Skip to content
Last updated · August 3, 2026

Privacy policy

This policy describes the intended RankPortfolio data flows. Final legal review is required before launch.

Controller and account data

Division by Heroes e.U. operates RankPortfolio. Supabase supports authentication and application storage. We process account identifiers and workspace configuration to provide the service.

Google Search Console and AI

RankPortfolio requests read-only Search Console access, encrypts refresh tokens server-side, and stores imported daily facts. Bounded evidence may be sent to the configured AI provider to answer a user request; customer data is not enabled for model training by default.

Analytics and cookies

PostHog and Microsoft Clarity are optional analytics providers and initialize only after analytics consent. Private queries, page URLs, chat content, email addresses, billing data, and tokens are excluded.

Rights, retention, and deletion

Authenticated controls support immediate export, Search Console-data deletion, Google disconnection, and account deletion requests. Application records in scope are deleted by the product workflow when the request completes; encrypted infrastructure backups age out under provider retention schedules. Some billing or security records may need legally required retention. Contact support@rankportfolio.com for confirmation or assistance. Legal bases, transfer safeguards, complaint details, and precise periods require counsel review.

Subprocessors

Core infrastructure: Supabase (authentication and database), hosting provider (application delivery), Google (Search Console data source). Product services: Stripe (billing), Brevo (transactional email), configured AI provider (bounded analytical processing). Optional analytics: PostHog and Microsoft Clarity (after consent only). Complete DPAs and international-transfer details are pending final legal review before production launch.