Privacy Policy

Last updated: August 31, 2026

1. Introduction

Joon Labs Inc. ("we", "our", or "us") operates the joon ai marketing platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

Account Information

When you sign in with Google, we receive your name, email address, and profile picture from your Google account. We use this information to create and manage your account.

Google Permissions We Request

Signing in with Google asks you to grant the following permissions. This is the complete list — we do not request anything else:

  • Google Ads: Read your Google Ads accounts and create / manage campaigns, ad groups, and ads.
  • Merchant Center: Read your Merchant Center products so you can target them in Shopping and Demand Gen campaigns.
  • Google Analytics (optional): Read GA4 conversion data to inform AI targeting and audience recommendations.
  • Email: Identify you across sessions so we can save your campaigns and settings.
  • Profile: Show your name and avatar in the app.

Every permission except Google Analytics is required for the Service to work, and sign-in stops with an explanation if one of them is not granted. Google Analytics is optional — you can decline it on Google's consent screen and the rest of the Service still works.

Advertising Platform Data

With your explicit authorization, we access data from your connected advertising accounts (Google Ads, Meta Ads, Microsoft Advertising, TikTok Ads, Apple Search Ads) to display campaign performance metrics and enable campaign management. This includes:

  • Campaign names, budgets, and performance metrics (impressions, clicks, conversions, spend)
  • Keywords, search terms, and audience and targeting settings
  • Ad creative content, including headlines, descriptions, images, and video
  • Account-level settings and billing information

Merchant Center Product Data

For Shopping and Demand Gen features we read the product listings in the Merchant Center account you select — item ID, title, brand, price, product type, image URL, feed label, target country and condition — so you can choose which products to advertise and so we can tell you when products are not being promoted by any campaign.

Google Analytics Data

If you grant the optional Google Analytics permission and select a GA4 property, we read that property's aggregated reports: sessions, total and new users, page views, average session duration, bounce rate, conversions and revenue, broken down by date, traffic source and medium, top pages, and event name. This is report-level data — we do not receive individual visitor records. We use it to give you conversion context alongside your ad data and to ground targeting and audience recommendations in what actually happens after the click.

Contact, Demo and Sign-Up Requests

When you submit the contact form, we store the name, email address, company and message you entered, which form you used, and the IP address the request came from. We use the IP address only to rate-limit and triage abuse of the form. We keep these records to reply to you; Section 6 says who else receives them, and Section 8 explains what our deletion controls do and do not reach. (Records created earlier by the "Try Demo" and demo request forms, which no longer exist, are still held and are covered by the same sections.)

Usage Data

Our servers and our hosting provider record standard request logs — the pages and API endpoints you request, timestamps, and error details — which we use to operate, secure and debug the Service.

We also use third-party analytics and advertising tags. Section 3 sets out exactly which ones, what they are allowed to see, and the consent they require before they run. We do not use session-recording or session-replay trackers: nothing we run captures your screen, your mouse movements, your keystrokes, or the contents of the pages you view.

3. Cookies and Browser Storage

This section covers the cookies and browser storage the Service itself uses. There are three groups; only the third is optional. One thing sits outside all three and we would rather name it than let "everything" imply otherwise: when you preview a YouTube video asset inside the campaign creators, that video is embedded from YouTube, and YouTube sets its own cookies on your device when the player loads. That happens only if you open such a preview, and it is not covered by the choices below.

Strictly necessary cookies

These are set by us, carry no third party, and are not consent-gated, because sign-in does not work without them. They are the only cookies we set of our own accord:

  • joonads_session — keeps you signed in. A signed token holding your user id, email address, role, account status and current organization. It is httpOnly, so scripts on the page cannot read it, is marked Secure in production, and lasts 30 days or until you sign out.
  • joonads_oauth_state_g, joonads_oauth_state_m, joonads_oauth_state_ms — one random value per sign-in attempt with Google, Meta or Microsoft, checked when you return so a sign-in cannot be forged from another site. Also httpOnly, limited to our authentication endpoints, valid for ten minutes, and discarded as soon as the sign-in finishes.

Browser storage the app uses

Beyond cookies, the app keeps working data in your browser's local and session storage. This is not a tracker and is not transmitted anywhere on its own — it is read by the app running on your own device — and clearing your browser data for this site removes all of it. It includes:

  • Caches, so pages load without re-fetching: recent dashboard metrics, keyword research, suggestions, and saved campaign, search-term and creative analyses, kept per ad account
  • Your last selections — which ad account, organization and business profile you were working in, and the email address you last signed in with
  • A description of your connected Meta session: the ad account names and ids the account picker needs. Access tokens for your connected advertising platforms are deliberately not kept here — they are held on our servers
  • Your in-app notifications, the feedback and learning records behind the AI suggestions, a log of the suggestions you have applied, and business profile and planner drafts
  • Interface state, such as a reminder you dismissed, and short-lived hand-offs that carry a selection from one page to the next as you navigate

Some of this mirrors data we also hold on our servers. Clearing it in your browser does not delete our copy — Section 8 covers what does.

Analytics and advertising tags

The Service can run two kinds of third-party tag. An analytics tag — Google Analytics 4 — tells us which parts of the product are used, so we can improve them. Advertising tags — the Google Ads tag and the Meta pixel — measure our own ad campaigns and let us reach people who have visited this site.

Each tag runs only where its identifier has been configured for that deployment, and only after you have agreed to that tag's category. A tag whose identifier is not configured is never loaded. Where none of the three is configured, no analytics or advertising tag runs at all, none of the cookies described below are set, and no consent banner appears — there would be nothing to consent to. We describe the mechanism rather than listing which identifiers happen to be set this week, so that this section stays accurate as tags are switched on or off.

Consent. Where a tag is configured, nothing loads until you choose. Every storage and advertising signal is set to denied before any tag code can run, and we do not fetch the tag script itself until you have granted its category — so no tag request reaches Google or Meta from this site before your decision. Analytics and advertising are two separate choices: granting analytics alone never loads the Meta pixel or the Google Ads tag. You are asked on your first visit, through a banner offering accept all, reject all, or a per-category choice.

Withdrawing consent. A Cookie settings control sits in the footer on every page, signed in or out, and reopens the same choices at any time, with the same "reject all" option the banner offered. Withdrawing is no harder than granting was. When you withdraw, we send the tags a real withdrawal signal, stop sending them anything ourselves, clear the account identifier we had given Google Analytics, tell the Meta pixel to stop sending events, and delete the identifiers those tags had already written to your browser. Four limits we would rather state than gloss over. First, that deletion is done by script and can only reach cookies that are visible to it, so it is thorough in practice but not something we can guarantee for every browser configuration. Second, a tag script that has already loaded stays in the page until your next full page load. Third — and this is the one most cookie notices skate over — what the withdrawal signal does differs by tag: the Meta pixel stops transmitting, but Google's tag treats it as a ban on storing and reading cookies rather than a ban on sending, so until that next full page load it can still send Google a small number of measurements it takes by itself, such as that you scrolled a page or clicked a link to another site. Those carry no analytics cookie and no account identifier of ours, and we send nothing further, but we are not going to claim they do not happen; reloading the page, or closing the tab, ends them. Fourth, none of this reaches what Google or Meta already hold on their own systems, for which you would need their own privacy controls.

What the tags set. When you grant analytics, Google Analytics sets cookies whose names begin _ga, _gid and _gat, to tell browsers and sessions apart. When you grant advertising, the Google Ads tag and the Meta pixel set cookies whose names begin _gcl, _fbp and _fbc, to attribute a visit to an ad click. These are set by Google and Meta rather than by us, and they are the ones we delete when you withdraw. Your choice itself is recorded in your browser's local storage under joonads_consent — deliberately not a cookie, so that recording a refusal does not itself set one.

What the tags are allowed to see

The signed-in app displays your advertising data, and its addresses and page titles can carry ad-account ids, customer ids and campaign identifiers. We do not let the analytics tag read them. Rather than reporting the address you are on, the tag reports a name taken from a fixed internal list of pages — "Dashboard", "Create campaign", "Settings" and so on. Query strings and fragments are dropped in every case, the page titles sent are our own fixed labels rather than the title the page displays, and any page not on that list is reported as an unnamed route instead of by its address. The list is closed by design, so a page added in future is withheld until it is deliberately added to it.

The same applies to where you came from. A browser normally tells the next page the address of the previous one, and within a site that address is passed in full, query string included — so a page we would redact could otherwise be handed over the moment you clicked a link away from it. We set that value ourselves rather than letting the tag read it: a page inside this site becomes the same fixed name from the same list, and if you arrived from somewhere else we record that site's address alone — example.com, not the page or the link you followed.

When you are signed in, Google Analytics also receives our own internal identifier for your account and the fact that you are signed in, so that a visit before and after sign-in can be counted as one journey. It does not receive your name or email address, your customers' data, or any campaign, keyword or ad-account identifier. As with any request your browser makes to any site, Google and Meta do receive your IP address and browser details.

One limitation we would rather name than bury: the Meta pixel reads the browser's address bar — and the address of the page you came from — for itself, and Meta offers no supported way to override either. So where the Meta pixel is configured and you have granted the advertising category, both of those addresses can reach Meta in full even though we also pass it a reduced path and a reduced referring page of our own. The scrubbing described above is applied wherever we control what is sent, but it cannot bind Meta's own collection. If that matters to you, decline the advertising category and the pixel is never loaded.

4. How We Use Your Information

  • To provide and maintain the Service, including displaying your advertising data and enabling campaign creation
  • To generate the AI features you ask for — optimization recommendations, keyword and audience research, ad copy, and generated images and video. This involves sending the relevant data to the AI providers named in Section 6
  • To authenticate your identity and manage your account
  • To communicate with you about Service updates and support
  • To improve and optimize the Service
  • To comply with legal obligations

5. Google API Services

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means we use Google user data — your Google Ads data, Merchant Center products, and GA4 reports — only for the purposes described in this policy: showing you your advertising data, making the campaign changes you choose to apply, and producing the AI recommendations and creative that are the core of the Service. We do not use it to serve advertisements, we do not sell it, and we do not use it to build advertising or credit profiles.

Generating those AI features requires transferring Google user data to the AI providers listed in Section 6. They process it on our instructions to return a result to you, and for no independent purpose of their own. Access by our own staff is limited to what is needed to operate and support the Service, to investigate a security issue, or where the law requires it.

6. Data Sharing and Disclosure

We do not sell or rent your personal information. Everything we do share falls into the categories below: a provider processing data on our instructions so we can deliver a feature you asked for, a transfer you initiated yourself, a disclosure the law requires, or — only if you consent to it, and only for data about your use of this website and app — the analytics and advertising tags described in Section 3. Those categories are the commitment. The provider names inside them are the current facts as of the "Last updated" date at the top of this page — when we change, add or remove a provider we update this section rather than leave it stale, and you can ask us at the address in Section 12 for the providers in use on any given date.

  • AI Providers: To produce recommendations, keyword and audience research, ad copy, creative analysis, and generated images and video, we send the relevant data to AI services that process it and return a result. Depending on the feature this can include campaign names, budgets, spend and performance metrics, keywords and search terms, existing ad copy and creative, your ad images and video, and — where you have connected Google Analytics — the aggregated GA4 figures described in Section 2. The providers we use are:
    • Anthropic — optimization recommendations, keyword and audience research, ad copy, and creative analysis
    • OpenAI — image generation and editing in Creative Studio
    • Google (Gemini / Vertex AI) — creative embeddings, creative feature extraction, and video generation
    • fal.ai — video generation and editing in Creative Studio
  • Hosting and Infrastructure: Google Cloud Platform hosts the Service and stores your data (Cloud Run, Cloud SQL, and Cloud Storage for generated creative), in the United States
  • Payments: Stripe processes subscription and credit purchases. You enter your card details with Stripe directly; we store only the Stripe customer and subscription identifiers, never your card number
  • Email Delivery: Resend delivers our email — sign-up and access messages, organization invitations, low-credit alerts and scheduled digests. It receives your email address and the content of the message
  • Website Screenshot Capture: Creative Studio lets you paste the address of a web page or a live ad to use as a visual style reference. To turn that address into an image we send it to a third-party screenshot service, which loads the page and returns a picture of it. The address is all that leaves our systems for this — no account data goes with it. Unless we have configured a different screenshot provider, that service is microlink.io. Because the address itself is what we hand over, do not paste a URL that is private or that carries a token or personal detail in it
  • Sales Enquiries: The contact, demo and sign-up submissions described in Section 2 are emailed to our own team through Resend, and — where we have a spreadsheet mirror configured — also posted to a Google Sheets webhook so the enquiry reaches our sales sheet. Both carry the name, email address, company and message you entered and which form it came from; neither carries the IP address
  • Analytics and Advertising Tags: Where these tags are configured and you have consented to them (Section 3), Google receives website and app usage data through Google Analytics, and Google and Meta receive it through the Google Ads tag and the Meta pixel. This is data about your use of our product: which pages of joon ai you visited — as the fixed page names described in Section 3 — your IP address and browser details, and, when you are signed in, our internal identifier for your account. Two specific actions are also reported to the Google Ads tag as conversions: creating an account, which sends our internal identifier for your account as the order reference and no monetary value; and buying credits, which sends the amount you paid, its currency, and the payment processor's reference for that purchase as the order reference. Neither carries your name, your email address, your card details, or anything about your advertising accounts. Google and Meta process it in the United States and in the other countries in which they operate, consistent with the United States hosting described above, and they may use it under their own terms as well as ours. This is the only category of sharing you can switch off, and switching it off costs you nothing in the Service
  • Advertising Platforms: When you create or modify campaigns, we send data to the respective advertising platform APIs on your behalf. This is your ad account data — campaigns, budgets, targeting and creative — sent to the platform that already holds the account because you instructed us to act on it. It is a different thing from the usage data in the entry above, and none of it is ever sent to the analytics or advertising tags
  • Legal Requirements: When required by law, regulation, or legal process
  • With Your Consent: When you explicitly authorize sharing

What stays fixed, whatever the provider list says on a given day, is the bound on the sharing. Your account data, your advertising-platform data, your Merchant Center products and your GA4 reports are disclosed only to deliver a feature you asked for, to carry out a transfer you initiated, or where the law compels us. We do not sell or rent them, we do not disclose them to advertising networks or data brokers, and we do not authorize any provider to use them for purposes of their own.

The one thing that sits outside that bound is the website and app usage data collected by the analytics and advertising tags. We should be plain about it rather than let the paragraph above imply otherwise: that data is collected for our own measurement and marketing rather than to deliver a feature you asked for, it does go to Google and Meta acting as advertising networks, and they may use it for their own purposes under their own terms. It is also the only category here that is entirely optional. It is collected only if you consent, only where a tag is configured, and only for as long as you leave that consent in place — and it never includes your customers' advertising data.

7. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS/SSL), secure token storage, and access controls. However, no method of transmission or storage is 100% secure.

8. Data Retention

We keep your account data, and the advertising data we pull from your connected accounts, for as long as your account is open. To be plain about what that means: the metrics, analyses, alerts, keyword records and creative records we store are not deleted on a schedule. There is no automatic expiry and no purge job. They stay until you delete them, or until you ask us to.

You can delete data yourself in two ways:

  • Delete a connected ad account (Settings) removes the data we store against that account: its analyses and alerts, daily metric and search-term snapshots, keyword repository entries and trend alerts, keyword feedback, analysis jobs, creative records with their snapshots and embeddings, and any audiences we created for it. It runs as a single all-or-nothing operation and cannot be undone.
  • Close your JoonAds account (Settings) deletes your user record and the data stored against it, including your Creative Studio history and stored platform tokens. If you are the only member of your organization, the organization goes with it, along with its business profiles, credit balance and pending invitations. If other members remain, you leave and their shared data stays with them — and if you are the last owner of an organization that still has members, we ask you to transfer ownership first rather than strand your team.

Both controls work by finding the rows that are keyed to your account or to the ad account you named. Some records we hold are not keyed that way, so neither control reaches them. We would rather list them than let "delete" imply a clean sweep:

  • Payment records held by Stripe. These are financial records a business is required to retain, and they live with Stripe rather than in our database. This one is deliberate.
  • Sales enquiry records. The contact, demo and sign-up submissions described in Section 2 are stored against the email address you typed, not against a user account — you may never have had one when you sent them. Closing your account does not remove them.
  • Meta lead-form submissions. Where Meta lead-ad delivery is enabled for a page, the details a person enters into one of your lead forms reach us keyed to the Meta page, form and ad they came from — not to your user record and not to an ad account id. That is their personal data rather than yours, and neither deletion control can locate it from your side, so neither removes it.
  • Files stored in Cloud Storage. Creative Studio keeps image and video files — both the ones you upload, such as product photographs and brand assets, and the ones the Service generates — in cloud storage, while the database holds only the path to each file. Closing your account or deleting an ad account removes the database records, so the history disappears from the Service, but it does not currently delete the stored files themselves.

For everything in that list except the Stripe records, tell us at the address in Section 12 — which email address you used, which Meta page or lead form the submissions belong to, or that you want your stored files removed — and we will delete those records for you.

Separately, the Service stores data in your browser rather than on our servers — the caches, selections and interface state listed in Section 3, plus, where analytics or advertising tags are configured, your recorded consent choice and the tags' own cookies. The dashboard metric cache is refreshed at the start of each calendar day. Clearing your browser data for this site removes all of it, and Section 3 explains how to withdraw tag consent without clearing anything.

You may also request deletion of your data at any time by contacting us at the address in Section 12.

9. Your Rights

You have the right to:

  • Access the personal data we hold about you, and request a copy of it
  • Request correction of inaccurate data
  • Request deletion of your data — see Section 8 for the controls you can use yourself
  • Disconnect your connected advertising accounts at any time — see Section 10
  • Give, refuse or withdraw your consent to the analytics and advertising tags at any time, using the "Cookie settings" control in the footer — see Section 3. Refusing or withdrawing costs you nothing: every feature of the Service works the same either way

Access, copy and correction requests are handled by our team rather than through a self-service export. Contact us at the address in Section 12 and we will respond.

10. Disconnecting and Revoking Access

You can disconnect a connected advertising account at any time from the Service's Settings page. For Google Ads and Meta Ads this does two things. First we ask the platform to revoke the app's access — Google's token revocation endpoint, or removing joon ai's permissions from your Meta account. Then we delete the credential we hold, whether or not that revocation succeeded.

Deleting our copy is the part that always happens, and it is the part that stops us using your grant. Revocation at the platform is attempted, not guaranteed: the call can fail, time out, or report an error because you had already revoked the grant yourself. Settings tells you which of the two happened, and when we could not confirm the revocation it points you at the platform's own permissions page.

Microsoft Advertising can be connected two ways, and disconnecting does something different in each. If you connected it by signing in through Microsoft, we hold a refresh token from that consent — disconnecting deletes our copy, but it does not withdraw the consent itself, so remove JoonAds from your Microsoft account permissions if you want the grant gone at the source. If instead you supplied credentials directly, there is nothing held at Microsoft for us to revoke and deleting our copy is the whole of it.

For TikTok Ads and Apple Search Ads the credential is one you supplied to us directly rather than an authorization we were granted, so disconnecting deletes our stored copy and there is nothing for us to revoke upstream. Revoke or rotate those in the platform's own console.

In a shared workspace, disconnecting removes your connection only. If another member of your organization has also connected that platform for the same ad account, the Service keeps reaching the account through their authorization — the workspace may continue to show as connected, and scheduled syncs and analyses running under their account may keep pulling its data. Their grant is theirs to revoke, not ours. To stop the Service reaching an ad account altogether, every member who connected it has to disconnect, or the access has to be removed at the platform.

You can revoke the authorization at its source at any time, directly with the platform:

Disconnecting stops future access. On its own it does not delete the data we have already collected — use the deletion controls in Section 8 for that.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at contact@joonlabs.ai, or by mail:

Joon Labs Inc.
6 Craig Cres, Georgetown ON L7G 5J9, Canada