Privacy policy
RankShield is built on proof, not surveillance. Our products protect you, and our approach to your information reflects that: we practice data minimization, prove what needs proving without exposing what doesn't, and give you control. This page explains, in plain terms, how we handle information across our web platform and the RankShield iOS app. It is our privacy policy and may be updated; the effective date below reflects the current version.
Effective 16 July 2026 · RankShield is a trade name (DBA) of SEO Elite Agency, the data controller · [email protected]
Our principle: minimum necessary
RankShield's core design is to verify and protect without collecting more than is needed. Our security products focus on integrity and threat signals — attack patterns, not your private content. Where we can prove something is safe without seeing the underlying data, we do.
Information we collect
We collect information you provide directly (such as an email address when you contact us or request access), information needed to deliver and secure our services (such as account, device-integrity and traffic-scoring signals relevant to protecting you), and standard technical information collected when you use our website (such as basic analytics and security logs). We aim to keep this to what is necessary for the purpose.
How we use information
We use information to provide, maintain and improve our products; to detect, prevent and investigate security threats and fraud; to communicate with you; and to meet legal and compliance obligations. We do not sell your personal information.
Google user data — Search Console, Google Analytics (GA4) and Google Ads
Some RankShield products — including our WordPress plugin and Shopify app — let you connect your own Google accounts so we can show your search, analytics and ad-performance data inside the product and use it to detect ranking, click and ad-spend attacks. This connection uses Google OAuth, which means you sign in with Google and grant access explicitly; we never see or store your Google password. This section describes exactly what Google data we access, how we use it, and how you stay in control. It governs alongside, and is not overridden by, the summary sections above.
What we access, and why (read-only). When you connect Google, we request only the minimum, read-only scopes needed for the feature you enabled:
- Google Search Console — webmasters.readonly: to read your verified sites, search-performance metrics (impressions, clicks, position, queries) and indexing/coverage signals, so we can surface ranking changes and detect negative-SEO, click-fraud and manipulation attacks.
- Google Analytics (GA4) — analytics.readonly: to read your GA4 properties and traffic/engagement reports, so we can correlate anomalies with security events and show your data in the dashboard.
- Google Ads (only if you connect it) — read-only reporting access to your campaigns and spend metrics, so we can detect click fraud and wasted ad spend. We do not create, edit, pause or manage campaigns.
- Basic Google profile — your name, email address and account identifier, solely to establish and display the connection and to associate it with your RankShield account.
We request access on a per-feature basis and only after you initiate the connection. We do not request write access to your Google properties, and we do not perform any action in your Google accounts on your behalf beyond reading the data described above.
How we use it. Google data is used only to operate the specific features you connected it to — displaying your metrics, detecting attacks and anomalies, and generating the verifiable security receipts our platform produces. We do not use Google user data for advertising, and we do not sell it or share it with data brokers.
How we store and protect it. OAuth tokens are encrypted at rest and used only to make the read-only API calls above. Where practical we process metrics in transit and retain only the aggregated results needed to power the feature and its history. All Google data is protected with the same modern, post-quantum-capable cryptography and access controls we apply across the platform.
What we never do. RankShield does not transfer or sell your Google data; does not use it for advertising or to build advertising profiles; does not use it to train generalized or foundation AI/ML models; does not allow humans to read it except with your explicit consent, where required for security or to comply with law, or on aggregated/anonymized data for operations; and does not use it to determine creditworthiness or for lending.
Google API Services — Limited Use
RankShield's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your control — revoke access and delete data. You can disconnect Google at any time from within the RankShield plugin or app, and you can revoke RankShield's access directly at myaccount.google.com/permissions. Revoking access stops all further data collection and invalidates our tokens. To have data we already stored deleted, disconnect and then email [email protected] — we delete connected Google data on request, and connected data associated with a closed account is deleted within 30 days except where retention is legally required.
RankShield for iPhone and iPad (App Store)
This section describes the RankShield iOS app specifically, and governs alongside the summary sections above. The app is a device-security tool: it checks what iOS genuinely allows an app to check, gives you a protection score, and provides guidance for the risks a phone app cannot inspect directly. It does not require your name or email, contains no advertising or third-party analytics SDKs, does not use Apple’s Advertising Identifier (IDFA), and performs no cross-app or cross-site tracking.
What the app collects, and why.
- Device and account identifiers — a device identity (Secure Enclave key fingerprint, the vendor identifier (IDFV) and an install identifier) and an anonymous account identifier that groups your own devices together. The account identifier is an opaque key — it is not your name or email. These let us attribute scans to your device, detect device cloning, and protect your account across your devices.
- Device security signals — technical posture signals such as VPN/proxy configuration, screen-recording status, biometric availability, Secure Enclave availability, device fingerprint drift, OS version, network type and a behavioral anomaly baseline. These are used to compute your protection score and detect risks. They describe your device’s security posture, not your content.
- Purchase and subscription information — your subscription status and transaction identifiers, via Apple’s In-App Purchase, to unlock and maintain your paid plan. Payment is handled by Apple; we never receive your card or full payment details.
- Product interaction — that a scan ran and its result, so the app can show your history and protection receipt.
- Phone number — only if you ask. If you use the optional “Check my SIM with carrier” feature, you enter your own number and consent to a one-time lookup. The number is transmitted to our service, which forwards it to a number-intelligence provider (such as Twilio or Telesign) to check for a recent SIM swap. We do not store your raw phone number — we retain only a one-way (HMAC) hash to correlate the result. The feature is entirely opt-in.
- Push token — if you enable notifications, an Apple Push Notification token, used only to deliver your security alerts.
- Network information — our servers record the IP address of scan requests to detect “impossible travel” and concurrent sessions that can indicate a device clone.
Honest scope — what the app does not do. iOS deliberately prevents any third-party app from inspecting parts of your device, and we do not claim otherwise. The app does not check for jailbreak or system integrity; it cannot read your messages, photos or other apps’ content; it cannot enumerate your installed apps or read their permissions; and it cannot access the cellular baseband (IMSI/SS7/SIM internals). Protections that depend on those are shown in the app as carrier-side intelligence or advisory guidance, clearly labelled with their real scope, and never presented as an on-device scan.
Legal bases (EEA/UK GDPR). We process this data to perform our contract with you and provide the security functionality you request; for our legitimate interests in keeping users safe and securing the service; and with your consent where required (the optional carrier check and push notifications), which you may withdraw at any time.
Retention. Scan results and security signals are retained while your account/device is active and for a limited period afterward, then deleted or aggregated. Carrier-check results are kept as a hashed verdict for up to 7 days. Short-lived correlation records (such as active-threat propagation) auto-expire within about 24 hours. Subscription records are retained as needed for accounting and to honor your entitlement.
International transfers. We operate from, and use service providers in, the United States. If you use the app from the EEA, UK or another region, your information may be transferred to and processed in the United States. Where required, we rely on appropriate safeguards for such transfers, including the European Commission’s Standard Contractual Clauses.
Your choices. Notifications and the carrier check are optional and fully under your control. You can request access to, correction of, or deletion of your data at any time by contacting us — see Your rights and choices below. Because we do not sell or share personal information for advertising, no “Do Not Sell or Share” action is needed.
The RankShield Network
Our products share threat intelligence across the RankShield Network to make protection stronger — a threat seen in one place helps defend the rest. This intelligence is about attack patterns and integrity signals, not your private communications or content. The goal is collective defense, not profiling. From the iOS app, what is shared is anonymous threat patterns and counts — never your device identity or personal data.
How we protect information
We apply strong technical and organizational safeguards, including modern and post-quantum-capable cryptography for the attestations and receipts our platform produces. No system can be guaranteed perfectly secure, and we do not claim otherwise; we design to contain and prove, and to fail safe.
Data sharing
We share information only as needed to operate our services (for example, with service providers acting on our behalf under appropriate obligations), to comply with the law, or to protect rights and safety. We do not sell personal information to third parties.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, and to object to certain processing. You can exercise these rights, or ask questions about this policy, by contacting us. We honor privacy-preserving technologies (such as Apple Private Relay) rather than penalizing them.
Cookies and analytics
Our website may use essential cookies and privacy-respecting analytics to operate and improve the site. Where required, we seek consent for non-essential cookies and default to the most privacy-preserving option.
Children
Our products are not directed to children under the age required by applicable law, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy as our products and legal obligations evolve. Material changes will be reflected here with an updated effective date.
Contact us and who we are
RankShield is a trade name (DBA) of SEO Elite Agency, which is the data controller responsible for the information described in this policy, including the information collected by the RankShield iOS app.
SEO Elite Agency (d/b/a RankShield)
1950 Mayfair Street, Ste 313
Naples, FL 34104
United States
[email protected]
Questions about privacy, or to exercise any of the rights described above? Reach us at [email protected], at the address above, or via the contact page. We respond to verified requests within the timeframes required by applicable law. See also our Terms of Service.