Cookie policy

Last updated Version 1.2

Principle

When Google Analytics audience measurement is enabled, it runs only on some public pages of neorank.ai (pricing, partners, about, contact, support, service status and legal documents) and uses these cookies, which require your prior consent: _ga, _ga_JCG7BVFB7D. They are set only after you explicitly agree. Refusing is as easy as accepting and does not limit the service. Customer workspaces, the dashboard and the development environment are never measured.

The other cookies and browser data described below are strictly necessary for the service you request (including signing in to your account) or record a preference you set yourself; those categories are exempt from consent.

Cookie inventory

_ga / _ga_JCG7BVFB7D
Optional Google Analytics audience measurement (Google), subject to your consent: pseudonymous browser identifier and session state. Configured maximum lifetime: 180 days, without automatic extension. No advertising consent is requested or granted. Withdraw at any time with "Manage cookies".
neorank_session / __Host-neorank_session
Strictly necessary. Keeps you signed in. Removed on sign-out or when the session expires. In production your browser shows the prefixed name __Host-neorank_session: it is the same cookie, the prefix binding it to this origin alone, over HTTPS and at the root path.
neorank_signed_out
Strictly necessary (security). Set when you sign out on purpose so that automatic Google sign-in does not sign you straight back in. Holds only the value "1". Removed at your next sign-in; 180 days at most.
neorank_gsi_nonce
Strictly necessary (security), only when one-tap Google sign-in is enabled. Binds Google's reply to this browser so a token cannot be replayed. Scoped to the Google sign-in endpoint, 10 minutes at most.
g_state / g_csrf_token
Cookies set on neorank.ai by Google's sign-in library (Google Identity Services), only on the sign-in and sign-up pages and only when one-tap Google sign-in (Google One Tap) is enabled. g_state remembers whether you closed or ignored the Google sign-in prompt, so it is not shown again straight away; g_csrf_token protects the hand-over of the sign-in to NeoRank against request forgery. Strictly necessary for the sign-in you came to these pages to perform. Their lifetime is set by Google. They are never set on the other pages of the site.
neorank_mfa_pending
Strictly necessary (security). Set only when an account protected by two-factor authentication signs in with Google or GitHub: it carries the pending code request until you enter the code. Scoped to the code check, 5 minutes at most, removed once the code is accepted.
neorank_express_start
Strictly necessary. Set only when you click “Continue with Google” after an express check: it holds the name of the checked site, so that site's full analysis starts by itself after you sign in. 15 minutes at most, removed as soon as the analysis is launched.
neorank_language
Preference. Remembers the language you chose, so the same URL is served to you in that language.
neorank_country
Preference. Remembers the country or region you selected, used to show the prices that apply to you.
neorank_theme
Preference. Remembers light or dark theme, applied before first paint so the page does not visibly change colour.
neorank_site
Preference. Remembers the active site in your workspace, so you return to it between visits.
neorank_period
Preference. Remembers the analysis period selected in the product.
nr_gsc_country
Preference. Remembers the country you chose to filter Search Console data in the dashboard. Set by your browser when you make that choice; 180 days, removed if you go back to all countries.
nr_gsc_period
Preference. Remembers the period you chose for Search Console data in the dashboard. Set by your browser when you make that choice; 180 days.

Data stored in your browser

Some features also keep data in your browser's local storage (localStorage) or session storage (sessionStorage). These are not cookies: they are not sent to our servers automatically and no third party reads them. Session storage is cleared when the tab is closed.

neorank.analytics-consent.v1
Local storage. Your choice to accept or refuse audience measurement, and its date. Kept 180 days, after which you are asked again. Necessary to respect your choice.
neorank.research.chat.v1
Local storage. The history of your conversations with the NeoRank Research chat (at most 30 conversations of 60 messages each), kept only in this browser until you clear it from the chat or in your browser settings.
neorank:public-audit:retry
Local storage. When the free audit's limit is reached, the audit's last reply (including the address analysed and the time from which a new attempt is possible), to show that delay if you reload the page. Removed as soon as the delay has passed.
neo-ai:v1:…
Session storage. The current conversation with the dashboard's Neo AI assistant, per user and per site (the user identifier as a digest, never the e-mail address), and the guidance towards a setting (dropped after 2 minutes if not shown). Removed on sign-out, when another site is opened and when the tab is closed.
neorank:domain-proof:…
Session storage. The DNS ownership-verification record you just generated for a site, so you can verify it once it has propagated without generating a new one. Removed once verification succeeds or when the tab is closed.
neorank:product-learning:…
Session storage. A plain "already sent" marker that avoids counting twice, in the same tab, one product-usage event (for example an offer being shown) sent only to NeoRank's servers to improve the service. The marker holds the event name and, where relevant, the identifier of the site concerned; no third party reads it. Cleared when the tab is closed.

Managing your choices

The "Manage cookies" link at the bottom of the site's public pages (and on this page) reopens the audience-measurement choice at any time: you can accept, refuse or withdraw your consent there. When audience measurement is active and you have made a choice, an "Audience preferences" button also remains available on the other pages, including the customer area. Withdrawing is as easy as consenting: it deletes this site's _ga cookies and reloads the page to stop the tag.

You can also delete or block the site's cookies and storage from your browser settings. Blocking neorank_session will prevent you from staying signed in; blocking preference cookies returns those settings to their defaults on each visit; clearing the site's storage resets your audience-measurement choice and erases the NeoRank Research chat history.

Questions about this document: privacy@neorank.ai.