Page
Privacy Policy
What Ransack collects, what it deliberately does not, and how deletion works.
Last updated: July 15, 2026
This policy describes what Ransack collects and how it is used. The short version: we collect what the service needs to operate, and visitors to published sites are not tracked.
What we collect
- Account and organization data: email address, display name and handle; organization names, memberships, roles and invitations; optional Google identity subject and verified profile name used for sign-in; and one-way hashes and non-secret prefixes for API keys and login credentials. Ransack does not retain Google access or refresh tokens. Raw API keys and partner-review access codes are shown only when created and are not stored.
- Your content: whatever you publish through the platform — it is stored, versioned, and served as the product's core function.
- Connected applications: the application name, approved organizations and scopes, OAuth grant lifecycle, and limited use metadata needed to authorize and revoke connected agents. A connected application receives only the Ransack tool results requested through that connection; Ransack does not receive or store the rest of your conversation with that provider.
- Partner-review access: when an organization owner creates temporary access for an app store or security reviewer, we store its provider and label, designated organization and scopes, lifecycle and client binding, an isolated reviewer identity, and a one-way hash of the access code. Revoked or expired review records are retained for up to 90 days for audit and abuse response, then purged with the isolated identity.
- Visitor notes: when a site enables note intake, we store the note and a one-way, purpose-specific IP hash for abuse prevention. Notes expire after 180 days unless removed sooner with their site or organization; rate-limit records expire after about 24 hours.
- Transactional email records: delivery status and provider message identifiers for login, invitation, and organization-claim email. Completed delivery records expire after about 30 days.
- Operational logs: our infrastructure providers may record requests, including IP addresses, for security, abuse prevention, reliability, and debugging. They are retained only for the limited operational period established in our service configuration and are not used for advertising or profiling.
What we deliberately do not do
Public and unlisted Ransack sites set no visitor-tracking cookies, run no third-party trackers, and embed no analytics scripts. Private sites and account pages use one strictly necessary, host-only session cookie so signed-in members can authenticate. The only script a published page loads is our own site behavior. We do not sell or share personal information for advertising.
Service providers
We use Cloudflare (serving, object storage, security, and logs), Neon (database hosting and backups), Resend (transactional email for login, invitations, and organization claiming), and Google (optional federated sign-in). Each processes data to provide its service to us. When you connect Ransack to an AI client or other application, that provider separately processes the prompts and Ransack tool results you choose to send under its own terms and privacy policy.
Deletion
Deleting your organization immediately revokes access and starts durable erasure of its sites, content, assets, credentials, history, and organization-linked audit data. Stored objects and organization-tagged derived image caches are deleted by retrying background jobs; the deletion is not considered operationally complete while those jobs are pending. A non-linkable receipt containing only aggregate counts may remain. Neon recovery history expires within seven days, and deleted data is not restored into active service except as part of disaster recovery.
Deleting your user account revokes sessions immediately and removes every organization membership. Organizations with another owner survive, final-member organizations enter the same full-erasure process, and deletion is blocked when the user is the sole owner of an organization that still has other members until ownership is handed off. Privacy-safe audit records may retain opaque random identifiers, but not the erased email, display name, or handle.
Contact
Privacy questions: privacy@ransack.io.