Legal
Privacy Policy
Last updated: July 13, 2026
This Privacy Policy explains how Joisk Studios Inc., a company based in Ontario, Canada (“Joisk,” “we,” “us”), the data controller for your information, collects, uses, and shares information when you use the Joisk website, iOS or Android apps, builder, and marketplace (the “Service”). It works alongside our Terms of Service. For any privacy question or request, contact privacy@joisk.com.
1. Information we collect
We collect information in three ways: what you give us, what you create, and what we observe.
- Account information, your email address, a username/handle, and authentication details, handled by Google Firebase Authentication. If you sign in with Google or Apple, we receive the basic account information that provider makes available, such as your email, display name, and profile image. Apple may provide a private relay email address.
- Payment information, when you subscribe, buy credits, or make a purchase, payment is processed by Stripe. We do not store your full card number; we keep limited records such as a Stripe customer ID, subscription status, and purchase history.
- Seller & payout information, if you sell, Stripe collects the identity and bank/payout details needed to pay you (via Stripe Connect). We receive payout status and transaction records, not your full banking credentials.
- Content you create, the prompts you write, the projects, assets, listings, storefront details, uploaded files (images, audio, video), and messages you send through the Service.
- Connected social accounts, if you connect a social platform (such as Facebook or Instagram) to publish from Joisk, we store an access token — encrypted at rest— plus basic account details (such as your Page or account names) so we can publish on your behalf, at your direction. You can disconnect at any time, which deletes the stored token. We use this access only to provide the features you enable and in accordance with each platform's terms.
- Usage & device data, how you interact with the Service, plus technical data such as IP address, browser/device type, mobile platform and app version, security-attestation results, and log events. If you turn on device alerts, we store a Firebase push token and a one-way identifier for that app installation until you sign out, disable the registration, or the token is no longer valid.
- Community-safety data, reports you submit, your reason and optional details, accounts you block, and the technical information needed to prevent report spam and investigate abuse.
- Reviewed mobile games, game code receives the taps or keyboard input and basic WebView runtime information needed for the play session. The first mobile release does not pass your email, profile, Joisk cloud saves, scores, achievements, device permissions, or native APIs to creator-authored game code. Reviewed games cannot make external network requests or offer purchases inside the app.
2. AI processing of your prompts
The builder uses artificial intelligence to turn your prompts and inputs into output. To do this, we send your prompts and relevant project context to trusted third-party AI service providers that generate the result and return it to us. We don't use these providers to sell your data, and we work with providers that contractually limit their use of your inputs. Don't put information into a prompt that you wouldn't want processed this way.
3. How we use information
- provide, maintain, and secure your account and the Service;
- run the builder, host your published projects, and deliver purchases;
- process payments, credits, payouts, taxes, refunds, and disputes;
- meter usage (credits, storage, bandwidth) and enforce limits and these policies;
- moderate content, prevent fraud and abuse, and comply with legal obligations;
- respond to support requests and send service-related communications; and
- understand usage and improve the Service.
5. Data retention
We keep your information for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to meet legal, tax, accounting, security, and dispute-resolution obligations. We may retain limited records of transactions and content others have purchased even after you delete the original.
Reports and moderation audit records may be kept for as long as reasonably necessary to investigate abuse, enforce our policies, protect users, or comply with law. Access is restricted, and when an account is deleted we remove or replace direct account identifiers where doing so does not undermine those safety purposes. We also retain a minimal deletion tombstone so delayed systems cannot recreate deleted account data.
6. Your choices & rights
You can update your account details, cancel your subscription, and manage billing from your account. Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing (for example under the GDPR or CCPA/CPRA). You can request account deletion inside the Joisk mobile app or at joisk.com/account/delete. You may also make a request through the contact page or at privacy@joisk.com. We'll respond as required by applicable law and won't discriminate against you for exercising these rights. Canadian users have rights under PIPEDA and may contact us or, if unsatisfied, the Office of the Privacy Commissioner of Canada.
Where the GDPR applies, we process personal information on the legal bases of performing our contract with you (providing the Service), our legitimate interests (securing, operating, and improving the Service and preventing abuse), your consent (where we ask for it, such as certain cookies), and compliance with legal obligations. Where required, cross-border transfers rely on appropriate safeguards such as Standard Contractual Clauses. We honor recognized browser opt-out signals, including Global Privacy Control (GPC), as a request to opt out where applicable law requires.
8. Security
We use technical and organizational measures to protect your information, and rely on established providers (Google, Stripe) for core infrastructure. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security. If you discover a vulnerability, please report it via our security page.
9. Children
The Service isn't directed to children under 13, and we don't knowingly collect their personal information. If you believe a child has provided us information, contact us and we'll delete it.
10. International users
We operate from, and use service providers located in, the United States and other countries. By using the Service, you understand your information may be transferred to and processed in countries with different data-protection laws than your own.
11. Data in the apps & stores you build
Joisk lets creators add sign-in, a database, contact/lead forms, and similar features to the apps, sites, and stores they build. When end users of a creator's published projectprovide information through those features (for example, they create an account in a creator's app or submit a creator's contact form), the creator is the controllerof that information and is responsible for how it's collected and used, for having a lawful basis and a privacy notice of their own, and for honoring their end users' requests. Joisk acts as a processorand stores and processes that data on the creator's behalf to run the feature (passwords are stored only in salted, hashed form; we don't use end-user data for our own marketing). If you are an end user of a project built on Joisk and have a request about your data, contact that project's creator; we'll assist them as required by law.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we'll update the “Last updated” date and, where appropriate, provide additional notice.
13. Contact
Questions about your privacy, or want to exercise a data right? Email privacy@joisk.com or use our contact page.
Joisk Studios Inc. · Ontario, Canada