Skip to main content
On this page
  1. Hosting
  2. What NeoRank keeps
  3. Access protection
  4. What is sent, and to whom
  5. What you can do yourself
  6. Retention and rights

Account and plan

Data and privacy

A practical summary of what NeoRank does with your data, drawn from how the product actually works. The [privacy policy](/legal/privacy) remains the reference text: when in doubt, it prevails.

Hosting

The application, its database and its processing workloads are hosted in the European Union, in Belgium: Google Cloud, europe-west1 region. The database is a managed PostgreSQL instance (Cloud SQL) in that region, and the platform's secrets are replicated in that same region.

Some providers may process data outside the European Union: GitHub sign-in (United States), optional audience measurement, the AI providers and the anti-bot protection of the free express check. The privacy policy details them, provider by provider.

What NeoRank keeps

CategoryContent
AccountEmail address, name if you provide one, language, timezone, sign-in method and two-factor enrolments.
Organisation and workspacesName, members, roles and invitations.
Sites and analysesDeclared domains, verification evidence, crawled URLs, public page content, response codes, internal links and the technical findings drawn from them.
AI visibilityYour tracked prompts and prompt groups, the observed AI engines' answers and what is extracted from them: mentions, citations, sentiment, KPIs.
Google AI OverviewsManual readings entered by a member (whether an overview showed, site cited, optional URL and note) and, when enabled, automatic tracking of your tracked keywords.
ConnectorsThe access tokens of the services you connect (Search Console, Analytics 4, Google Ads, automatic-fix platforms) and the measurements those services return.
BillingStripe customer identifier, plan, subscription status, invoice history and usage counters. No card data passes through or is stored on NeoRank's servers.
Technical logsIP address, timestamp, user agent and request identifier, for security and diagnostics.

Access protection

  • Data is isolated per workspace, in the application layer; what each member can do depends on their role.
  • Tokens, keys and passwords entrusted to NeoRank by a connector are encrypted (AES-256-GCM) before storage and never shown again.
  • API keys are shown only once: NeoRank keeps only a fingerprint of them (API and MCP).
  • Passwords are stored as an Argon2 hash, never in plain text.
  • Exchanges are encrypted in transit; sessions can be revoked one by one and sensitive actions are logged (Account and security).
  • Google connectors are used read-only: NeoRank never changes your Search Console or Analytics properties, or your Google Ads campaigns.

What is sent, and to whom

RecipientWhat it receivesWhen
The observed AI enginesThe text of your tracked promptsAt each AI visibility observation
Neo AI's AI provider (Anthropic by default)Your question, the latest turns, your display name, your role, the plan and, when needed, the measured data of the site concerned onlyWhen you use Neo AI, where it is switched on
NeoRank Research's AI providersThe question, with email addresses and phone numbers removed automatically; no account or analysis dataWhen you ask a question in NeoRank Research
Google (Search Console, Analytics 4, Google Ads)Read requests for your properties and accountsOnly if you connect them
The SERP data provider (DataForSEO)The text of your tracked keywords and their market (country, language, device), no personal dataFor automatic AI Overviews tracking, when enabled
StripePayment and billing dataAt subscription and payment
The transactional email providerVerification, invitation and alert emails, and scheduled reportsAt each send
Cloudflare (Turnstile)The IP address and the browser's technical signalsOn the public free express check and its form

The complete list of processors, with their role and region, is in the privacy policy; the data processing agreement applies to the data you place in a workspace, for which NeoRank acts as a processor.

What you can do yourself

  • Delete a tracked prompt, a tracked competitor or a manual AI Overview reading.
  • Revoke an API key, a session or an automatic-fix connector.
  • Disconnect Google Ads (“Disconnect” button); for Search Console and GA4, remove NeoRank's access from your Google account (Integrations).
  • Export your tables as CSV (Reports) or read your data through the read-only API, depending on your plan.
  • Choose the product, digest and marketing emails you receive in the notification settings; security and critical billing emails stay mandatory.

Retention and rights

Retention periods, category by category, are those of the privacy policy. You have the right of access, rectification, erasure, restriction, objection and portability, to exercise at privacy@neorank.ai; the answer comes within one month. Cookies are described in the cookie policy.

Need more help?

A question the documentation does not answer? The help center covers every dashboard page, and support answers the rest.