RRankoHub
RO Log in Get started
ENRO

Security practices at RankoHub

Answers to the questions we get about how your data is handled. Anything else — write to [email protected] and you will get a straight answer.

Do you collect any personal data?

Only what Google sign-in provides: your name, email address and profile picture, used to create and identify your account. We do not sell or share personal data with third parties, and we run no advertising or third-party tracking scripts in the application.

Do you store GSC and GA4 site data?

Yes — storing your history is the core of the product. Google deletes Search Console data after 16 months; RankoHub warehouses every daily sync in its own database so your history only grows. The data belongs to your account: deleting a site permanently deletes all of its data, deleting your account deletes everything, and revoking RankoHub's access from your Google account stops all synchronization immediately.

Where is the data stored?

On our own server hosted in the European Union (Finland, with Hetzner as the infrastructure provider). Data does not leave the EU. Traffic is proxied through Cloudflare with TLS.

Who has access to the underlying systems and data?

RankoHub is run by a very small team; production access is limited to the founder. Accounts used to operate the service are protected with multi-factor authentication.

How do you protect sensitive data?

All traffic is encrypted in transit (HTTPS). Google OAuth tokens are encrypted at rest — we never see or store your Google password. The database is not exposed to the public internet. Data is logically segregated per account, so each account can only access its own sites. File uploads are validated by content, not by file name. Public endpoints — sign-in, shared report links, uploads — are rate limited against brute force and enumeration, and shared reports can be password-protected, paused or revoked at any time.

Do you keep backups?

Yes. The database and uploaded files are backed up daily to encrypted off-site storage in the EU (Frankfurt), with restores tested for real, not assumed. Daily backups are kept 8 days and weekly backups at most 35 days, so deleted data also leaves the backups within 35 days. A failed backup alerts us immediately.

Have you ever had a data breach?

No. If we ever do, we will notify affected users immediately and take all necessary steps to mitigate the impact.

Do you have ISO 27001, SOC 2 or a similar certification?

Not currently — RankoHub is a young, small product. It is something we would consider as the service grows.

Are you willing to complete a security questionnaire?

For larger customers, yes — reach out at [email protected] and we will do our best to answer promptly.

Do you have a Data Processing Agreement (DPA)?

A formal DPA covering GDPR requirements, subprocessors and security measures is being prepared. Until it is published, it is available on request at [email protected].

Ask a security question