  • Team memberships and permissions

2.3 Technical data

  • IP address (anonymized after 7 days in session data and the administration log, deleted after 14 days in server and application logs); for the block log, section 2.4 applies
  • Browser type and version
  • Operating system
  • Referrer URL (originating page)
  • Time of access
  • Cookies (see section 8)

2.4 Block log (disposable addresses)

If you register, sign up for the first time via Google, or submit a request through the free AI Reality Check form (publicly accessible, no login required) and the email address you provide belongs to a disposable email provider we recognize, we reject the request. We store this attempt in a block log: the IP address, the domain of the email address (the part after the @), the reason for rejection, and the time. We do not store the full email address. Entries are automatically deleted from the block log after 90 days.

The block log helps us detect abuse: disposable email addresses should not be used to claim the free starting credit or the free AI Reality Check more than once. It shows us how often a blocked domain is used and whether attempts pile up from the same IP address, so we can keep our block list up to date.

The legal basis is Article 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to detect abuse of our free services and to maintain the block list. You may object to this processing under Article 21 GDPR for reasons arising from your particular situation. Information about our balancing of interests is available on request from datenschutz@rankion.ai.

We process personal data on the following legal bases:

  • Art. 6(1)(b) GDPR: Performance of a contract (provision of our services)
  • Art. 6(1)(a) GDPR: Consent (e.g. for marketing, analytics)
  • Art. 6(1)(f) GDPR: Legitimate interests (security, improvement of our services)
  • Art. 6(1)(c) GDPR: Legal obligations (tax law, retention obligations)

4. Disclosure to third-party providers

To provide our services we use specialized third-party providers. All providers are contractually obliged to comply with the GDPR.

4.1 AI content generation (USA - transfer to a third country)

Important: AI content generation is carried out by US providers. Your text prompts are transferred to the USA. Since 2023 the USA has again been classified as a "safe third country" (EU-US Data Privacy Framework), but laws such as FISA 702 and Executive Order 12333 mean that US authorities theoretically have the possibility of access. Both providers are contractually committed to "Zero Data Retention" - that is, API requests are neither stored nor used for training.

Rankion AI (Anthropic Inc.)
Purpose: Content generation, SEO/GEO optimization, AI Humanization, Fact-Checking
Location: USA (San Francisco, California)
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) + your consent to the transfer to a third country
Data: Your text prompts, Style Profiles, Knowledge Base entries (transmitted encrypted via TLS 1.3)
Storage period: 0 days - Zero Data Retention (contractually guaranteed, API requests are not stored)
Adequacy decision: EU-US Data Privacy Framework (since 2023)
Risk: Theoretical access by US authorities under FISA 702
Data protection: anthropic.com/privacy

OpenAI LLC (GPT-4)
Purpose: Content generation (alternative to Claude)
Location: USA (San Francisco, California)
Legal basis: Art. 6(1)(b) GDPR + consent to the transfer to a third country
Data: Text prompts, responses
Storage period: 0 days - Zero Data Retention for API use (API Data Usage Policies)
Adequacy decision: EU-US Data Privacy Framework
Risk: Theoretical access by US authorities
Data protection: openai.com/privacy

Our recommendation: Do not enter sensitive personal data (names, addresses, health data, etc.) in text prompts. Anonymize your examples. For highly sensitive use cases, consult your data protection officer.

4.2 Payment processing

Stripe Inc.
Purpose: Payment processing, invoicing, subscription management
Location: USA/EU (PCI-DSS Level 1 certified)
Data: Payment information (credit card, SEPA), transaction data
Important: Credit card data is never stored on our servers but processed directly by Stripe
Data protection: stripe.com/privacy

4.6 Authentication

Google LLC (OAuth)
Purpose: Single sign-on (optional login with a Google account)
Location: USA (adequacy decision)
Data: Google ID, name, email address, profile picture (only if you sign in with Google)
Data protection: policies.google.com/privacy

4.7 Hosting & infrastructure

netcup GmbH
Purpose: Operation of the platform: application server, database, file storage and database backups
Location: Nuremberg, Germany (data centre; provider netcup GmbH, registered in Karlsruhe); no transfer to a third country
Security: Data centre certified to ISO/IEC 27001 (TÜV Nord); server access exclusively via SSH keys
Encryption: Transport exclusively via TLS 1.2/1.3; passwords stored as bcrypt hashes, API keys and 2FA secrets encrypted in the database
Legal basis: Data processing agreement under Article 28 GDPR
Data protection: netcup.com/de/kontakt/datenschutzerklaerung

For the complete list of all sub-processors with purpose, region, and legal basis, see /trust/sub-processors.

5. Storage period

  • Account data: Until your account is deleted
  • Content (articles, projects): Until manual deletion or deletion of the account
  • Payment data: 10 years (statutory tax retention period)
  • IP addresses: in session data and the administration log 7 days (security), then anonymized; for the block log, section 2.4 applies
  • Server and application logs: 14 days (security, error analysis), then deleted; block lists of the intrusion defence at most 7 days
  • Proof of waiver of the right of withdrawal: IP address and time of your consent to the immediate start of the service (Section 356(5) German Civil Code), for as long as your customer account exists — the record is deleted together with the account; it serves to defend against claims within the standard limitation period of three years (Sections 195, 199 German Civil Code)
  • Reports (incidents, forum): the IP address is stored only as a hash (pseudonymized), together with the report
  • Block log (rejected disposable addresses): 90 days, then automatically deleted (see section 2.4)
  • Chat histories: 90 days (automatic deletion)
  • Cookies: See cookie settings (max. 1 year)
  • Backups: Database dump before every change to the database structure; the last 10 versions are kept, older ones deleted

6. Your rights under the GDPR

You have the following rights at any time:

  • Right of access (Art. 15 GDPR): You can request information about the data we store about you
  • Right to rectification (Art. 16 GDPR): Rectification of inaccurate data
  • Right to erasure (Art. 17 GDPR): "Right to be forgotten"
  • Right to restriction (Art. 18 GDPR): Restriction of processing
  • Right to data portability (Art. 20 GDPR): Export of your data in a machine-readable format
  • Right to object (Art. 21 GDPR): Objection to processing
  • Right to withdraw consent (Art. 7 GDPR): Consent once given can be withdrawn at any time

To exercise your rights, please contact:datenschutz@rankion.ai

7. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority:

State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Phone: 0711/615541-0
Email:poststelle@lfdi.bwl.de

8. Cookies

Our website uses cookies. You will find details in ourCookie Settings.

Necessary cookies: locale (language), session (authentication), csrf_token (security), theme (dark/light mode)
Term: session up to 1 year

Analytics software (Matomo)

On our public website (not in the logged-in customer area) we additionally use the self-hosted analytics software Matomo, run on our own infrastructure (provimedia.de). Matomo runs cookie-free — nothing is stored on your device, so no cookie consent is required under Section 25 of the German Telecommunications-Digital-Services-Data-Protection Act. The legal basis for this processing is our legitimate interest in analyzing website usage to improve our offering (Art. 6(1)(f) GDPR). Your IP address is anonymized and never shared with third parties. We respect your browser's "Do Not Track" setting — if it is enabled, no analysis takes place.

You may object to this processing at any time under Art. 21 GDPR; to do so, please contact us at datenschutz@rankion.ai.

Object to analytics

Your visits are currently counted anonymously.

You have objected. Your visits are not being counted.

Your objection is stored for one year in a cookie on this device. After clearing your cookies, or on another device, please set it again.

9. Data security

We employ comprehensive security measures:

  • SSL/TLS encryption: All data transfers are encrypted (TLS 1.2/1.3)
  • Password hashing: Bcrypt algorithm (never stored in plain text)
  • Two-factor authentication: Optional, for increased security
  • Firewalls & DDoS protection: Protection against unauthorized access
  • Backups: Database dump before every change to the database structure; the last 10 versions are kept, older ones deleted; stored only on the server in Germany
  • Security Audits: Regular security reviews
  • Access Controls: Strict access restrictions for employees

10. Changes to this privacy policy

We reserve the right to amend this privacy policy in order to adapt it to a changed legal situation or to changes in our services. The version in force at the time applies to each new visit. In the event of substantial changes we will inform you by email.

Version of this privacy policy: 21.09.2026
Version: 2.1

Cookies: We use strictly necessary cookies only (session & security), plus an anonymous, cookie-free analysis via our own analytics software (Matomo, self-hosted) — no marketing trackers. Details