Customer Identity & Communication Policy
CICP — Our Privacy Policy, Reinvented
Introduction
Most privacy policies are afterthoughts — legal documents written to protect companies, not people. At RankForge, we rejected that approach entirely. We created the Customer Identity and Communication Policy (CICP) because we believe that privacy governance deserves the same engineering rigor as our SEO tools. The CICP is not a compliance checkbox; it is a living framework that defines how we interact with your identity, your data, and your trust. Every section of this policy was written with a specific philosophy: your identity belongs to you, your data should never be a commodity, and every communication from RankForge must earn its place in your inbox.
The CICP replaces the traditional "Privacy Policy" label because the word "privacy" alone fails to capture the full scope of what we govern. This policy covers not just data collection and storage, but the entire lifecycle of your identity on RankForge.cloud — from the moment you first visit our free SEO tools, through every interaction with our AI chat assistant, to the way we communicate with you via email through Brevo. We chose the name deliberately: "Customer Identity" because your identity is sacred, and "Communication" because how we talk to you matters as much as what we do with your data.
This document applies to all services offered by RankForge, including our Performance Analyzer tool, SSL Checker, Broken Link Checker, DNS Lookup, SERP Preview, OG Preview, HTTP Headers tool, Redirect Checker, Meta Tag Generator, Schema Generator, Robots.txt Generator, Sitemap Generator, Keyword Density Analyzer, Word Counter, Text Cleaner, Lorem Ipsum Generator, URL Encoder/Decoder, Base64 Tool, HTML Minifier, CSS Minifier, and our AI-powered SEO chat assistant. All of these tools are accessible at rankforge.cloud and are governed by the principles outlined below.
1. Identity Philosophy
RankForge views user identity not as a collection of data points to be harvested, but as an expression of digital sovereignty. When you visit rankforge.cloud, you are not a "user" in the reductive sense — you are a professional, a business owner, a developer, or a marketer who has chosen to trust our platform with your time and attention. That choice carries weight, and we honor it by treating your identity with the respect it deserves. Your email address is not a marketing asset. Your browsing patterns are not a product. Your tool inputs are not training data.
Digital sovereignty means that you retain ultimate control over how your identity intersects with RankForge. You decide whether to provide an email address, and if you do, you decide which tier of engagement suits your needs. You decide whether to accept cookies, and you can revoke that consent at any time. You decide whether to subscribe to our newsletter, and unsubscribing takes exactly one click. These are not concessions we grudgingly offer — they are architectural principles built into every system we deploy on Cloudflare Workers and Cloudflare D1.
We recognize that identity in the digital age is fragmented, contextual, and deeply personal. A freelancer checking their own site's performance score at 2 AM has different identity needs than a marketing director managing a team's SEO workflow at noon. Our three-tier email identity system, detailed in Section 4, reflects this understanding. We do not force every visitor into the same data-collection mold. Instead, we calibrate our identity requirements to match the actual risk and privilege level of each interaction.
2. Information We Collect
Transparency demands specificity. We do not hide behind vague language about "information you provide" — we tell you exactly what we encounter, how we process it, and what happens to it afterward. RankForge collects information through several distinct channels, each governed by different rules and retention policies.
URLs and Text Inputs: When you use our SEO tools — such as the Performance Analyzer at /speed-audit, the SSL Checker at /ssl-checker, or the DNS Lookup at /dns-lookup — you submit URLs or text content for analysis. These inputs are processed in real time by our Cloudflare Workers backend and are not stored on our servers after the result is delivered to your browser. The URL you submit for the Performance Analyzer is analyzed directly in your browser using native web APIs, and no data is sent to any external API or persisted in Cloudflare D1 or any other storage system. Your text inputs for tools like the Keyword Density Analyzer or Meta Tag Generator are processed entirely within your browser session and are never transmitted to our servers at all.
Automated Data: Like all internet-facing services, RankForge receives standard access data when you visit our site. This includes your IP address (as seen by Cloudflare's edge network), browser type and version, operating system, referring URL, pages visited, and timestamps. Cloudflare logs this data as part of its DDoS protection and content delivery services. We use this data solely for security monitoring, performance optimization, and abuse prevention. We do not correlate IP addresses with individual identities for marketing or profiling purposes.
Cookies: RankForge uses cookies for three specific purposes. Essential cookies maintain your session state if you log into the admin dashboard. Analytics cookies, managed through our advertising partner Ezoic, help us understand aggregate usage patterns such as which tools are most popular and where visitors encounter friction. Advertising cookies, also managed by Ezoic, support the free model that allows us to offer all 20+ SEO tools at no cost. You can manage your cookie preferences through the Ezoic consent management tool that appears when you first visit rankforge.cloud, or through your browser's cookie settings at any time.
3. How We Use Information
Every piece of information RankForge encounters serves a specific, documented purpose. We do not collect data speculatively — there is no "we might find a use for this later" category in our data practices. The information we process is used exclusively for the following purposes: real-time tool processing, security and abuse prevention, analytics-driven service improvement, email communications you have explicitly requested, and legal compliance where required.
Real-time processing is the core of RankForge's service. When you submit a URL to our Performance Analyzer, it is analyzed directly in your browser using native web APIs — no external API calls are made. When you use our DNS Lookup, we query Cloudflare's DNS-over-HTTPS endpoint and return the records. In every case, processing is ephemeral — the data flows through our Cloudflare Workers and is not persisted after the response is sent. This architectural decision was intentional: by not storing tool inputs or results, we eliminate entire categories of privacy risk.
We use aggregated analytics to understand how RankForge is used in the aggregate — which tools receive the most traffic, what times of day see peak usage, and how visitors navigate between pages. These analytics never include personally identifiable information. We cannot and do not use analytics to build individual profiles, track specific users across sessions, or target individuals with personalized content. Our analytics serve one purpose: making RankForge better for everyone who uses it.
Most importantly, we never sell, rent, trade, or share your personal information with third parties for their marketing purposes. This is not a qualified statement with fine-print exceptions — it is an absolute prohibition built into our data governance framework. Your data is not a revenue stream for RankForge. Our revenue comes from advertising partnerships, and even those are structured to minimize the data shared with our ad partners.
4. Email Identity Tiers
RankForge operates a three-tier email identity system that calibrates the level of personal information we require to the sensitivity of the action being performed. This system was designed to enforce the principle of minimum necessary identity — we only ask for the level of identification that the specific action genuinely requires, and nothing more.
Tier 1 — Branded/Verified Email: This tier requires an email address associated with a verified domain (e.g., admin@yourcompany.com rather than yourcompany@gmail.com). Tier 1 identity is required for actions that carry significant security or data-access implications: accessing the RankForge admin dashboard, managing API keys, exporting data from Cloudflare D1, verifying brand ownership for account modifications, and performing any action that could affect the configuration or security of the RankForge platform. Branded emails matter for security because they provide a chain of accountability. When you use admin@yourcompany.com, we can verify that the email domain matches the organization through DNS/MX record verification. This makes impersonation dramatically harder than with free email providers, where anyone can create an account in seconds. A branded email tells us that the person requesting administrative access has control over the DNS records of their organization's domain — a meaningful proof of identity that goes far beyond a simple username and password.
Tier 2 — Standard Email: This tier accepts any valid email address, including those from free providers like Gmail, Outlook, or Yahoo. Tier 2 identity is accepted for actions that benefit from a communication channel but do not carry significant security implications: subscribing to the RankForge newsletter via Brevo, submitting messages through our contact form, using tools that store user preferences, and posting comments on blog articles. We chose to accept standard emails for these interactions because the risk profile is lower, and we do not want to exclude users who legitimately use free email providers for everyday communication.
Tier 3 — No Email Required: This tier requires no personal information whatsoever. Tier 3 access covers the vast majority of RankForge's functionality: using all free SEO tools (Performance Analyzer, SSL Checker, Broken Link Checker, DNS Lookup, SERP Preview, OG Preview, HTTP Headers, Redirect Checker, Meta Tag Generator, Schema Generator, Robots.txt Generator, Sitemap Generator, Keyword Density Analyzer, Word Counter, Text Cleaner, Lorem Ipsum Generator, URL Encoder/Decoder, Base64 Tool, HTML Minifier, CSS Minifier), reading our blog content, accessing the AI chat assistant, and reading all policy documents including this one. We designed Tier 3 to be as broad as possible because we believe that access to essential SEO tools should never be gated behind an email wall.
5. Data Retention
RankForge's data retention philosophy is simple: if we do not need it, we do not keep it. This principle governs every aspect of our storage architecture on Cloudflare D1 and Cloudflare Workers. Tool inputs and results are never stored on our servers — they are processed in real time and discarded immediately after delivery. This means that your Performance audit URLs, DNS lookup queries, SSL check domains, and all other tool inputs exist in our system only for the milliseconds required to process them, and are never written to persistent storage.
Server access logs, which include IP addresses, request paths, user agents, and timestamps, are retained for a maximum of 30 days for security monitoring and abuse prevention. After 30 days, these logs are automatically purged from Cloudflare's systems. Contact form submissions and newsletter subscription records stored in Cloudflare D1 are retained for as long as necessary to provide the service you requested — for example, we retain your email address in our subscriber database for as long as you remain subscribed to the newsletter, and we delete it promptly upon your unsubscribe request.
Admin session tokens stored in Cloudflare D1 expire automatically after 7 days of inactivity. When a session expires, the token is deleted from the database entirely. We do not maintain historical session logs or track individual login patterns over time. This aggressive retention minimization is a deliberate architectural choice that trades some analytical capability for significantly stronger privacy protection.
6. Third-Party Services
RankForge integrates with several third-party services to deliver our tools and maintain our platform. Each integration was chosen with privacy as a primary criterion, and each is governed by its own privacy policy in addition to this CICP. We provide full disclosure of every third-party service below so that you can make informed decisions about your data.
Performance Analyzer: When you use our Performance Analyzer tool, the URL you submit is analyzed directly in your browser using native web APIs (Performance API, DOMParser, Fetch API). No data is sent to any external API or third-party service. Your analysis runs entirely within your browser session, and no URLs or results are transmitted to our servers or any third party.
Cloudflare DNS: Our DNS Lookup tool queries Cloudflare's public DNS-over-HTTPS endpoint at cloudflare-dns.com. These queries are processed according to Cloudflare's privacy policy, which commits to not selling DNS query data and to purging query logs within 24 hours. We chose Cloudflare DNS specifically because of their strong privacy commitments regarding DNS query data.
Cloudflare Workers: Our entire backend runs on Cloudflare Workers, which processes your requests at the edge of Cloudflare's global network. Cloudflare Workers does not persist request data between invocations, making it inherently privacy-friendly. Request data exists in memory only for the duration of the Worker execution and is discarded immediately afterward.
Cloudflare D1: We use Cloudflare D1 as our SQL database for storing admin credentials, contact form submissions, newsletter subscriptions, and application settings. D1 data is encrypted at rest and accessible only through authenticated Worker scripts. We never store tool inputs or results in D1.
Brevo: We use Brevo (formerly Sendinblue) for email delivery, including newsletter distribution and contact form auto-replies. When you subscribe to our newsletter or submit a contact form, your email address and message content are processed by Brevo for delivery purposes. Brevo's privacy policy governs their handling of this data. We configure Brevo to comply with our no-spam commitment and include unsubscribe links in every email.
Workers AI: Our AI chat assistant is powered by Cloudflare Workers AI, which processes chat messages ephemerally on Cloudflare's infrastructure. Chat messages are not stored, logged, or used for model training. The AI processes your input, generates a response, and discards the conversation data immediately.
7. Advertising and Cookies
RankForge partners with Ezoic to display advertisements on rankforge.cloud, which enables us to offer all 20+ SEO tools completely free of charge. We understand that advertising can feel intrusive, and we have structured our Ezoic partnership to balance sustainability with user respect. Ezoic serves as our advertising technology partner, handling ad selection, placement, and performance optimization across our platform.
The cookies used in connection with advertising fall into several categories. Essential cookies ensure that the site functions correctly and that your tool sessions work as expected. Performance cookies help us and Ezoic understand how pages are performing, where visitors encounter issues, and how to improve load times. Functionality cookies remember your preferences and settings between visits. Targeting and advertising cookies are used by Ezoic to serve advertisements that are relevant to your interests, based on your browsing behavior on rankforge.cloud and other websites in Ezoic's network.
When you first visit rankforge.cloud, Ezoic's consent management tool presents you with granular control over which cookie categories you accept. You can accept or reject each category independently, and you can change your preferences at any time by accessing the cookie consent banner. Rejecting advertising cookies does not affect your ability to use any RankForge tool — you will still have full access to all features regardless of your cookie consent choices. We have specifically configured Ezoic to ensure that tool functionality is never dependent on advertising cookie acceptance.
8. Your Rights
RankForge recognizes and respects your data protection rights under all applicable regulations, including the General Data Protection Regulation (GDPR) for EU/EEA residents, the California Consumer Privacy Act (CCPA) for California residents, and the California Online Privacy Protection Act (CalOPPA). Regardless of your jurisdiction, we extend these rights to all RankForge visitors as a matter of principle, not just legal compliance.
Under GDPR, you have the right to access your personal data, request correction of inaccurate data, request deletion of your data (the "right to be forgotten"), restrict processing of your data, request data portability in a structured, commonly used format, and object to processing based on legitimate interests. You also have the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out prior to withdrawal.
Under CCPA, California residents have the right to know what personal information is collected, request deletion of personal information, opt out of the sale of personal information (RankForge does not sell personal information), and not be discriminated against for exercising these rights. Under CalOPPA, you have the right to review our privacy practices as described in this CICP and to request information about how your data has been handled.
To exercise any of these rights, contact us at support@rankforge.cloud. We will respond to all legitimate requests within 30 days. Because we minimize data retention by design — not storing tool inputs, purging server logs within 30 days, and deleting subscriber records upon request — most deletion requests can be fulfilled immediately. For data stored in Cloudflare D1, we will process your request and confirm completion within the 30-day window.
9. Communication Protocols
RankForge communicates with you through carefully controlled channels, and every communication must meet a strict threshold of value before we send it. We use Brevo as our email delivery platform, and all outbound emails include a one-click unsubscribe link as required by CAN-SPAM, CASL, and GDPR. Our communication protocols are designed around a simple principle: we earn your attention or we do not send the message.
Newsletter emails are sent only to subscribers who have explicitly opted in through our subscription form. We send approximately one to four newsletters per month, covering topics such as new tool releases, SEO tips, platform updates, and occasional curated content we believe our subscribers will find valuable. We never send promotional emails on behalf of third parties, and we never share our subscriber list with anyone. Unsubscribing is immediate and permanent — your email address is deleted from our Brevo contact list and our Cloudflare D1 subscriber database within 24 hours of your unsubscribe request.
Transaction-related emails — such as contact form auto-replies and admin notifications — are sent only in direct response to your actions. These are not marketing communications and do not require separate opt-in consent, but they always include our contact information and an option to opt out of future similar communications. For support, you can reach us at support@rankforge.cloud or through our contact form at rankforge.cloud/contact. We respond to all support inquiries within 48 hours during business days.
10. Children's Privacy
RankForge is not directed at children under the age of 13, and we do not knowingly collect personal information from children. Our SEO tools are designed for professionals, business owners, developers, and marketers — audiences that are overwhelmingly adult. If we discover that a child under 13 has provided personal information to RankForge (such as an email address through our contact form or newsletter subscription), we will delete that information from our Cloudflare D1 database and Brevo contact list immediately upon discovery.
Parents or guardians who believe their child has interacted with RankForge in a way that involved personal data submission should contact us at support@rankforge.cloud with the relevant details. We take children's privacy seriously and will act promptly to remove any such data from our systems. Our Ezoic advertising partnership is configured to avoid serving age-inappropriate advertisements, though we cannot guarantee that every ad served by third-party networks meets this standard.
11. Security Measures
RankForge implements multiple layers of security to protect the information that passes through our systems. All traffic to and from rankforge.cloud is encrypted using HTTPS with TLS 1.3, enforced through Cloudflare's SSL/TLS configuration. Cloudflare provides DDoS protection at the network and application layers, mitigating volumetric attacks and sophisticated application-layer exploits before they reach our Workers backend. Rate limiting on all API endpoints prevents abuse and ensures fair resource allocation across all users.
Admin passwords are hashed using a secure hashing algorithm with a cryptographic pepper stored as a Cloudflare Workers secret. This means that even if our Cloudflare D1 database were somehow compromised, the pepper — which is stored separately from the database — would be required to attempt any password cracking. Session tokens are cryptographically random UUIDs stored in D1 with automatic expiration after 7 days of inactivity. Cross-site request forgery (CSRF) protection is enforced on all state-changing API endpoints by validating the Origin header against our allowed origins list.
We regularly review our security posture and update our protections as new threats and best practices emerge. However, no system connected to the internet can be guaranteed to be completely secure. We encourage all users to practice good security hygiene, including using strong, unique passwords and keeping their browsers and operating systems up to date.
12. Changes to This Policy
RankForge may update this Customer Identity and Communication Policy from time to time to reflect changes in our practices, technology, legal requirements, or organizational structure. When we make material changes, we will update the "Last updated" date at the top of this page and, for significant changes, post a notice on the RankForge homepage for at least 30 days. For subscribers to our newsletter, we will communicate material policy changes via email through Brevo, giving you the opportunity to review the changes before they take effect.
Your continued use of RankForge after any changes to this CICP constitutes acceptance of the revised policy. We encourage you to review this page periodically to stay informed about how we protect your identity and data. If you do not agree with a revised version of this policy, you should discontinue use of RankForge and request deletion of any personal data you have provided.
13. Contact
If you have any questions, concerns, or requests regarding this Customer Identity and Communication Policy, please contact us at support@rankforge.cloud or through our Contact page. We take all privacy inquiries seriously and will respond within 48 hours during business days. For data access, correction, or deletion requests, please include enough information for us to verify your identity and locate the relevant data in our systems.