How RankQ protects your account and data.

A plain-language look at how authentication, encryption, and payments actually work under the hood, distinct from our legal Privacy Policy.

Encryption

Sensitive credentials, including connected Google account tokens, are encrypted at rest with AES-256-GCM before they're ever stored, using a dedicated encryption key separate from other application secrets.

Authentication & access

Sign in with email/password, magic-link (passwordless), Google, or Microsoft. Sessions use a bearer token or an httpOnly cookie. Auth, email-verification, and password-reset tokens each use a separate signing secret, so a leaked purpose-specific secret can't be used to forge the others.

Payments

Payments are processed by Razorpay. Payment webhooks are verified against the raw signed request body before RankQ trusts them, so a forged webhook call can't be used to grant access.

Server-side enforcement

Plan and feature limits are enforced on the backend for every request, not just hidden in the interface. The UI mirrors these limits for a better experience, but the server is what actually decides what an account can do.

Data retention

If you cancel your subscription, your account data is retained for 30 days, after which it may be permanently deleted.

Reporting a concern

If you believe you've found a security issue, email support@rankq.ai with details and we'll follow up.

RankQ does not currently publish third-party security certifications or audit reports. If formal compliance documentation is required for your organization, contact us directly and we'll work with you.

Questions about how RankQ handles your data?

We're happy to walk through it before you sign up.