Privacy Policy
Last updated: February 2026
1. Introduction
AimRank ("we", "us", "our") is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and share your information when you use the AimRank platform (the "Service").
We comply with the EU General Data Protection Regulation (GDPR) and applicable Lithuanian data protection laws.
2. Data We Collect
Account Data
- Email address
- Username and display name
- Password (stored as a bcrypt hash; we never store plaintext passwords)
- OAuth provider and ID (if you sign in via Google or GitHub)
- Profile information you choose to provide (bio, avatar)
Usage Data
- Rankings you create and their settings
- Votes you cast (entity selections, timestamps, decision time)
- Gamification data (achievements, streaks, points)
Technical Data
- IP address (for rate limiting and fraud detection)
- Browser user agent
- Authentication tokens (stored in your browser's localStorage)
3. How We Use Your Data
- Provide and operate the Service
- Authenticate your identity and secure your account
- Calculate rankings using our algorithms (Glicko-2, Elo, Bradley-Terry, TrueSkill)
- Generate personalized recommendations
- Detect and prevent fraud and abuse
- Send service notifications (ranking updates, achievements)
- Improve the Service based on aggregate usage patterns
4. Legal Basis for Processing
- Contract: Processing necessary to provide the Service you signed up for
- Legitimate interest: Fraud prevention, security, service improvement
- Consent: Optional analytics cookies (if enabled)
5. Data Retention
We retain your data for as long as your account is active. If you delete your account, we anonymize your personal data immediately. Anonymized vote data may be retained for ranking integrity.
6. Data Sharing (Subprocessors)
We do not sell your personal data. The full canonical list of subprocessors, with purpose, data categories, region, and transfer mechanism for each, is at /legal/subprocessors. Summary:
- Amazon Web Services (AWS EMEA SARL): compute, RDS, S3, ElastiCache, Bedrock LLM inference, SES email, all in eu-central-1 (Frankfurt)
- Anthropic Ireland (via AWS Bedrock): Claude models used as LLM-judges when enabled. Article 50 disclosed, inference in eu-central-1
- Stripe Payments Europe Limited (Ireland): subscription billing, VAT-OSS invoicing
- Sentry (EU instance): error monitoring with PII scrubbing enabled
- PostHog EU: opt-in product analytics only (gated on your Cookie Banner consent)
- OAuth identity providers: Google Ireland, GitHub (US, SCCs), only when you choose social sign-in
- Law enforcement: only when required by law and only the minimum data required
We notify business customers under signed DPAs at least 30 days before adding a new subprocessor. To object on data-protection grounds: privacy@aimrank.io.
7. Your Rights (GDPR)
You have the right to:
- Access: View all personal data we hold about you
- Portability: Export your data in machine-readable JSON format (Settings → Privacy)
- Erasure: Delete your account and personal data (Settings → Privacy)
- Rectification: Update your personal information (Settings → Profile)
- Restriction: Request we limit processing of your data
- Objection: Object to processing based on legitimate interest
To exercise any of these rights, use the self-service options in Settings or contact us at privacy@aimrank.io.
8. Cookies
We use essential cookies for authentication (HttpOnly access + refresh tokens). If you accept analytics via the Cookie Banner, we also set a PostHog cookie + localStorage entry (EU-hosted at eu.i.posthog.com) to record anonymous pageviews and clicks. You can choose "Essential only" on the banner; PostHog will not initialise. We do not use third-party advertising or cross-site tracking cookies.
9. Security
We protect your data with: HTTPS encryption in transit, bcrypt password hashing, JWT token-based authentication with blacklisting, rate limiting, account lockout, and structured security audit logging.
10. AI involvement (EU AI Act Article 50)
AimRank is itself an AI-assisted product. Two surfaces involve automated processing by large language models, and we disclose them here so you are never confused about whether a vote or a label was cast by a human or by a machine.
LLM judges as a vote source. The owner of a ranking may optionally invoke an LLM judge (currently Anthropic Claude models running on AWS Bedrock eu-central-1) to cast preference votes alongside human voters. These AI-cast votes are recorded with source="judge:<model>"and excluded from the per-annotator quality metrics in Layer 4 of our methodology. Any ranking containing AI votes shows an "AI-assisted ranking" badge near its title, and the count of AI votes (plus the specific model IDs invoked) is reported in §2.1 of every exported data card. Only the ranking owner can trigger AI votes. They cannot be cast by other users on someone else's ranking.
LLM-assisted post-ranking analysis. When a ranking has an ends_at deadline and a declared goal, an LLM is used to auto-generate a written summary of the ranking's outcome after the ranking closes. These reports are clearly labelled as machine-generated.
No part of AimRank's safety-critical voting flow (qualification, vote ingestion, fraud detection, payment) is mediated by an LLM. Bradley-Terry, Glicko-2, and the other rating algorithms are deterministic and inspectable in our open-source reference implementation. AI use is opt-in by ranking owners and disclosed at every layer where it appears.
11. Contact
If you have questions about this policy or wish to file a complaint, contact us at: privacy@aimrank.io
You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI) at vdai.lrv.lt.