AdDesk Privacy Terms

Privacy Policy

Last updated 7 September 2026

AdDesk is operated by ZOI Studio PTY LTD (“we”). This policy explains what data AdDesk accesses from connected advertising platforms, why, how it is stored, and who can see it.

1. What AdDesk is

AdDesk is a reporting dashboard. An authorised person connects their advertising and monetization accounts, and AdDesk retrieves daily performance reports from those platforms and presents them together. It is used by mobile game studios to see revenue, advertising spend and profitability in one place.

2. Data we access

We access only aggregated advertising reporting data, and only for accounts whose owner has explicitly authorised AdDesk.

SourceData accessedScope
Google Ads Campaign name and ID, date, cost, impressions, clicks, conversions, account name, currency and time zone .../auth/adwords
Google AdMob Publisher account ID, app ID and name, date, estimated earnings, impressions, clicks, ad requests, match rate .../auth/admob.readonly
AppLovin MAX Package name, date, ad revenue, impressions, eCPM, mediated network, ad format Report key

What we do not access

We do not access end-user or player data, device identifiers, advertising IDs, contact lists, email, files, billing or payment instruments, or any personal information about the people who saw or clicked an advertisement. The data AdDesk reads is aggregate campaign and app performance only.

3. Read-only access

AdDesk only retrieves reports. It does not create, modify, pause or delete campaigns, budgets, bids, keywords, ad units or any other resource, and contains no functionality to do so. Google Ads publishes no read-only scope — .../auth/adwords is the only scope offered and technically permits writes — but AdDesk issues report queries exclusively.

4. Google user data — Limited Use

AdDesk’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data obtained from Google APIs is used solely to provide and improve the reporting features visible to the authorising customer. It is not transferred to others except as necessary to provide the service, comply with law, or as part of a merger or acquisition; it is not used for advertising; it is not sold; and no human reads it except with the customer’s explicit permission for support, for security investigation, or where required by law.

5. Credentials

Connecting an account stores an OAuth refresh token or API key so reports can be retrieved on a schedule without repeated sign-in. Credentials are encrypted with AES-256-GCM before being written to the database, held in a schema that is not exposed through any public API, and decrypted only by the background process that calls the platform. They are never sent to a browser and never appear in the interface.

Access can be revoked at any time by the account owner at myaccount.google.com/permissions, or by asking us to delete the connection. Revoking access immediately stops all further retrieval.

6. Storage, retention and location

Reporting data is stored as daily aggregates in a managed PostgreSQL database. Each customer organisation’s data is isolated at the database level, so one customer cannot read another’s. Data is retained while the account is active. On request, or within 30 days of an account closing, we delete the stored credentials and reporting data.

7. Sharing

We do not sell data and we do not share it with advertisers, data brokers or any third party for their own purposes. Data is processed by infrastructure providers acting on our instructions (hosting and database services). Within a customer organisation, an administrator controls which games each member can see.

8. Your rights

You may request a copy of the data we hold for your organisation, ask us to correct it, or ask us to delete it. Write to [email protected] and we will respond within 30 days.

9. Changes

If this policy changes materially we will update the date above and notify connected customers by email before the change takes effect.

10. Contact

ZOI Studio PTY LTD, Australia — [email protected]