Privacy policy
This policy explains what Upranke Index (“we”, “us”), operated by digiPanda Consulting Pvt Ltd, H-112, sector 63,Noida, India, collects when you use https://index.upranke.com, why, who it is shared with, how long it is kept, and the choices you have.
Upranke Index’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Information we collect
From your Google account (when you sign in)
- Your name, email address and profile picture, and Google’s account identifier — used to create and secure your account.
From Google Search Console (only after you grant access)
| Permission we ask for | What we read or do | Why |
|---|---|---|
https://www.googleapis.com/auth/webmasters | The list of your Search Console properties and your permission level on each; the sitemaps already registered for a property; URL Inspection results for pages you submit; Search Analytics page lists used to skip already-performing pages during bulk import. We resubmit sitemaps that are already registered. | To confirm you own a site before acting on it, to signal new pages through Google’s own channel, and to show you Google’s answer for each page. |
We never change your Search Console settings, add or remove users, or delete properties or sitemaps.
That you give us or we generate for you
- URLs you submit, the results of our checks on those pages, and their history.
- Public content of your pages and your
robots.txt, fetched by our crawler (see our crawler) to run pre-checks and access checks. - Access-log lines you upload or forward from your server or CDN. We keep only requests made by known search and AI crawlers, including the crawler’s IP address and user-agent. Lines from ordinary visitors are discarded while the file is read and never stored.
- Prompts you choose for AI answer checks, and the answers and cited sources returned by the AI services we query.
- Workspace settings, team members you invite, and an audit log of actions taken in your workspace.
Automatically
- A session cookie (
uidx_sid, httpOnly, up to 30 days) to keep you signed in. We use no advertising or analytics cookies. - Your theme choice, kept only in your browser’s local storage.
- Server logs (IP address, time, request path) kept for security and debugging.
2. How we use information
- To provide the features you use: ownership checks, pre-checks, submitting official signals, reading inspection results, crawl proof and AI answer checks.
- To secure the service, prevent abuse and fix problems.
- To contact you about your account, billing and important changes.
We do not sell your information, do not use it for advertising, and do not use data received from Google APIs to develop, improve or train generalised AI or machine-learning models. People at digiPanda Consulting Pvt Ltd do not read your Google data unless you ask us to (for support), it is needed for security or abuse investigation, or the law requires it.
3. Who we share information with
Only the service providers needed to run Upranke Index, each for that purpose alone:
- Hosting: DigitalOcean (Bengaluru, India) runs our servers and database.
- Google: Search Console, URL Inspection and Site Verification APIs, called with your authorisation.
- IndexNow: when you enable it for a verified host, the URLs of your pages (and your IndexNow key, which is public by design) are sent to
api.indexnow.org, which shares them with participating search engines such as Bing. - Payments: Razorpay (payments in INR) or Stripe (payments in USD), whichever you choose at checkout. They collect your payment details directly on their own pages; we never see or store card, UPI or bank details — only a customer and subscription reference, the plan and its status.
- Email delivery: Resend sends our account emails (invites, trial and billing notices, digests you can turn off). It receives the recipient address and the message.
- AI answer check providers (OpenAI, Perplexity, Google Gemini, Anthropic), when you use AI answer checks: we send the prompts you chose. We do not send your Google account data or Search Console data for these checks.
- Keyword research (DataForSEO), when you search for keywords: we send the topic you typed and the market you chose. Nothing about your account or your Search Console data.
- Article writing and fact-checking (Anthropic or OpenAI, whichever is configured), when you create an article: we send the keyword, your site’s address, the URLs of your site’s existing pages, the Search Console queries your site already ranks for on that topic (with positions and impressions), and the draft text for fact-checking with web search. Only at your request, only for that article.
- Your WordPress site, when you connect it: we store the username and an Application Password you create (encrypted) and use them only to create the posts you approve. You can revoke the Application Password in WordPress at any time.
- Index Doctor (Anthropic or OpenAI, whichever is configured), when a page that Google hasn’t indexed is diagnosed — automatically when it lands in “Needs attention”, or when you ask: we send that page’s public text and headings, Google’s inspection result for it, the Search Console queries (with impressions and positions) on its topic, and the addresses and titles of your site’s strongest pages. Technical problems are diagnosed without sending anything to an AI provider. The provider may not use it to train its models under its API terms.
- AI title and meta drafts (Anthropic or OpenAI, whichever is configured), only when you click “Suggest title & meta” on a page: we send that page’s public text and the Search Console queries (with their impressions and positions) for that page, so the draft matches what searchers look for. This is done only at your request, only for that page, and the provider may not use it to train its models under its API terms.
We may disclose information if required by law, or to protect the rights and safety of our users and the service. If digiPanda Consulting Pvt Ltd is involved in a merger or sale, this policy continues to apply to your information.
4. How long we keep it
- Account, workspace and page history: while your account is active.
- Crawler log records: 180 days, then deleted automatically.
- After you ask us to delete your account, we delete your data within 30 days. Encrypted backups roll off within 14 days after that.
5. Security
All traffic uses HTTPS. Google access and refresh tokens are encrypted at rest (AES-256-GCM). Session tokens and ingest tokens are stored only as one-way hashes. Every workspace’s data is isolated from every other workspace’s.
6. Your choices and rights
- Revoke Google access at any time from your Google Account permissions. We stop all Google calls for that connection immediately.
- Access, correct or delete your data by writing to info@upranke.com.
- Grievances (including under India’s Digital Personal Data Protection Act, 2023): Narender Rana, info@upranke.com. We respond within the time the law requires.
7. Children
Upranke Index is a business tool and is not meant for anyone under 18.
8. Changes
If we change this policy in a way that matters, we will tell signed-in users before the change takes effect. The effective date above always shows the current version.
9. Contact
digiPanda Consulting Pvt Ltd, H-112, sector 63,Noida, India · info@upranke.com