Privacy Policy
Last updated 26 August 2026
1. Who we are
SoaRank is operated by MD5 Labs Inc. The service is available at https://www.soarank.com. In this policy, “SoaRank”, “we”, “us” and “our” mean MD5 Labs Inc. Maya is the in-product AI assistant.
2. Scope
This policy covers the SoaRank website, sign-in, dashboard, diagnosis reports, generated brand sites, Maya, billing, and related emails. It does not cover third-party sites we link to, or Google’s or Stripe’s own practices.
If you put our crawler beacon or plugin on your own website, we process that traffic data on your behalf. See Customer websites.
3. Personal information we collect
Account and sign-in
Email address, display name, language preference, plan and trial dates, and a sign-in session. If you use Google sign-in, we also receive your Google account identifier, name, and profile photo URL. We request the openid email profile scopes.
Brand and business content you provide
Brand name, website URL, category, competitors, what you sell, who you sell to, voice, materials, and other brand profile data. Maya chat messages are stored against your account. Generated site drafts and published pages can include contact details you choose to add, such as an email or phone number.
Diagnostics and reports
You need an account to run a brand diagnosis. We store the brand and URL you submit, generated scores, competitor names, and report files.
Billing
Plan, order, subscription, and invoice records. Checkout is handled by Stripe. We send Stripe your email so it can create the payment. We do not store your payment card information. Stripe’s own privacy policy applies to the payment data Stripe processes.
Crawler analytics and referral beacon
If you connect crawler analytics, we may store request path, user agent, IP address, bot name, and timestamps for hits on your site. The JavaScript beacon sends the document referrer and path when a visitor arrives from listed AI products.
Product events, logs, and device storage
The site may post funnel events to /api/track. We store the JSON the client sends, plus a timestamp. Server access logs include IP address, path, and a trace id. The browser stores a session cookie and several local keys. See cookies below.
4. How we use information
- Create and keep your account, session, and language preference.
- Run diagnoses, generate reports, sites, articles, and Maya replies.
- Measure AI-search visibility and crawler activity for brands you manage.
- Provide billing, paid plans, and related notices.
- Send transactional email and product email from Maya.
- Secure the service, debug, prevent abuse, and comply with law.
Where GDPR or UK GDPR applies, we rely on: performing the contract for account, diagnosis, sites, Maya, and billing; legitimate interests for security, logs, funnel events, and product improvement; consent where Google sign-in or optional beacons are involved; and legal obligation when the law requires us to keep or disclose information. You can object to legitimate-interest processing by contacting us by email.
5. AI features
SoaRank uses machine-learning models to score visibility, draft copy, generate images, and operate Maya. Those outputs are assistance, not legal, medical, or financial advice.
Prompts can include brand content, site text we fetch from the URL you gave us, chat messages, and related metadata. We do not use your data to train models.
6. Google user data
Google sign-in is used to create or access your SoaRank account. We use the email, name, and profile photo Google returns for that purpose. We do not sell Google user data or use it for advertising. We do not use it to train models.
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies and local storage
We do not use third-party advertising or analytics cookies. A first-visit notice explains this. Dismissing it stores soa_ca in localStorage. The cookies we set are needed to run the service, so the notice is an acknowledgment, not a choice to turn them off.
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
soa_s |
Cookie (HttpOnly, SameSite=Lax, Secure in production) | Keep you signed in | Until it expires or you sign out |
soa_gs |
Cookie (HttpOnly, SameSite=Lax, Secure in production) | Protect Google sign-in from CSRF | Until the sign-in flow finishes |
soa_l |
localStorage | Remember language | Until you clear it |
soa_ca |
localStorage | Remember that you dismissed the cookie notice | Until you clear it |
soa_cb_*, soa_onb*, soa_sj, soa_bi, soa_deep, soa_p |
localStorage or sessionStorage | Resume onboarding, scans, and workspace UI | Until you clear it or the tab ends |
soa_bp_* |
localStorage | Draft site prep, which can include email and phone you type | Until you finish or clear it |
8. Who we share information with
We do not sell personal information and we do not share it for cross-context behavioral advertising. We use vendors to run the product:
| Recipient | Why |
|---|---|
| Account sign-in | |
| Stripe | Paid plans, checkout, invoices, and tax handling Stripe performs |
| AI model providers | Diagnosis, writing, image generation, and Maya |
| IndexNow / search engines | URLs of sites you publish, when IndexNow is enabled |
We may also disclose information if required by law, to protect the service, or as part of a merger or sale of the business, with notice where the law requires it.
9. Retention
- Account profile: until the account is deleted.
- Maya chat, reports, and diagnosis cache: kept while the account remains, and deleted 30 days after the account is deleted.
- Crawler logs and funnel events: 90 days.
- Brand sites after you delete the brand: taken offline, then purged after about 30 days.
- Maya instance after paid access ends: stopped, then deleted after 7 days.
- Stripe records: also retained by Stripe under its own rules.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing, and to withdraw consent.
To make a request, contact us by email. We may need to verify you control the account.
11. Customer websites
If you publish a SoaRank-generated site, that site is your content. If you install our beacon or crawler plugin, you are the controller of your visitors’ data and SoaRank is your processor for the hits we ingest. You must tell your visitors and have a lawful basis. For an enterprise contract, contact us by email.
12. Children
SoaRank is a business product. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have, contact us by email and we will delete it.
13. Security
We use HTTPS, HttpOnly session cookies, hashed credentials and tokens, rate limits on several endpoints, and checks against server-side request forgery when we fetch a URL you give us.
14. Contact
Email contact@soarank.com.
15. Changes
We will update this page when our data practices change. The date at the top is the current version.
