Privacy policy

Last updated Version 1.15

Data controller

Controller
ASKAIDE ASBL
Contact address
Avenue Emile Duray 24, 1050 Ixelles, Belgique
Privacy contact
privacy@neorank.ai

NeoRank is the controller for its own customer account data. For the data you place in a workspace — in particular pages crawled from your own sites — NeoRank acts as a processor, and the data processing agreement applies.

Data processed

The service processes the following categories, and no others.

  • Account: email address, name if you provide one, language, timezone, authentication method (password, passkey, Google, GitHub and, when enabled, Facebook), two-factor enrolments. For a sign-in provider, NeoRank keeps the identifier that provider assigns to it; for Facebook, nothing else (no name, no address, no access token).
  • Automatic Google sign-in (optional, when enabled): for a signed-out visitor, only the sign-in and sign-up pages load the Google Identity Services library from accounts.google.com to offer sign-in with Google; Google then receives your browser's technical connection information, and its library sets the g_state and g_csrf_token cookies described in the cookie policy. No other page of the site loads it. After a deliberate sign-out, automatic selection is turned off in that browser.
  • Organisation and workspace: name, members, roles, invitations.
  • Sites and analyses: domains you declare, verification evidence, crawled URLs, public page content, response codes, internal links, and the technical findings produced from them.
  • Manual AI Overviews readings: when a member records what they saw in Google (“Check in Google” opens the search in their own browser; NeoRank does not query Google), NeoRank keeps the prompt or keyword checked, whether an AI Overview showed, whether the site was cited, the cited URL and the note typed (both optional), the date and the author's identifier. Workspace members can see them; an authorised member can delete them. Do not type personal data in the note.
  • Automatic AI Overviews tracking (when enabled): for the keywords you track, NeoRank sends the keyword text and its market (country, language, device) to DataForSEO OÜ, a licensed SERP data provider, which returns the matching Google results page; NeoRank does not query Google itself. For each reading NeoRank keeps whether an AI Overview was present, the links it cited (address, title, domain, position), an excerpt of at most 600 characters, the date, the number of requests and an estimate of their cost, and the NeoRank engine's analysis of those links (site cited, competitors cited). No personal data is sent.
  • Connectors: access tokens for services you deliberately connect (Search Console, Analytics) and the metrics those services return. PageSpeed Insights: the analysed page URL and returned measurements, with an optional server API key; no OAuth token from your account is used for PageSpeed.
  • Billing: Stripe customer identifier, plan, subscription status, invoice history, usage counters. No card data passes through or is stored on our servers.
  • Contact requests: name, email address, message, topic and, if you provide it, the workspace name, sent with the “Talk to a human” form of the Support and Contact pages.
  • Customer reviews (“Rate NeoRank”): rating, optional comment, chosen display name, language, the identifiers of your account and organisation, proof of use (the identifier of a verified Auto-Fix fix), the origin of the comment's text and its moderation state, and your answer to the review request — see the “Customer reviews” section.
  • Technical logs: IP address, timestamp, user agent and request identifier, kept for security and diagnostics.
  • Anti-bot protection: the public Express check and its email-report form show a Cloudflare Turnstile check; Cloudflare receives your IP address and the browser and device technical signals needed for the check, and NeoRank uses only the result of that check, to apply its usage limits. A missing or failed check blocks neither the preview nor the sending, which are then subject to tighter limits.
  • Optional audience measurement: when accepted, on some public pages listed in the cookie policy, Google Analytics receives pageviews, pseudonymous browser identifiers and technical connection information. URL parameters, fragments, customer titles and referrers are excluded from our events. This integration does not enable personalized advertising. Withdrawal remains available at any time through the “Manage cookies” link.
  • Analytics sharing: the account retains four Google data-sharing options: Google products and services; modeling contributions and business insights; technical support; recommendations for our business. These uses are additional to operating Analytics and are not disabled by denying advertising personalization in our tag. Refusing audience measurement prevents this tag from loading on NeoRank.

Crawling collects publicly reachable pages only, honours the target site's robots.txt, and runs under a bounded budget and timeout.

Purposes and legal bases

  • Providing the service, running analyses and returning results — performance of the contract (GDPR art. 6(1)(b)).
  • Account management, authentication and session security — performance of the contract and legitimate interest in securing the service (art. 6(1)(b) and 6(1)(f)).
  • Billing, collection and accounting obligations — performance of the contract and legal obligation (art. 6(1)(b) and 6(1)(c)).
  • Abuse prevention, rate limiting and security logging — legitimate interest (art. 6(1)(f)).
  • Audience measurement and non-essential communications — consent (art. 6(1)(a)), withdrawable at any time.
  • Answering questions asked to the NeoRank AI assistant and limiting its use — legitimate interest in providing online help and preventing abuse (art. 6(1)(f)).
  • Correcting and checking the address typed in the home page's analysis field and, when enabled, answering through the home page assistant — legitimate interest in easing access to the free analysis and preventing abuse (art. 6(1)(f)).
  • Answering NeoRank Research chat messages, limiting its use and counting paid messages against the organisation's AI allowance — legitimate interest in providing the service and preventing abuse (art. 6(1)(f)) and, for account holders, performance of the contract (art. 6(1)(b)).
  • Answering questions asked to NeoRank Research, possibly publishing the question as the topic of a public page, and limiting its use — legitimate interest in publishing informational content and preventing abuse (art. 6(1)(f)).
  • Answers from the assistant of the Support and Contact pages, and limiting its use — legitimate interest in providing online help and preventing abuse (art. 6(1)(f)) and, when you ask about a plan, steps taken at your request before entering into a contract (art. 6(1)(b)).
  • Handling requests sent with the “Talk to a human” form, and limiting its use — legitimate interest in answering the people who write to us and preventing abuse (art. 6(1)(f)) and, when the request is about a plan, steps taken at your request before entering into a contract (art. 6(1)(b)).
  • Collecting, moderating and publishing customer reviews — consent (art. 6(1)(a)), given by sending the review and withdrawable at any time; remembering your answer to the review request (“Later”, “Don't ask again”) — legitimate interest in not asking you against your wishes (art. 6(1)(f)).

NeoRank AI assistant

Public pages offer a help assistant, NeoRank AI, usable without an account. It answers from the public content of NeoRank's help centre.

  • Data sent: the question you type, the latest turns of the current conversation and the chosen language are sent to Google (Gemini API), as a processor, to generate the answer. No account, workspace or analysis data is read or sent.
  • Rate limiting: your IP address is turned into a hash to count questions per visitor; the plain IP address is not used for this, and the counters expire daily at midnight UTC.
  • Retention: NeoRank does not store the text of questions or answers. Only aggregated counters (number of questions, token volume, cost) and technical logs without the content of the exchange are kept, for the log retention period stated below. Processing by Google is governed by the terms applicable to its API.
  • Precaution: do not enter sensitive personal data or confidential information in your questions. Generated answers are informational and must be checked.

Home page analysis field and assistant

The home page's “Start free analysis” field fixes common typing mistakes directly in your browser, then checks which address of your site answers. If you write a sentence rather than an address, an optional assistant may answer briefly and suggest a plan.

  • Address check: NeoRank contacts the site you entered (response headers only, without reading page content) to find the address that answers. The result is kept for at most 10 minutes, linked to the domain name only.
  • Assistant (optional, when enabled): the sentence you type, after e-mail addresses and phone numbers are automatically removed, is sent to Google (Gemini API), as a processor, to extract the site and the need expressed. Any plan suggested is chosen by NeoRank from its catalogue, not by the AI.
  • Rate limiting: your IP address is turned into a hash to count checks and answers per visitor; these counters expire by the following day at the latest.
  • Retention: NeoRank stores neither the sentence you type nor the answer. Only aggregated counters (number of requests, token volume, cost) and technical logs without the typed text are kept. This field sets no cookie.

NeoRank Research

The public NeoRank Research page (/research) lets anyone, without an account, ask a question about SEO, AEO, GEO, AI visibility or digital marketing. The question is submitted to several AI answer engines and a synthesis is written from their answers.

  • Data sent: the question, after e-mail addresses and phone numbers are automatically removed, is sent to the AI providers asked (OpenAI, Anthropic, Perplexity, Google and, once activated, xAI and Meta), as processors, to generate the answers. No account, workspace or analysis data is sent to the providers.
  • Publication: your question may become the topic of a public page, without personal data. It is kept with the page produced; a page is published only if it passes automatic filters (topic, sources, duplicates, sensitive subjects, personal data), otherwise it stays a non-public draft.
  • Rate limiting: your IP address is turned into a hash to count questions per visitor; neither the address nor its hash is stored with the question, and the counters expire daily at midnight UTC. A request carrying a rejected session cookie is also counted on that hash, for 10 minutes, to limit abuse.
  • Accounts: for a signed-in user, questions are counted against the plan's daily quota on a counter tied to a hash of their organisation's identifier — or of the user's, when they may not use the organisation's AI allowance; that counter expires at most 48 hours after it is created. On a paid plan that includes an AI allowance, each question is also counted against the organisation's monthly AI allowance (cost and token volume, not the content). To do so NeoRank reads the session, the default workspace, the memberships of the organisation and its workspaces (with the role) and the plan subscribed to, and keeps the result (the organisation's identifier, plan and quota) for at most 60 seconds under a hash of the user's identifier; a per-minute request counter tied to the same hash limits abuse. None of these is sent to the AI providers.
  • Precaution: do not include personal or confidential information in your question. To ask for a page to be removed, contact NeoRank through the Contact page.

NeoRank Research chat

The NeoRank Research page offers a Chat mode: a conversation with the AI engine of your choice. Gemini is free; ChatGPT, Claude, Perplexity, DeepSeek and, once activated, Grok and Meta AI offer a few trial messages a day, then are reserved for accounts whose plan includes AI.

  • Data sent: your message, at most the last ten turns of the conversation (each truncated) and the chosen language are sent only to the provider of the engine you pick, as a processor: Google (Gemini), OpenAI (ChatGPT), Anthropic (Claude), Perplexity, DeepSeek, xAI (Grok) or Meta (Meta AI). No workspace, site or analysis data is read or sent.
  • Retention: NeoRank does not store your conversations. The history is saved only in your browser (local storage); you can delete it at any time from the chat or by clearing the site's data. No conversation is kept server-side, including for visitors without an account. Technical logs contain only counters (number of messages, tokens, cost), never the text of the exchange.
  • Rate limiting: your IP address (and, for an IPv6 address, its IPv6 network prefix /48) is turned into a hash to count messages per visitor; the counters expire daily at midnight UTC.
  • Accounts: beyond the trial messages, a message a signed-in user sends to a paid engine is counted against their organisation's monthly AI allowance (cost and token volume, without the content), and a daily counter tied to a hash of the user identifier limits the pace of use. For this, NeoRank reads the session, the memberships of the organisation and of its workspaces (with the role, to check that the user may use the AI allowance) and the subscribed plan.
  • Publication: a conversation never becomes a page by itself. If you choose "Publish as a Research page", only your question is submitted to NeoRank Research and processed as described in the previous section.
  • Precaution: do not enter sensitive personal data or confidential information. Answers are generated by AI and must be checked.

Neo AI, the dashboard assistant

Where it is enabled, the dashboard offers Neo AI, an assistant that answers a workspace member's questions about the open site from that site's measured data.

  • Data sent: your question, the last turns of the current conversation (each truncated), your display name, your role, the organisation's plan and, when the assistant needs it, the measured data of the site concerned and of that site only (Search Console data, site audit results, backlinks, AI visibility, stored positions, plan usage) are sent to the AI provider configured for the platform (Anthropic by default), as a processor, to generate the answer. No data of another workspace, organisation or user is read or sent.
  • Retention: NeoRank does not store your conversations with Neo AI; they stay in the open page of your browser. Technical logs contain only counters (calls, tokens, cost), never the text of the exchange.
  • Rate limiting: questions are counted against the plan's daily quota on a counter tied to a hash of the organisation identifier, which expires at most 48 hours after it is created, and a pace counter tied to a hash of the user identifier expires after one minute. On a paid plan that includes an AI allowance, each question is also counted against the organisation's monthly AI allowance (cost and token volume, not the content). A read-only client of the workspace (unless they own or administer the organisation) never spends that allowance: their questions are counted on their own daily counter, tied to a hash of their user identifier and expiring at most 48 hours after it is created, and paid by NeoRank. To do so NeoRank reads your role in the workspace and in the organisation.
  • Security: a question refused because it looks like an attempt at misuse (attacking a site, revealing secrets, bypassing quotas) is logged with your identifier, those of the organisation, workspace and site, and a truncated hash and the length of the question, never its text — legitimate interest in protecting the service and your data (art. 6(1)(f)).
  • Precaution: answers are generated by AI from your data and must be checked before acting.

Support and Contact page assistant

When it is enabled, the Support (/support) and Contact (/contact) pages offer NeoRank AI, an AI assistant — not a person — that can be used without an account. It answers from the help center, the documentation index and public product information, and names the NeoRank address to write to.

  • Data sent: your question and at most the last six turns of the current conversation (each truncated), with email addresses and phone numbers automatically removed from your messages, plus the language and the page used, are sent to Google (Gemini API), as a processor, to generate the answer.
  • Signed-in users: NeoRank reads your session, your display name, your first active organisation and its plan, and sends Google only your first name (the first word of your display name) and the name of your plan. No site, analysis, billing or settings data is read or sent.
  • Rate limiting: your IP address (for an IPv6 address, its /64 network prefix) is turned into a hash to count questions per visitor; the plain address is not kept for this purpose and the counters expire daily at midnight UTC.
  • Retention: NeoRank stores neither your questions nor the answers, on its servers or in your browser; the conversation is gone when you leave the page. Technical logs contain only counters (tokens, cost, links removed), never the text of the exchange. Google's processing is governed by the terms applicable to its API.
  • Precaution: do not enter sensitive personal data or confidential information. Answers are generated by AI and must be checked; to reach a person, use the “Talk to a human” form.

“Talk to a human” form

The Support and Contact pages offer a form to write to the NeoRank team. It is not sent to any AI provider.

  • Data processed: your name, your email address, your message, the topic chosen and, if you provide it, the name of your workspace, with the language, the page it was sent from, the time it was sent and a request reference. Markup and control characters are removed.
  • Recipient: the request is recorded in NeoRank's email sending queue, then sent by the transactional email provider to the single NeoRank address that matches the topic chosen (for example hello@neorank.ai, enterprise@neorank.ai or privacy@neorank.ai).
  • Rate limiting: your IP address is turned into a hash to limit the number of requests per visitor; these counters expire after one hour and after 24 hours.
  • Retention: the copy of the request recorded in the email sending queue is deleted automatically 90 days after sending (or 90 days after sending finally fails); the message received by the NeoRank team is kept for the time needed to handle it. Technical logs contain only the topic and the message length, never your name, your address or your message.
  • Requests about this data, as about any other personal data, go to privacy@neorank.ai.

Customer reviews (“Rate NeoRank”)

After a verified automatic fix on your site, NeoRank may invite you to rate the service. Leaving a review is optional and nothing is offered in return. How reviews are collected, moderated and published is described on the “How we collect reviews” page (/avis/methode).

Data processed
Your rating (1 to 5); your optional comment (1,000 characters at most); the display name you choose — your first name and the initial of your last name, derived from your account name, or “Anonymous”; the language of the review; the identifier of your user account and of your organisation; the identifier of the verified Auto-Fix fix that proves you used the product; the origin of the comment's text (written freely, taken from a NeoRank suggestion, or corrected with AI help at your request); the moderation state (decision, date, any rejection reason, moderator identifier). We also record when the review request was shown to you and, where applicable, your “Later” or “Don't ask again” choice.
Purpose
To collect, moderate and publish verified customer reviews on neorank.ai, and to be able to demonstrate that they come from people who actually used the service (article L. 111-7-2 of the French Consumer Code). Not to ask you again if you declined.
Legal basis
Your consent (GDPR art. 6(1)(a)), given by sending the review; you can withdraw it at any time by asking for the review to be deleted, without affecting the lawfulness of its earlier publication. Your answer to the review request is kept on the basis of our legitimate interest in respecting your choice (art. 6(1)(f)).
Moderation and publication
Every review is read by a person before publication. It can be rejected only for one of these reasons: insults, spam, personal data about someone else, content unrelated to NeoRank. Negative reviews are published like the others. The rating, comment, display name and date are published; your e-mail address, your identifiers, the proof of use and the origin of the text are never published.
Recipients
Published reviews can be read by any visitor of neorank.ai. Pending or rejected reviews and moderation data are accessible only to the NeoRank staff in charge of moderation.
Writing help
Sentence suggestions are produced by NeoRank, without AI, from your own verified fixes only. If you use “Improve my text”, your comment is sent to Google (Gemini API), a processor listed below, for spelling, grammar and clarity corrections; the proposal replaces your text only if you accept it, and the rating is never changed. A daily counter tied to your account limits the number of requests.
Retention
Until you ask for deletion — write to privacy@neorank.ai from your account's address — or close your account. Editing your review replaces the previous version, which is moderated again.

Processors

The categories of providers below process data on NeoRank's behalf. The region named is where processing takes place.

Cloud hosting and database
Running the application, primary database, analysis job queue and technical logs — European Union (Belgium).
Payments and invoicing (Stripe)
Subscription payments, invoicing and EU VAT handling — Ireland (EU).
Sign-in providers (Google, GitHub)
Signing in with Google or GitHub, only if you choose to, and Google connectors (Search Console, Analytics 4) only if you link them — European Union.
Transactional email
Sending verification and invitation emails, scheduled reports, and “Talk to a human” form requests to NeoRank mailboxes — European Union.
Domain name and mailboxes
The neorank.ai domain name and receipt of email sent to us — European Union.
Audience measurement (optional, consent-based)
Google Analytics on public pages, only after you agree — Ireland (EU); may involve international processing under Google's applicable terms. Analytics account settings and Google's applicable processing terms require verification before activation.
AI providers
AI-visibility measurement (your tracked prompts are submitted to the observed AI engines), answers from the NeoRank AI help assistant, including on the Support and Contact pages (Google Gemini), and from the optional home page assistant (Google Gemini) and from NeoRank Research and its chat (OpenAI, Anthropic, Perplexity, Google, DeepSeek and, once activated, xAI and Meta), and from Neo AI, the dashboard assistant, from the measured data of the site concerned (configured provider, Anthropic by default), and optional correction, at your request, of the text of a customer review (Google Gemini) — May involve processing outside the European Union, depending on the provider. Processing is governed by each provider's applicable terms, set out in the complete named list.
SERP data for AI Overviews (DataForSEO OÜ)
Automatic tracking of Google AI Overviews, when enabled: keywords tracked by the customer and their market (country, language, device), no personal data — Estonia (EU); the provider also lists an office in Ukraine, outside the European Union. No personal data is sent; processing is governed by DataForSEO's terms.
Anti-bot protection (Cloudflare Turnstile)
Anti-bot verification of the public Express check and its email-report form: IP address and the browser and device technical signals needed for the check — May involve processing outside the European Union. Processing is governed by Cloudflare's applicable terms.

The complete named list of sub-processors is available to customers on request at privacy@neorank.ai, and any change is notified before it takes effect.

Transfers outside the European Union

The application, its database and its processing workloads are hosted in the European Union (Belgium). The other providers listed above process data within the European Union, except optional Google Analytics audience measurement, the AI providers (including the Gemini API used by the NeoRank AI assistant) the SERP data provider for AI Overviews (which receives no personal data) and the Cloudflare Turnstile anti-bot protection of the public Express check, which may involve international processing under each provider's applicable terms. Google's practices are described at https://policies.google.com/technologies/partner-sites; the account's applicable settings and terms must be verified before activation.

Retention

  • Account and workspace: for the life of the account, then 30 days after deletion.
  • Crawl results and findings: for the retention window of the subscribed plan, then automatically deleted.
  • Billing records: 10 years, under accounting and tax obligations.
  • Technical and security logs: 12 months at most.
  • Connector tokens: until you revoke them or remove the connector.
  • Manual AI Overviews readings: until an authorised member deletes them, or the site or workspace is deleted; the author's identifier is erased if their account is deleted.
  • Automatic AI Overviews readings: until the site or workspace is deleted.
  • NeoRank AI assistant: question text is not kept by NeoRank; counters tied to the hashed IP address expire daily at midnight UTC.
  • NeoRank Research: the question (without personal data) and the page produced are kept for as long as the page exists; counters tied to the hashed IP address expire daily at midnight UTC, an account's at most 48 hours after they are created.
  • NeoRank Research chat: no conversation is kept by NeoRank (the history stays in your browser); the daily counters expire at midnight UTC.
  • Neo AI: no conversation is kept by NeoRank (it stays in the open page of your browser); the daily counters, tied to a hash of the organisation or user identifier, expire at most 48 hours after they are created, the pace counter after one minute.
  • Support and Contact page assistant: no conversation is kept by NeoRank; counters tied to the hashed IP address expire daily at midnight UTC.
  • “Talk to a human” form: the copy recorded in the email sending queue is deleted 90 days after sending (or after sending finally fails); the message received by the team, for the time needed to handle the request; counters tied to the hashed IP address expire after one hour and after 24 hours.
  • Customer reviews: until you ask for deletion (privacy@neorank.ai) or close your account; your answer to the review request, for the same period.

Your rights

You have the right of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent at any time where processing relies on it.

Exercise these rights at privacy@neorank.ai. We respond within one month. You may also lodge a complaint with your supervisory authority — in France the CNIL, in Belgium the Data Protection Authority.

Security

  • Encryption in transit across all exchanges.
  • Per-workspace data isolation, enforced in the application layer.
  • Two-factor authentication by authenticator app (TOTP) and passkeys.
  • Individually revocable sessions from security settings.
  • Audit log of sensitive actions.

Changes

Any change to this policy produces a new dated version, shown at the top of this page. Substantial changes are notified to account holders before they take effect.

Version 1.15 (6 October 2026): the “Transfers outside the European Union” section describes the production service: the application, its database and its processing workloads are hosted in the European Union (Belgium); the SERP data provider for AI Overviews is listed among the exceptions already flagged in the processor list, and Meta is named among the AI providers of that list, as in the NeoRank Research section. Cloudflare Turnstile anti-bot protection of the public Express check and its email-report form (IP address and the technical signals needed for the check) is added to the data processed, the processor list and the exceptions of the “Transfers outside the European Union” section.

Version 1.14 (28 September 2026): automatic Google AI Overviews tracking added: the keywords the customer tracks (no personal data) are sent to the processor DataForSEO OÜ (Estonia) to obtain the Google results page; the readings are kept with the site.

Version 1.13 (28 September 2026): Meta (Meta AI) added to the AI providers acting as processors for NeoRank Research and its Chat mode, once activated.

Version 1.12 (28 September 2026): customer reviews (“Rate NeoRank”) added; automatic Google sign-in is now offered only on the sign-in and sign-up pages; consent to audience measurement is withdrawn through the “Manage cookies” link.