MAGRANK AI / PRIVACY

Privacy, in plain language.

Last updated 25 September 2026.

Who is responsible for your data

The data controller is Veebiagentuur OÜ (registry code 12050902), Pääsukese 6, Kopli küla, Rae vald, Harjumaa, Estonia. Contact: info@magrank.com.

What we collect and why

We store your submitted website, brand, market and competitors to run your requested analysis. Reports contain buyer questions, sampled AI answers, source links and analysis results. If you provide an email address, we store it to send you your report. Account registration stores your name, email and a securely hashed password. For purchases we store order, payment and subscription identifiers, not card numbers. Optional marketing consent is recorded separately with its timestamp. If you answer “Was this report useful?”, we store your answer and any comment with that report to improve MagRank AI; it is deleted with the report.

Legal basis

We process account, analysis, report, payment and transactional email data to provide the service you request (performance of a contract). Security logs, abuse and rate-limit protection and aggregate product usage counts rely on our legitimate interest in running a safe, reliable service. Marketing emails are sent only with your consent, which you can withdraw at any time. Accounting records are kept to meet our legal obligations.

Service providers

We use these processors to run MagRank AI: Hostinger (website hosting and email delivery), Supabase (database hosting), OpenAI (website discovery, AI answers and answer analysis) and Stripe (payments). Google Gemini, Perplexity and Anthropic (Claude) receive the same buyer questions when they are enabled as answer providers. Public website content and questions are sent to the AI providers; your account password and card details are never sent to them. Some of these providers process data outside the EU/EEA, mainly in the United States; such transfers rely on the safeguards those providers offer, such as the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.

Cookies and analytics

Essential HttpOnly cookies protect your guest reports and authenticated session. Guest access lasts up to 90 days and sessions up to 30 days. First-party funnel events record activity counts without raw prompts, email addresses or raw IP addresses. Where IP-based rate limiting is used, only a keyed hash of the client IP is stored, never the IP itself. The landing event respects the browser’s Do Not Track setting. We do not use third-party advertising or analytics cookies.

Private and shared reports

Reports are private by default. If you enable sharing, anyone with the public link can view that report. Turning sharing off invalidates the link. Avoid sharing a report if its questions or answers contain confidential information.

How long we keep data

Reports are kept for 90 days and then removed automatically, along with expired authentication tokens and rate-limit records. Account data is kept until you delete your account. Payment and accounting records are kept for at least seven years, as required by the Estonian Accounting Act, even after an account is deleted.

Email choices

Providing an email for a report does not subscribe you to marketing. We currently send no marketing emails. Transactional account and report emails are separate and are needed to run the service.

Your rights

You can request access to, correction or deletion of your data, restrict or object to its processing, and receive your data in a portable format. You can export your account data and request account deletion from Settings after stopping subscriptions and active audits, or contact info@magrank.com. We respond within one month. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or the data protection authority in your own country.