Account and plan
Data and privacy
A practical summary of what NeoRank does with your data, drawn from how the product actually works. The [privacy policy](/legal/privacy) remains the reference text: when in doubt, it prevails.
Hosting
The application, its database and its processing workloads are hosted in the European Union, in Belgium: Google Cloud, europe-west1 region. The database is a managed PostgreSQL instance (Cloud SQL) in that region, and the platform's secrets are replicated in that same region.
Some providers may process data outside the European Union: GitHub sign-in (United States), optional audience measurement, the AI providers and the anti-bot protection of the free express check. The privacy policy details them, provider by provider.
What NeoRank keeps
| Category | Content |
|---|---|
| Account | Email address, name if you provide one, language, timezone, sign-in method and two-factor enrolments. |
| Organisation and workspaces | Name, members, roles and invitations. |
| Sites and analyses | Declared domains, verification evidence, crawled URLs, public page content, response codes, internal links and the technical findings drawn from them. |
| AI visibility | Your tracked prompts and prompt groups, the observed AI engines' answers and what is extracted from them: mentions, citations, sentiment, KPIs. |
| Google AI Overviews | Manual readings entered by a member (whether an overview showed, site cited, optional URL and note) and, when enabled, automatic tracking of your tracked keywords. |
| Connectors | The access tokens of the services you connect (Search Console, Analytics 4, Google Ads, automatic-fix platforms) and the measurements those services return. |
| Billing | Stripe customer identifier, plan, subscription status, invoice history and usage counters. No card data passes through or is stored on NeoRank's servers. |
| Technical logs | IP address, timestamp, user agent and request identifier, for security and diagnostics. |
Access protection
- Data is isolated per workspace, in the application layer; what each member can do depends on their role.
- Tokens, keys and passwords entrusted to NeoRank by a connector are encrypted (AES-256-GCM) before storage and never shown again.
- API keys are shown only once: NeoRank keeps only a fingerprint of them (API and MCP).
- Passwords are stored as an Argon2 hash, never in plain text.
- Exchanges are encrypted in transit; sessions can be revoked one by one and sensitive actions are logged (Account and security).
- Google connectors are used read-only: NeoRank never changes your Search Console or Analytics properties, or your Google Ads campaigns.
What is sent, and to whom
| Recipient | What it receives | When |
|---|---|---|
| The observed AI engines | The text of your tracked prompts | At each AI visibility observation |
| Neo AI's AI provider (Anthropic by default) | Your question, the latest turns, your display name, your role, the plan and, when needed, the measured data of the site concerned only | When you use Neo AI, where it is switched on |
| NeoRank Research's AI providers | The question, with email addresses and phone numbers removed automatically; no account or analysis data | When you ask a question in NeoRank Research |
| Google (Search Console, Analytics 4, Google Ads) | Read requests for your properties and accounts | Only if you connect them |
| The SERP data provider (DataForSEO) | The text of your tracked keywords and their market (country, language, device), no personal data | For automatic AI Overviews tracking, when enabled |
| Stripe | Payment and billing data | At subscription and payment |
| The transactional email provider | Verification, invitation and alert emails, and scheduled reports | At each send |
| Cloudflare (Turnstile) | The IP address and the browser's technical signals | On the public free express check and its form |
The complete list of processors, with their role and region, is in the privacy policy; the data processing agreement applies to the data you place in a workspace, for which NeoRank acts as a processor.
What you can do yourself
- Delete a tracked prompt, a tracked competitor or a manual AI Overview reading.
- Revoke an API key, a session or an automatic-fix connector.
- Disconnect Google Ads (“Disconnect” button); for Search Console and GA4, remove NeoRank's access from your Google account (Integrations).
- Export your tables as CSV (Reports) or read your data through the read-only API, depending on your plan.
- Choose the product, digest and marketing emails you receive in the notification settings; security and critical billing emails stay mandatory.
Retention and rights
Retention periods, category by category, are those of the privacy policy. You have the right of access, rectification, erasure, restriction, objection and portability, to exercise at privacy@neorank.ai; the answer comes within one month. Cookies are described in the cookie policy.