Privacy Policy
Last updated 7 September 2026
AdDesk is operated by ZOI Studio PTY LTD (“we”). This policy explains what data AdDesk accesses from connected advertising platforms, why, how it is stored, and who can see it.
1. What AdDesk is
AdDesk is a reporting dashboard. An authorised person connects their advertising and monetization accounts, and AdDesk retrieves daily performance reports from those platforms and presents them together. It is used by mobile game studios to see revenue, advertising spend and profitability in one place.
2. Data we access
We access only aggregated advertising reporting data, and only for accounts whose owner has explicitly authorised AdDesk.
| Source | Data accessed | Scope |
|---|---|---|
| Google Ads | Campaign name and ID, date, cost, impressions, clicks, conversions, account name, currency and time zone | .../auth/adwords |
| Google AdMob | Publisher account ID, app ID and name, date, estimated earnings, impressions, clicks, ad requests, match rate | .../auth/admob.readonly |
| AppLovin MAX | Package name, date, ad revenue, impressions, eCPM, mediated network, ad format | Report key |
What we do not access
We do not access end-user or player data, device identifiers, advertising IDs, contact lists, email, files, billing or payment instruments, or any personal information about the people who saw or clicked an advertisement. The data AdDesk reads is aggregate campaign and app performance only.
3. Read-only access
AdDesk only retrieves reports. It does not create, modify, pause or delete campaigns, budgets,
bids, keywords, ad units or any other resource, and contains no functionality to do so. Google
Ads publishes no read-only scope — .../auth/adwords is the only scope offered
and technically permits writes — but AdDesk issues report queries exclusively.
4. Google user data — Limited Use
AdDesk’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained from Google APIs is used solely to provide and improve the reporting features visible to the authorising customer. It is not transferred to others except as necessary to provide the service, comply with law, or as part of a merger or acquisition; it is not used for advertising; it is not sold; and no human reads it except with the customer’s explicit permission for support, for security investigation, or where required by law.
5. Credentials
Connecting an account stores an OAuth refresh token or API key so reports can be retrieved on a schedule without repeated sign-in. Credentials are encrypted with AES-256-GCM before being written to the database, held in a schema that is not exposed through any public API, and decrypted only by the background process that calls the platform. They are never sent to a browser and never appear in the interface.
Access can be revoked at any time by the account owner at myaccount.google.com/permissions, or by asking us to delete the connection. Revoking access immediately stops all further retrieval.
6. Storage, retention and location
Reporting data is stored as daily aggregates in a managed PostgreSQL database. Each customer organisation’s data is isolated at the database level, so one customer cannot read another’s. Data is retained while the account is active. On request, or within 30 days of an account closing, we delete the stored credentials and reporting data.
7. Sharing
We do not sell data and we do not share it with advertisers, data brokers or any third party for their own purposes. Data is processed by infrastructure providers acting on our instructions (hosting and database services). Within a customer organisation, an administrator controls which games each member can see.
8. Your rights
You may request a copy of the data we hold for your organisation, ask us to correct it, or ask us to delete it. Write to [email protected] and we will respond within 30 days.
9. Changes
If this policy changes materially we will update the date above and notify connected customers by email before the change takes effect.
10. Contact
ZOI Studio PTY LTD, Australia — [email protected]