Privacy Policy
Last updated: September 16, 2026
1. Who we are
RANKT (“we”, “us”) is operated by RANKT LLC, a limited liability company registered in the State of Florida, United States (document number L26000363908), with its registered address at 7301 Wiles Rd Ste 201, Coral Springs, FL 33067, United States. You can reach us at info@ranktapp.com or +1 754 259 1582.
RANKT provides a verified score for content creators based on their Instagram performance. For any privacy question or request, contact us at info@ranktapp.com.
2. Information we collect
Account information: when you create an account we collect your email address and authentication credentials (managed by our infrastructure provider, Supabase). Your profile stores your display name, an Instagram handle, your chosen content niche, and your CreatorScore and tier once calculated.
Instagram data (with your permission): when you connect your Instagram professional account through Meta’s official API, we access and store: your follower count and account creation date; your profile picture (we store the link Instagram provides, not a copy of the image); and for your recent posts (up to 100), the post type, timestamp, caption text, and performance metrics (reach, views, likes, comments, saves, shares). We store an access token that allows us to read this data on your behalf; this token is stored server-side and is never exposed in the app.
We do NOT collect: your Instagram password (authentication happens on Meta’s own login), your private messages, your photos or videos (other than your public profile picture, above), your contacts, or your precise location.
3. How we use your information
We use your Instagram data for one purpose: to calculate your CreatorScore and the insights we show you inside the app (your score, tier, pillars, weekly mission, and shareable credential). We do not use your data for advertising. We do not sell your data. We do not share your data with third parties for their own purposes.
4. Where your data lives
Your data is stored with Supabase, our infrastructure provider, which acts as a data processor on our behalf. Two other processors handle narrow, specific jobs.
PostHog provides product analytics. We send a small set of events about how the app is used (for example, that a session started) so we can tell which parts of RANKT work and which do not. Your events are attached to an opaque account identifier, not to your name, your email, or your Instagram handle. We do not use advertising SDKs, we do not run cross-application tracking, and we do not build advertising profiles.
Resend delivers email. It is used only for account email such as password recovery.
Beyond Supabase, PostHog, Resend, Meta (which you connect to directly), and the notification services described in section 5, no third party receives your data. We do not sell it and we do not share it for anyone else's purposes.
5. Push notifications
What we store: if you turn notifications on, we store a push token issued by Expo for the device you are using, together with the platform it belongs to (iOS or Android) and the account it belongs to. The token identifies that installation of the app, not you by name. We keep one token per device platform per account, and it is replaced each time the app opens rather than accumulated. No push token is stored unless your phone has granted notification permission: without it we never request one. We also store your notification preference, which exists for every account whether or not notifications are on, and one record per week for that Monday notification. That weekly record holds the week it belongs to, which of two fixed messages was sent, the delivery identifiers the push service returned and the device token they refer to. It never holds the text of the notification and never holds your score.
What we use it for: RANKT works fully without notifications; turning them on is optional and changes nothing else in the app. When they are on, we use them for one thing: a notification once a week, on Monday, telling you that your weekly reading is in. It may include how your score moved since the previous week (for example, “+14 since last week”), once you have a previous week to compare against. The score itself is never sent in a notification, because a notification can be read from a locked screen. Tapping it opens the app. We do not send marketing notifications: the app has a single sending path and its wording is fixed in code.
Who it goes through: Expo operates the push service and acts as a processor on our behalf. What we send it is the token, the notification title and body, a marker for the week it belongs to, and the technical delivery settings the service needs. Your name, your email address, your Instagram handle and your score are not part of anything we send. Expo hands the notification to Apple (Apple Push Notification service) on iPhone, or to Google (Firebase Cloud Messaging) on Android, which deliver it to your device. Expo deletes the notification content once it has been handed to Apple or Google.
How long we keep it: we keep the token while the device stays registered. Turning the notification off also removes the token from our servers; turning it back on registers a new one. We also delete it when you sign out of RANKT on that device, and when the push service reports that the app is no longer installed on it. The weekly notification records, including the device token they refer to, are kept while your account exists and are deleted with it.
How to turn it off: inside the app, go to Profile, then Account, then Notifications, and switch “Monday reading” off. Your reading still updates every Monday; we just stop notifying you about it. You can also turn notifications off for RANKT in your phone’s own settings, which stops delivery whatever the app says.
6. Data retention
Your CreatorScore is recalculated weekly, and we keep that weekly history — one reading per week — so we can show you how your score moves over time. We also keep a daily record of your follower count for up to 120 days, which is what lets us measure growth. Your most recent Instagram post data is replaced on each refresh rather than archived.
We retain your data while your account is active. When your account is deleted, all of your data is permanently removed from our systems immediately, including your profile, Instagram connection and access token, cached Instagram data, your full score history, follower history, and missions. Deletion is immediate and permanent; nothing is kept in an archive.
7. Your rights and choices
You can disconnect Instagram at any time from your device’s settings on Meta’s side (Instagram app → Settings → Website permissions / Apps and websites → remove RANKT), which invalidates our access. You can delete your account and all associated data at any time from inside the app, under Profile → Account → Delete account; deletion is immediate. You can also see our Data Deletion page or email info@ranktapp.com. Depending on where you live, you may have additional rights (such as access or correction) under applicable law; contact us to exercise them.
8. Security
Access to your data is restricted through row-level security and server-side controls. Instagram access tokens are held server-side only and are never exposed to the client application.
9. Children
RANKT is not directed at children under 13 (or the minimum age required by Instagram in your country), and we do not knowingly collect data from them.
10. Changes to this policy
We may update this policy as RANKT evolves. We will update the date above and, for significant changes, notify you in the app.