Privacy
Last updated: October 8, 2026
What RankDesk keeps, why, and what you can do about it.
What we keep about you
Your name, email and password (as a hash only), and your preferred language. For each sign-in, the browser and IP address, so you can see and end your other sessions.
If you connect Telegram or Bale, the chat id and username, to send you alerts.
What we keep about your sites
The results of auditing your site's public pages: titles, descriptions, links, page text for content analysis, and Core Web Vitals.
If you connect Search Console, your site's search statistics (clicks, impressions, positions). The Google access token is stored encrypted and erased when you disconnect. Access is read-only.
Competitor watch reads only a competitor's public pages and sitemap.
Payments
Payment happens on Zarinpal's page; RankDesk never sees your full card number or PIN. Only the reference number and the masked card number the gateway returns are recorded on the invoice.
Cookies
One httpOnly cookie keeps you signed in. RankDesk uses no advertising cookies or third-party trackers. Your language and theme are stored in your own browser.
Who we share with
We do not sell data. To provide the service, these receive part of it: Google (page addresses for PageSpeed, and Search Console requests), Zarinpal (amount and email for payment), Telegram and Bale (alert text, if you connected them), and the email service that delivers our emails.
Anyone holding a client report link can open it; revoke it whenever you like.
Retention and deletion
Data is kept while the account and workspace are in use. A deleted workspace is taken out of use but kept so it can be restored; email support to have it permanently erased, to delete your account entirely, or to get a copy of your data.
Security
Connections are encrypted, passwords and connection keys are stored only hashed or encrypted, and the workspace owner decides which sites each member can reach.
Questions about this page: support@rankdesk.ir.