Privacy Policy
Last updated 2 October 2026
This notice covers ProveRank, the software at proverank.ravinaro.com. It explains what the service collects, why it is allowed to, who else it reaches, how long it stays, and what you can require us to do about it. It is written to be read, not to be survived.
Who is responsible
ProveRank is operated by RAVINARO L.L.C-FZ, a company licensed in the United Arab Emirates. RAVINARO L.L.C-FZ is the data controller for the personal data described here.
Registered address: 601, Meydan GrandStand, Floor 6, Dubai, United Arab Emirates.
- Privacy and data requests: privacy@ravinaro.com
- Anything else: hello@ravinaro.com
We are established in the UAE, so the federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the “PDPL”) applies to us directly. Because we offer the service to people in Europe and the United Kingdom, the GDPR and UK GDPR apply as well. Rather than run three standards, we apply the strictest one to everybody. Where a law gives you a right, you have it here whether or not that law reaches you.
The short version
- We only crawl websites whose address you gave us yourself.
- We do not sell, rent or share your data for anyone else’s advertising. There is no exception to this.
- The application itself needs two cookies, neither for advertising. Session recordings load only if you say yes in the cookie banner, and recordings inside your account hide what you type and see. Web analytics and measurement of our own ads load only after a yes in the EEA, the UK and Switzerland; elsewhere they are on unless you switch them off under Cookie settings.
- Some things you ask for cannot be done without sending a fragment of your data somewhere else: a keyword to a search-data provider, a page’s title and opening sentence to an AI model. Everything that leaves is named below.
- You can export your data, delete a project, or delete the whole account yourself, at any time.
What we hold, and why we are allowed to
Under the GDPR every purpose needs a lawful basis. Most of ours is the plainest one: you asked for the service and this is what running it requires.
| What | Why | Lawful basis |
|---|---|---|
| Your email address, a name if you give one, your role, and a hashed password | To have an account at all, to sign you in, and to reach you about it | Performance of the contract |
| Your projects: the site addresses you ask us to audit | They are the subject of the work | Performance of the contract |
| What an audit finds: page titles, meta descriptions, headings, canonical and hreflang tags, word and link counts, the internal link graph with its anchor text, and the first paragraph of a page up to 400 characters | This is the analysis you came for | Performance of the contract |
| Keywords, rankings, competitor domains, backlink data, AI-visibility results including the full text each model returned | To produce the measurements and the plan | Performance of the contract |
| Search Console tokens and the metrics imported with them | Only if you connect it. See the Search Console section below | Performance of the contract |
| Subscription status and payment-processor identifiers | To bill you and to apply your plan limits | Performance of the contract; legal obligation for tax records |
| Usage counters: audits, probes and research runs this month | To enforce plan limits fairly | Performance of the contract |
| A security log of sign-ins, failed sign-ins, password changes, account deletions and administrator actions, each with the email address it concerned | To investigate compromise and abuse | Legitimate interests in keeping accounts secure |
| A record of every email we sent you: address, subject, whether it was delivered | So we can prove what was sent and diagnose what was not | Legitimate interests in an accountable service |
| Requests to the AI-crawler beacon: the path visited, the status returned and the visiting bot’s user agent | To show you which AI crawlers reach your pages | Legitimate interests, and only for sites you registered |
| Terms acceptance records: which versions of the terms and this policy you accepted, the wording of the box you ticked, when, your IP address and your browser’s user agent | Proof of the contract both sides made, at signup, at checkout and when the documents change | Performance of the contract; legitimate interests in being able to establish and defend legal claims |
| Messages you send us: support emails, bug reports and feedback, with any screenshot you attach | To answer you and fix what you reported | Legitimate interests in supporting customers |
| Site analytics: pages visited, events such as signing up or starting an audit, device and browser type, approximate location from your IP address, and an opaque id derived from your account (never your email) | To understand how the site and product are used and which pages lead people to sign up | In the EEA, the UK and Switzerland, consent given in the cookie banner and withdrawable at any time; elsewhere, our legitimate interest in measuring our own site and ads, which you can switch off at any time under Cookie settings |
| Session recordings and heatmaps: clicks, scrolls and mouse movement on our pages. Inside your account all text and every input are masked before anything is sent; on public pages, form fields are masked | To find and fix the places where people get stuck | Consent, given in the cookie banner and withdrawable at any time |
Where we keep your IP address, and where we do not. An address is read in memory to rate-limit requests and is not stored, with one exception: the terms acceptance record above keeps the address you accepted from, because it is part of the evidence. If you allow analytics, the analytics and recording tools also see your address when your browser contacts them; we have configured them not to give it to us.
We take no automated decision that produces a legal effect for you or anything similarly significant. Scores and recommendations are advice you act on or ignore.
Crawling your site
We fetch only the addresses you give us, and only pages on that site. The crawler identifies itself as ProveRankBot/1.0 and requests robots.txt under the same name. It obeys the rules it finds there, including rules written for our bot specifically, and it honours a declared Crawl-delay up to ten seconds a page.
We do not keep the pages themselves. The HTML is parsed in memory and discarded. What survives is the derived material listed above, plus a fingerprint used to notice when a page changed. We do not build a general index of the web and no crawl is ever reused outside the project that asked for it.
If your details appear on a page we crawled
A website we crawl for a customer may mention people who never signed up here: an author byline, a team page, a contact address. Two places in the product hold that kind of information. Extracted page material such as titles, headings and an opening paragraph may name someone; and where a backlink source publishes a contact address, we store it so the customer can approach that site.
We have no way to contact you individually about this, so this section is how the law asks us to tell you instead. Our basis is our legitimate interest in providing an analysis service that a site owner has instructed us to run. You can object, and you can ask us to erase what we hold about you: write to privacy@ravinaro.com with the page address and we will deal with it within one month. If the site is one of our customers’, we will also tell them.
When a partner product uses ProveRank
Some products, such as BlogTend, use ProveRank behind the scenes. When one does, we process the site domains, the target country and language, the topic seeds and the keywords that product sends us, so that we can return keyword, search-result and site data for it. That data is used only to provide the service to that product.
If you choose to claim a ProveRank account from a partner, the partner shares your name, your email address and your site address with us at your request, so that the account and its first project can be set up for you. We use those details only for that purpose. If you also connect Google Search Console, we share that site’s Search Console query data with that partner, as explained in the Search Console section below.
Google Search Console data
Connecting Search Console is optional and nothing here applies unless you do it.
- What we ask for. One scope, read-only: webmasters.readonly. We cannot change anything in your Search Console. We cannot submit a sitemap, request indexing, or alter a property.
- What we import. The list of properties you can access, and for the property you pick: search queries, the page each applied to, clicks, impressions, click-through rate, average position and the date. Nothing else.
- Why. To show you what each page already ranks for, and to work out which queries sit just outside the positions that earn clicks. Both appear in the product. The only other use is the partner case described below, and it is never used for advertising.
- Where it goes. Into our database, with our hosting provider. The refresh token is encrypted before it is stored.
- Who else sees it. Nobody, with two exceptions described below.
The first exception, stated plainly. When a Search Console query is the strongest evidence of what a page is about, that query becomes the page’s target keyword, and the target keyword is included in the prompt we send to an AI model to draft a title and description for that page. So a query string can reach the model named in the next section. Clicks, impressions, click-through rate, position, dates and the page addresses from Search Console are never sent to any AI model.
The second exception: a partner you claimed your account from. If you claimed your ProveRank account from a partner product and also connected Search Console, we share that site’s Search Console query data (the queries, average positions, impressions and clicks) with that partner, for that same site only, so the partner can suggest keywords the site almost ranks for. The claim is what links the accounts, so this happens at your request and only for your own site. It stops when you disconnect Search Console or delete the project. We never sell Search Console data or use it for advertising.
We do not use Google user data to train or fine-tune any AI model, ours or anyone else’s, and the providers we use are engaged on terms that forbid them from training on what we send. Nobody at RAVINARO L.L.C-FZ reads your Search Console data except to investigate a security problem or a specific fault, to comply with the law, or because you asked us to look at something.
Disconnecting. Use the Disconnect button on the project’s Search Console card. We hand the token back to Google so the grant itself ends, delete our copy, and delete every metric imported under it. You can also revoke access at your Google account permissions; doing it there stops future syncs but does not delete what was already imported, so use the button if you want both.
What we send to AI models
Two features involve a third-party model, and they send different things.
- AI visibility probes send a question built from a template and one keyword, such as “What is the best project management software?”. No page content, no Search Console data and no personal data are included.
- Draft titles, descriptions and content briefs send more: the page address, your brand name, the target keyword and related keywords, the page’s current title and heading, and its opening sentence up to 300 characters. If that sentence names a person, that name is in the prompt.
Which providers are reachable depends on which the operator has configured. They may include OpenAI, Anthropic, Google, Perplexity, xAI and DeepSeek. Each is engaged on terms that prohibit training on our data. DeepSeek is subject to regulatory attention in parts of Europe; if that matters to you, ask us and we will confirm which engines are enabled on your account.
If you connect your own AI assistant to our API or MCP endpoint, that assistant is yours, not ours. Whatever you ask it to fetch, including Search Console figures, goes to whichever model you chose, under their terms.
Everyone else who touches it
We use other companies to run the service. Each acts on our instructions, is bound by a contract that holds them to the standard we owe you, and may not use your data for their own purposes. We remain responsible for what they do.
| Who | What for | What reaches them |
|---|---|---|
| Hosting and infrastructure provider | Hosting, the database, caching, the network, and the bot check on the sign-up, sign-in, password reset, contact and newsletter forms | Everything the service stores, and every request in transit |
| Payment processor | Payments and the billing portal | Your email address, an account identifier and, if analytics is on in your browser, its analytics client id so a purchase can be matched to the visit that led to it. Card details go straight to the payment processor; we never see or store them |
| Email delivery provider | Sending email | Your address and the content of the message |
| Google, only if you connect Search Console | Importing your Search Console data | The Search Console data you authorised |
| Web analytics provider (with your consent in the EEA, UK and Switzerland; elsewhere unless you switch it off) | Which pages are visited and which steps are completed; measuring which of our own ads led to a sign-up or purchase | Which pages you visit, the events listed above, your IP address, browser details and an opaque account id |
| Session-recording provider (only with your consent) | Session recordings and heatmaps | Clicks, scrolls and page structure, with text and inputs masked inside your account; your IP address, browser details and the same opaque account id. Never on administration, sign-in, password, checkout, print or shared-report pages |
| AI model providers | Visibility probes, drafts and briefs | As set out in the section above |
| Search and web data providers | Search results, keyword volumes and suggestions, page speed measurement, domain authority and link discovery | A keyword, your domain or hostname, or the address of a page being measured |
Search and web data providers receive only what a feature needs to work: measuring a page’s speed sends its address, expanding a keyword sends that keyword, and finding who links to you sends your hostname. None of them receives your email address or your name. The current list of providers is available on request from the address at the end of this policy.
If we change who processes your data in a way that affects you, we will say so here and tell account holders by email before it takes effect.
Sending data between countries
We are in the United Arab Emirates and the companies above are spread across the world, so your data crosses borders. Neither the European Commission nor the UK has decided that the UAE offers protection equivalent to their own, which means we cannot rely on that shortcut and use contractual protection instead.
- For transfers out of Europe we use the European Commission’s Standard Contractual Clauses, and for the United Kingdom the Addendum issued by the Information Commissioner.
- We assess whether those clauses can actually be honoured in the destination country before relying on them, and we keep that assessment under review.
- Data is encrypted in transit and secrets are encrypted at rest, so what crosses a border is not readable in passing.
You can ask us for a copy of the safeguards that cover a particular transfer. Write to privacy@ravinaro.com.
How long we keep things
Most of what we hold is yours and stays until you remove it. You can delete a project, which takes its crawls, keywords, rankings, reports, briefs, link graph, Search Console data and action items with it, or delete the whole account from Settings.
| What | How long |
|---|---|
| Projects and everything an audit produced | Until you delete the project or the account |
| Account details | Until you delete the account |
| Search Console tokens and imported metrics | Until you disconnect, delete the project, or delete the account |
| Partner claim records (your name, email and site address) | Until you delete the account |
| Sign-in sessions | Seven days, and immediately if you sign out everywhere |
| Confirmation links | Twenty-four hours |
| Password reset links | One hour, and once used they cannot be used again |
| Terms acceptance records | For the life of the account. After you delete it, a reduced record (a one-way hash in place of your account id, the versions and wording accepted, and the time; the IP address and user agent are erased) is kept until claims under the agreement can no longer be brought, then deleted |
| Billing records | As long as tax and accounting law requires us to keep them (in the UAE, currently up to seven years) |
| Bug reports and feedback sent from the product | Until you delete the account |
| Web analytics data | Two months, the shortest setting our analytics provider offers; cross-device signals are off |
| Session recordings and heatmaps | Recordings 30 days from recording; a small sample, and any we mark as favourites, up to nine months. Dashboard data up to 30 days |
| Your cookie choice | Twelve months, then we ask again |
When you accept the terms, at signup, before checkout or after we update them, we keep a record of that acceptance: the versions of the terms and this policy, the exact wording of the box you ticked, the time, your IP address and your browser’s user-agent string. It is proof of the contract both sides made, which is why a reduced form of it outlives the account, as the table says.
Two more records outlive a deleted account, and you should know which. The security log keeps the email address it concerned, because a record of who signed in and when is worthless if it can be erased by the person it describes. The email log keeps the address a message was sent to, so we can show what was sent. Both hold an address and a timestamp. Neither holds your content, your projects, or anything an audit produced. If you want them removed as well, ask, and we will weigh your request against the reason the record exists and tell you the outcome.
Deleting from the live database does not instantly erase copies in routine backups. Those are overwritten on their own cycle, and nothing is restored from them except to recover from a failure.
Your rights
Under the PDPL, the GDPR and the UK GDPR, and as our standard for everyone, you can require us to do all of the following, free of charge.
- See what we hold and get a copy of it.
- Correct anything wrong. Most of it you can edit yourself.
- Delete your data. Settings has a delete button for the account and for each project.
- Take it elsewhere in a machine-readable form. Keyword exports, reports and the API already do this.
- Restrict what we do with it while a dispute is being sorted out.
- Object to anything we do on the basis of legitimate interests.
- Withdraw consent where we asked for it, as easily as you gave it: the Cookie settings link turns analytics and recordings off at once.
- Not be subject to automated decisions with legal or similarly significant effects. We make none.
Write to privacy@ravinaro.com. We answer within one month. If a request is genuinely complicated we may take up to two months more, and we will tell you why within the first month. We may ask you to confirm who you are before we hand over personal data, which is a protection for you.
If we get it wrong you can complain to a regulator: in the United Arab Emirates to the UAE Data Office, in the European Union to the supervisory authority where you live or work, and in the United Kingdom to the Information Commissioner’s Office. You are welcome to come to us first, and we would rather you did.
Cookies, analytics and session recordings
Two cookies are strictly necessary for the application to work and need no consent: one keeps you signed in, one remembers whether you collapsed the sidebar. Everything else is optional. Session recordings are not loaded at all until you accept them in the cookie banner, wherever you are. In the EEA, the UK and Switzerland (and when we cannot tell where you are), web analytics is not loaded either until you accept; until then no cookie is set and no request reaches either provider. Elsewhere web analytics is on unless you switch it off. Rejecting is one click and carries the same weight as accepting. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a rejection. The Cookie settings link in the footer reopens the choice at any time, and withdrawing takes effect immediately.
Session recordings let us replay how pages are used, so we can see where people get stuck. Inside your account every piece of text and every input is masked in your browser before anything is sent, so the recording shows the layout and your clicks, not your data. Recordings never run on administration, sign-in, password, checkout, print or shared-report pages. Both tools are used only for our own analytics, plus, where analytics is on, measuring which of our own ads led to a sign-up or purchase (when you buy, our server reports the purchase too, with the analytics id from your browser, so it is counted even if a blocker stops the script): cross-device signals, remarketing and ad personalisation are off, and neither tool receives your email or name. The full list of cookies, what each does and how long it lasts is in the Cookie Policy.
Security
- Passwords are hashed with scrypt and a random salt for each account. We could not tell you your password if we wanted to.
- Provider credentials and Search Console tokens are encrypted with AES-256-GCM before storage.
- Sessions are signed and individually revocable. Signing out everywhere ends all of them at once.
- API keys are stored as a hash. The key itself is shown once, at creation, and never again.
- Access to every project is checked against your account on every request, including from the API and the MCP endpoint.
- Requests are rate-limited, and sign-in attempts more tightly than the rest.
If a breach happens that puts your rights at risk, we will report it to the relevant regulator without undue delay, and within 72 hours where the GDPR requires it. If it is likely to put you at high risk, we will tell you too, in plain language, and say what we are doing about it.
Children
The service is for adults: you must be 18 or over to use it. We do not knowingly collect data about anyone under 18. If you believe a child has created an account, tell us and we will remove it.
Changes to this notice
If we change this materially, the date at the top changes, account holders are told before it takes effect, and you will be asked to accept the new version the next time you sign in. If a change means using data you already gave us for something new, we will ask first rather than assume. Previous versions are available on request.
See also the Terms of Service and the Cookie Policy.