TriRank
  • How it works
  • Live demo
  • Pricing
Log inSign upFree audit
Privacy PolicyTerms of ServiceCookie Policy
TriRank

Get ranked on Google, cited by AI, on autopilot.

TriRank - Track AI citations, rankings & clicks | Product Huntai tools code.marketFeatured on Dofollow.ToolsFeatured on LaunchBoostsListed on AIToolHuntFeatured on FoundrListTriRank - Featured on Startup FameFazier badgeFeatured on Twelve ToolsVerified on DANG!Listed on Turbo0Featured on Findly.toolsFeatured on ScrollLaunchTriRank on LaunchIgniterTriRank on Acid ToolsFeatured on HuzzlerTriRank on Nick LaunchesTriRank on EarlyHuntTriRank on Appa ListTriRank on StartupTrusted
Product
  • Features
  • Live demo
  • Free audit
  • Audit service
  • How it works
  • Pricing
  • FAQ
  • Integrations
  • MCP
  • API docs
  • Alternatives by category
  • Chrome extension
  • Extension source
  • Agent skill
Resources
  • Blog
  • Glossary
  • Compare
  • Reviews
  • GEO tools compared
  • Solutions
  • AI Models
  • Free tools
  • Open data
  • AI Visibility Benchmark
  • AI Citation Sources
  • SaaS DR Leaderboard
  • AI Crawler Stats
Company
  • About
  • Methodology
  • Editorial promise
  • Contact
  • Roadmap
  • Changelog
Legal
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
© 2026 TriRank. All rights reserved.

Privacy Policy

How TriRank collects, uses, and protects your data — including data accessed from Google Search Console when you connect your account.

Last updated Aug 26, 2026

Introduction

This Privacy Policy explains how TriRank ("we", "us", "our") collects, uses, stores, and protects your information when you use our services at trirankai.com. It includes a dedicated section describing how we handle data obtained from Google Search Console when you choose to connect your account.

Information We Collect

  • Account Information: Name, email address, and authentication details you provide when registering or signing in (including via Google or GitHub sign-in).
  • Usage Data: Information about how you interact with our application, such as pages visited and features used.
  • Device Information: Technical details such as IP address, browser type, and operating system.
  • Connected Data Sources: When you connect a data source such as Google Search Console, we collect performance data from that source as described below.
  • Free-audit email requests: If you use the optional form under a free audit report to have it emailed to you, we store the address you enter, without an account. See "Emailing you your free audit" below.

Google User Data (Google Search Console)

TriRank lets you connect your Google Search Console account so we can show you how your own websites perform in Google Search. This section describes exactly how we handle that data.

What we access

When you connect Google Search Console, you grant TriRank the read-only scope https://www.googleapis.com/auth/webmasters.readonly. Using this scope we access:

  • The list of Search Console properties your Google account can access, so you can choose which site to analyze.
  • Search Analytics performance data for the properties you choose: search queries, landing pages, clicks, impressions, click-through rate (CTR), and average position, broken down by date.

We request only this single read-only scope. We never request write access, and we cannot modify, add to, or delete anything in your Search Console account.

How we access it

Authorization uses Google's OAuth 2.0 web-server flow with offline access, so TriRank receives a refresh token that lets it fetch your latest performance data on your behalf. We never see or store your Google password.

How we store it

  • Your Google OAuth refresh token is encrypted at rest using AES-256-GCM before it is stored. The encryption key is held separately as a server secret and is never exposed or logged.
  • The performance metrics we retrieve (queries, pages, clicks, impressions, CTR, and position) are stored in our database so we can display your trends and reports over time.

How we use it

We use your Search Console data solely to provide the TriRank features you request — your rankings, keyword opportunities, and performance reports — so you can see how your own sites perform. We do not:

  • sell your Google user data;
  • transfer it to third parties except sub-processors strictly necessary to operate the service;
  • use it for advertising; or
  • use it to develop, improve, or train generalized artificial intelligence or machine-learning models.

Our sub-processors for Google user data are: Cloudflare (hosting and infrastructure), Anthropic (AI content generation — receives only the target keyword a user or their pipeline selects, never raw Search Console metrics), and Perplexity (AI-visibility checks — receives only derived search query strings used to test whether AI engines cite the user's site, never metric values).

You may also choose to create a public share link (/r/<token>) for a site's report. While that link is active, anyone holding it can see the aggregated, derived metrics for the site you selected — rankings, clicks, and AI-citation statistics — without signing in. A share link never exposes your Search Console credentials, your OAuth token, or your other sites. You create these links yourself, they are never generated automatically, and you can revoke one at any time; revocation takes effect immediately and the link stops working.

Data retention and deletion

We retain the Search Console performance data we collect so we can show you historical trends over time. You can disconnect Google Search Console at any time from the Connections page; disconnecting immediately and permanently deletes the stored, encrypted authorization token, and no further data is retrieved. To delete the performance data we have already collected, delete your account or contact us, and we will remove it.

Limited Use disclosure

TriRank's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

The TriRank Browser Extension

The TriRank extension for Chrome shows what AI engines already know about the site you are viewing, and tests whether AI crawlers can reach it. It works without an account. Two things can tie its lookups to a TriRank identity, and both are listed here rather than left to be discovered: a session you already hold on trirankai.com, which your browser attaches by itself, and an optional API key you paste into the panel. Neither is required to use it, and this section says exactly what each one changes. It describes what it reads, what leaves your device, and what it stores.

What it reads

When you click the TriRank toolbar icon, the extension reads the page you are on after its JavaScript has run, so that it sees the page a reader sees rather than the raw HTML. It collects the page's structure and metadata — not your interaction with it:

  • headings: their levels, their order, and their text;
  • the page's title, meta description, meta robots directive, canonical link, viewport, and HTML lang;
  • Open Graph and Twitter card tags, and the site name they declare;
  • structured data (JSON-LD) blocks, copied under fixed limits on depth, number of fields, value length, and array size — the panel shows how much each limit dropped; and, where the page declares an FAQ, the questions in that block (up to 50 of them, each up to 240 characters) together with whether each one also appears in the page's visible text;
  • links: up to 150 of them, with their targets and up to 120 characters of anchor text;
  • images: up to 100 of them, with their alt and title text;
  • counts that describe the page's shape: lists, list items, tables, table rows, numerals, how much of the heading text is CJK, and how many question-and-answer widgets the page uses;
  • the page's robots directives, hreflang annotations, declared sitemaps, and whether an llms.txt is published, which it reads by requesting robots.txt, llms.txt and the sitemaps from the site itself;
  • how the site answers a request for an address nobody has published. On every scan, automatically and without you pressing anything, the extension sends one GET to a path on the site you are viewing that is generated fresh each time and cannot exist — /__trirank-unknown-url-probe- followed by eight random characters. A site that returns a proper 404 for an unknown address and a site that answers one with a normal-looking page are treated very differently by search and AI engines, and there is no way to tell them apart without asking. The site's operator will see this as a 404 in their access log, for a path nobody has ever linked to, and the path names us so they can tell who asked. The same site is not probed again for ten minutes. What is kept from the answer is the status code, whether it redirected and to where, the size of the response and whether it was HTML — never the body;
  • the page's full address, including any query string.

It does not read form fields, input values, cookies, browser storage, or anything on a page where you have not opened the panel.

How it reads it

The extension has no standing access to your browsing. It relies on Chrome's activeTab permission, which Chrome grants only at the moment you click the toolbar icon and revokes as soon as you navigate away. There is no content script running in the background, and no list of sites it watches. If you never click the icon on a page, the extension never sees that page.

To read the page after its scripts have run, it runs a single read-only function inside the tab. That function only reads: it does not modify the page, inject anything into it, or act on the page on your behalf.

What leaves your device

The domain name, and your API key if you connected one. When the panel opens, the extension asks TriRank what we already know about that domain, at /api/signals/<domain> and /api/site-cache/<domain>. The domain name is the entire request body: no path, no query string, and no page content.

If you are signed in on trirankai.com in this browser, those two requests carry that site's session cookie. Your browser attaches it; the extension neither reads nor stores it, and holds no permission that would let it. We use it for one thing: to recognise which plan the account is on and count the lookup against that account's daily allowance. It is sent to trirankai.com and nowhere else — in particular it is never attached to any request made to the site you are viewing. If you are not signed in there, no cookie is sent and those requests carry no identifier for you.

⚠️ This is worth reading twice, because it needs nothing from you: being signed in on our website is enough. There is no separate step in the extension, and the only ways to stop it are to sign out on trirankai.com or to remove the extension.

When the panel opens it also asks us once who you are. That is a GET to /api/me on trirankai.com, carrying the same session cookie or API key as the lookups above, and it answers with your plan, how much of today's allowance you have used, your display name and your initials. It exists so the panel can draw the account corner immediately instead of leaving it blank until a site lookup returns. If you have a profile picture, one more GET goes to /api/me/avatar to fetch it. Neither request mentions the site you are viewing, and the picture is not stored: it is held in memory for as long as the panel is open and fetched again next time. If you are not signed in and have connected no key, both answer as an anonymous visitor and there is nothing to draw.

There is a third request, and it is the one you ask for: signing out. Pressing Sign out in the panel sends one POST to /api/auth/sign-out on trirankai.com, carrying that same session cookie so the server knows which session to end. It is never sent unless you press that button, and its whole effect is that your browser is told to discard the session cookie. The extension does not read that cookie before, during or after — it holds no permission that would let it.

And a fourth, also only when you ask for it: refreshing a traffic estimate. The Traffic screen shows a Similarweb estimate we already had stored. Pressing Refresh this estimate on that screen sends one POST to /api/site-refresh/<domain> on trirankai.com, carrying the domain name and the same session cookie or API key as the lookups above. It is the only request the extension makes that can cost us money — it may buy a new reading from Similarweb — so it is charged against a daily allowance on your account, and it is never sent unless you press that button. Like the lookups, the domain name is the entire request body: no path, no query string, no page content. It changes only that one stored estimate for that one domain.

If you have not connected a key, that is the whole of it: the request carries no identifier for you, we cannot tell who made it, and we cannot link it to a TriRank account.

If you have connected one, the key travels with those two requests in an Authorization header, and it is an identifier: it names the TriRank account that issued it, so those two lookups are attributable to you and are counted against that account's daily allowance. That is the entire effect of connecting — it raises the allowance and tells the panel which plan you are on. It changes nothing about what the extension reads or sends. The key is sent to trirankai.com and to nowhere else, it is never attached to any request made to the site you are viewing, and disconnecting deletes it from this browser.

Everything listed under "What it reads" stays on your device. It is passed from the extension's background worker to the extension's own panel and is never uploaded: no request the extension makes carries it, and it is never written anywhere outside your browser.

Both endpoints answer only from what we have already stored. They never start a new measurement, so opening the panel on a site does not cause us to go and crawl or analyze it.

The crawler reachability test

This is the one part of the extension that requests something from the site you are viewing under another party's name, and it deserves to be described plainly, because those requests appear in that site's server logs as coming from an AI crawler. Everything else the extension sends to that site is automatic and goes out under your own browser's name: four requests per scan — robots.txt, llms.txt, the sitemaps, and the unknown-address probe described above, which is the one that shows up as a 404 for a path nobody has published. Those reach the site and appear in its logs too, but as ordinary requests from your browser, not as somebody else. Only what this section describes goes out under another party's name, and only after you press the button.

When you press the reachability button, the extension asks the site for its robots.txt, and then, for each AI crawler, requests the current page while identifying itself as that crawler — for example as GPTBot or PerplexityBot. That is the only way to learn what a site actually returns to those crawlers, rather than what it declares. If you run this on a site you do not operate, its operator will see those requests in their logs.

Three limits are built into it:

  • Your cookies never ride along. The requests omit credentials, so your own session with that site is never sent out under a crawler's name.
  • A crawler that robots.txt has already turned away is not impersonated. Where the site's robots.txt disallows a crawler, the extension records that and skips the request rather than sending it anyway.
  • We never invent a User-Agent. Of the twenty-three crawlers the panel reports on, only the five whose operators publish a User-Agent string we have transcribed are actually requested. For the other eighteen the extension reports what robots.txt says and states plainly that it did not test them.

The test runs only when you press the button. It is never triggered automatically, and the same page is not re-tested within ten minutes.

What it stores, and for how long

The extension stores what it reads in Chrome's session storage, which the browser clears when it closes. It never uses synced storage, so nothing it holds is copied to your other devices.

Three things are kept there: the address of the tab the panel was opened on; the result of a crawler reachability test, which is reused for ten minutes so that reopening the panel on the same page does not send that site a second round of crawler requests; and the result of the unknown-address probe, held once per site under a key of the form unknownurl:: followed by that site's origin, and reused for the same ten minutes, for the same reason.

Five things are kept longer, on purpose, in local storage on this device — two of them display preferences (theme, zoom level). All five survive a browser restart; none is ever uploaded; and because this is local rather than synced storage, none is copied to your other devices.

  • Your choice of light or dark theme, so the panel opens the way you left it. It stays until you change it or clear the extension's data.
  • The panel's zoom level, one of four steps between 85% and 130%, changed with Cmd or Ctrl and =, - or 0. It is a display preference and nothing else — it records how large you like the panel, not anything about you or the pages you visit — and it stays until you change it or clear the extension's data.
  • The TriRank API key you connected, if you connected one. It is stored so the panel does not have to ask for it again, it is sent only to trirankai.com, and pressing Disconnect deletes it from this browser.
  • A count of how many times a lookup has returned something, capped at three. It exists for one purpose — to decide whether to show a one-line invitation to rate the extension — and it stops counting once it reaches three, so it is not a record of how much you use the panel.
  • Whether you have closed that invitation. If you have, it is not shown again.

What it does not do

  • No account is required. Two things can connect its lookups to a TriRank user and there is no third: a session you hold on trirankai.com, and a key you paste. Signing out there, or pressing Disconnect here, ends the one it belongs to.
  • No password is ever asked for or handled: connecting means pasting a key you generated on our own settings page, not signing in through the extension.
  • No analytics, telemetry, crash reporting, or usage tracking of any kind.
  • No advertising, no selling or sharing of what it reads, and no use of it to train models.
  • No remote code: everything it runs ships inside the extension package.

Fetching the site you ask us to check

Emailing you your free audit

The free audit at /free-audit is public and needs no account. Beneath the finished report there is an optional form that asks for your email address. Nothing about the report depends on it: the report is fully rendered before that form appears, and it stays exactly as it is whether or not you use it.

What we store. If you submit the form we store your email address (lowercased), the domain you audited, the language you were reading in, the date your recheck falls due, whether it has been sent yet, and a random token that identifies your unsubscribe link. That is the whole record. There is no account behind it, and we store no name and no password. We also count submissions per IP address for the current day, as an abuse limit; that counter holds no address.

What we send. For each domain you ask about, we email you twice and no more: once immediately, with a link to that domain's report page, and once when the recheck falls due about two weeks later, describing what changed. We do not add the address to our newsletter, and we do not sell it, rent it, or pass it to anyone else for their own marketing.

How to stop it. Every one of those emails carries an unsubscribe link in the body and a List-Unsubscribe header, so your mail application may also offer a one-click unsubscribe of its own. Either one stops all further audit email to that address at once, and neither needs an account or a login.

How long we keep it. We keep the record for as long as we may still owe you a recheck. After you unsubscribe we keep the address itself, for one purpose only: so that we can honour that choice and never email it again. If you would rather we erase it altogether, contact us and we will delete it.

How We Use Your Information

Beyond the Google data described above, we use your information to:

  • provide and maintain our services;
  • authenticate you and keep your account secure;
  • provide customer support;
  • communicate service updates; and
  • detect, prevent, and address technical issues.

Data Security

We implement appropriate technical and organizational measures to protect your information, including encryption of sensitive credentials at rest and encrypted transport (HTTPS). No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.

Third-Party Services

We rely on third-party sub-processors to operate our service (for example, infrastructure hosting, email delivery, and payment processing). These providers process data only as needed to perform services on our behalf and are bound by confidentiality obligations.

Analytics that run on our public pages

Two analytics services load on every page of the public site, each under its own privacy policy. Google Analytics measures aggregate traffic. Microsoft Clarity records session replays and heatmaps — the pages you view, your clicks and your scrolling can be replayed by us as a recording of your visit; Clarity masks text input by default, so what you type into a form is not captured. Both set their own cookies. The Cookie Policy names them and explains how to block them.

Third-party badges in our footer

Our footer shows listing badges from directories that feature TriRank. Each is an image served from that directory's own domain, so when the footer comes into view that domain receives your IP address, your browser's user agent and the page you were on. They are lazy-loaded, so they are only requested if you scroll to the footer. The hosts are api.producthunt.com, code.market, dofollow.tools, launchboosts.com, aitoolhunt.co, foundrlist.com, startupfa.me, fazier.com, twelve.tools, dang.ai, turbo0.com, findly.tools and scrolllaunch.com, plus climate.stripe.com for the Stripe Climate badge. We send them nothing about you; what they receive is what any request to a server reveals.

Your Rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data. You can disconnect data sources at any time, and you can delete your account from your account settings. To exercise any of these rights, contact us.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the date above.

Contact Us

If you have any questions about this Privacy Policy, please contact us.