§A.0 Document metadata
Effective date: March 12, 2026. Last updated: March 12, 2026. Version: 1.2. Document owner: JOICE.AI CO., LIMITED.
Plain-language summary
JOICE.AI builds electronic products, consults on technical programs, sells hardware and software, runs import-export trade, and publishes mobile management apps on Google Play and the App Store. To do this we collect some personal data — names, emails, device identifiers, advertising identifiers, purchase receipts, and the usual operational metadata. We use it to operate the service, respond to you, show advertising, comply with the law, and improve the product. We never sell your personal data. You can access, correct, export, or delete it any time by emailing dpo@joicettech.com. We retain different categories for different periods, never longer than we need to, and we protect data with industry-standard controls. Children under 13 (16 in some EU/UK member states) are not our audience and we delete their data if we learn we've collected it. We honor Global Privacy Control.
§A.1 Definitions
Personal Data means any information relating to an identified or identifiable natural person. Examples: name, email, IP address, device identifier, advertising identifier (IDFA or GAID).
Processing means any operation performed on Personal Data — collection, storage, use, disclosure, deletion.
Controller means the entity that determines the purposes and means of Processing. For this policy, the Controller is JOICE.AI CO., LIMITED.
Processor means an entity that processes Personal Data on behalf of the Controller — for example, an analytics vendor.
User means any natural person who visits joicettech.com or installs a JOICE.AI mobile application.
Device Identifier means a value used to identify a device — for example, an IDFA (iOS) or GAID (Android), an Android ID, an iOS Identifier for Vendors (IDFV), or a hardware fingerprint.
Ad Identifier means a Device Identifier specifically used for advertising purposes, subject to platform-level controls (e.g., iOS App Tracking Transparency, Android Advertising ID).
SDK means a software development kit integrated into our mobile applications for a specific purpose — analytics, advertising, crash reporting, and so on.
Service means joicettech.com and all JOICE.AI mobile applications collectively.
App means each individual JOICE.AI mobile application published on Google Play or the Apple App Store.
§A.2 Who we are (controller)
Legal name: JOICE.AI CO., LIMITED
Registered office: Rm 701(108B) 7/F NEW MANDARIN PLZ TWR B, 14 SCIENCE MUSEUM RD, Tsim Sha Tsui East, Hong Kong
Website: https://joicettech.com
General support: support@joicettech.com
Key accounts: shaoyixin@joicettech.com
Privacy / DPO contact: dpo@joicettech.com (operational alias routing to support@joicettech.com)
EU representative: To be appointed and listed here before any EU-targeted app release — placeholder slot reserved per Article 27 GDPR.
UK representative: To be appointed and listed here before any UK-targeted app release — placeholder slot reserved per Article 27 UK GDPR.
If you are in the EU/UK and we have not yet listed a local representative, please contact dpo@joicettech.com and we will respond directly from our Hong Kong office or appoint a representative without undue delay.
§A.3 Scope of this policy
This policy applies to:
- The website — joicettech.com, including all subpages (the homepage, business services, corporate culture, company news, contact, this privacy policy, and the terms of service).
- The mobile applications — every App published by JOICE.AI CO., LIMITED on Google Play and the Apple App Store.
This policy does not cover third-party sites we link to. Each linked site has its own privacy policy; please read them.
This policy does not cover the Apple App Store or Google Play Store themselves. Their privacy practices are described in their respective privacy policies (Apple, Google).
§A.4 Personal data we collect
| Category | Examples | Source | Lawful basis (GDPR Art. 6) | Retention |
|---|---|---|---|---|
| Account data | Name, email, hashed password | Direct from user | Contract (b); Consent (a) | Account life + 30 days |
| Contact-form data | Name, email, company, message body | Direct from user | Consent (a) | 24 months |
| Device & usage | IP, OS, app version, crash logs, session timestamps | Automated (SDK) | Legitimate interest (f); Consent where required | 13 months |
| Advertising identifiers | IDFA (iOS), GAID (Android), IP, coarse location | Automated (ad SDKs) | Consent (where required by law — EU/UK/CA); Legitimate interest elsewhere | Per vendor; max 13 months |
| Purchase / IAP receipts | Receipt token, product ID, timestamp | App Store / Google Play | Contract (b); Legal obligation (c) | 7 years (tax) |
| Support correspondence | Emails, attachments | Direct from user | Contract (b) | 24 months after closure |
| Cookies & similar | See §A.8 | Browser | Consent (EU/UK); Legitimate interest elsewhere | See §A.8 |
We do not knowingly collect sensitive categories of personal data — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a person, health data, or data concerning a person's sex life or sexual orientation. If you choose to share such data with us (for example, in a support email), we delete it on receipt.
§A.5 How we use personal data
- Provide and maintain the Service. Account creation, authentication, syncing, in-app purchases, crash diagnostics.
- Respond to inquiries sent via the contact form, email, or in-app support.
- Process in-app purchases and refunds via Apple App Store and Google Play. Billing is handled by the App Store Provider; we receive receipt validation tokens only.
- Show advertising through the ad SDKs described in §A.6, in the ad formats described in §A.7.
- Detect fraud, abuse, and security incidents. Including anomalous sign-in patterns, scraping attempts, and unauthorized access.
- Comply with legal obligations. Tax, accounting, sanctions screening, law-enforcement requests, regulator correspondence.
- Improve the Service via aggregated, de-identified analytics.
- Send product updates — only where you have opted in. Every marketing email includes a one-click unsubscribe link.
§A.6 Third-party SDKs and ad platforms
JOICE.AI apps integrate the following third-party SDKs. For each: what it does · data collected · lawful basis · how to opt out · vendor privacy link.
1. Google AdMob
What it does: Ad mediation and waterfall serving of banner, interstitial, rewarded video, and splash ads. Collects: device identifiers (IDFA/GAID), IP, OS version, locale, coarse location (if granted), performance metrics. Lawful basis: consent where required (EU/UK/CA), legitimate interest elsewhere. Opt-out: in-app Settings → Privacy → toggle "Personalized ads"; OS-level "Limit Ad Tracking" (iOS) / "Opt out of Ads Personalization" (Android). Vendor privacy: policies.google.com/privacy.
2. Google Ad Manager (GAM)
What it does: Programmatic ad serving. Collects: device identifiers, IP, OS, locale, coarse location. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: as for AdMob. Vendor privacy: policies.google.com/privacy.
3. Meta Audience Network
What it does: Social-network-based ad serving. Collects: device identifiers, IP, OS, locale, advertising interactions. Lawful basis: consent. Opt-out: in-app toggle; OS-level; Meta's audience-based advertising opt-out. Vendor privacy: facebook.com/policy.php.
4. Unity Ads
What it does: In-app video ad serving. Collects: device identifiers, IP, OS, performance metrics. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: unity.com/legal/privacy-policy.
5. AppLovin
What it does: In-app ads and MAX mediation. Collects: device identifiers, IP, OS, locale. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level; applovin.com/optout. Vendor privacy: applovin.com/privacy.
6. ironSource (Unity LevelPlay)
What it does: Mediation. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: is.com/privacy-policy.
7. Pangle (ByteDance / TikTok)
What it does: In-app video ads. Collects: device identifiers, IP, OS, locale, advertising interactions. Lawful basis: consent. Opt-out: in-app toggle; OS-level; pangleglobal.com/privacy. Vendor privacy: same link.
8. Vungle
What it does: Video ad serving. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: vungle.com/privacy.
9. Chartboost
What it does: In-app ad serving. Collects: device identifiers, IP, OS. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: chartboost.com/legal/privacy-policy.
10. InMobi
What it does: Programmatic ad serving. Collects: device identifiers, IP, OS, locale, coarse location. Lawful basis: consent. Opt-out: in-app toggle; OS-level; inmobi.com/optout. Vendor privacy: inmobi.com/privacy.
11. Tapjoy
What it does: Offerwall and rewarded ads. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: tapjoy.com/legal/privacy-policy.
12. Mintegral
What it does: Programmatic and video ads. Collects: device identifiers, IP, OS, locale. Lawful basis: consent. Opt-out: in-app toggle; OS-level; mintegral.com/en/privacy. Vendor privacy: same link.
13. Digital Turbine
What it does: Mediation and on-device delivery. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: digitalturbine.com/privacy-policy.
14. Liftoff
What it does: Programmatic ad serving. Collects: device identifiers, IP, OS. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: liftoff.io/privacy-policy.
15. Moloco
What it does: ML-driven ad monetization. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: moloco.com/privacy-policy.
16. Yahoo Ads (Verizon Media)
What it does: Programmatic ad serving. Collects: device identifiers, IP, OS, locale. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level; Yahoo Ad Interest Manager. Vendor privacy: legal.yahoo.com/us/en/yahoo/privacy/index.html.
17. Smaato
What it does: Header bidding. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: smaato.com/privacy.
18. Start.io (Startapp)
What it does: In-app ad serving. Collects: device identifiers, IP, OS. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: start.io/policy/privacy-policy.
19. Appodeal
What it does: Mediation. Collects: device identifiers, IP, OS, advertising interactions. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: appodeal.com/privacy-policy.
20. BidMachine
What it does: Header bidding. Collects: device identifiers, IP, OS. Lawful basis: consent where required, legitimate interest elsewhere. Opt-out: in-app toggle; OS-level. Vendor privacy: bidmachine.io/privacy-policy.
§A.7 Ad formats — what we show and your choices
| Format | When shown | Data consumed by SDK | Your choices |
|---|---|---|---|
| Splash / open-screen ad | App cold start (immediately after launch) | Device identifiers (IDFA/GAID), IP, OS version, app version, locale | In-app Settings → Privacy → toggle "Personalized ads"; OS-level "Limit Ad Tracking" (iOS) / "Opt out of Ads Personalization" (Android); vendor opt-out pages listed in §A.6 |
| Rewarded video ad | User-initiated reward flows only (the user must tap "Watch ad to earn reward") | Engagement signal, device ID, IP, session metadata | Fully voluntary — simply don't tap the reward button; opt-out via in-app Settings |
| Interstitial ad | Natural transition points (between screens, between levels, returning from background) | Session metadata, device ID, IP, app state | In-app Settings → Privacy → toggle "Personalized ads"; OS-level opt-out |
| Banner ad | Persistent strip on selected in-app screens | Device ID, IP, coarse location (if granted), session metadata | In-app Settings → Privacy → toggle "Personalized ads"; reset ad ID via OS |
§A.8 Cookies and similar technologies on joicettech.com
We use a minimal set of cookies on joicettech.com. We do not run advertising cookies or third-party tracking pixels on this website.
What cookies are used
- Strictly necessary — a session cookie that remembers your acceptance of this policy. Expires when you close the browser.
- Preferences — a cookie that remembers your "reduce motion" preference if you toggled it. Expires after 30 days.
- Analytics — only after explicit consent. We use a privacy-respecting analytics provider that does not require cookies. We do not currently run third-party analytics on this site; this entry is reserved.
- Marketing — none. We do not run advertising or marketing cookies on this website.
Do Not Track / Global Privacy Control
We honor Do Not Track (DNT) and Global Privacy Control (GPC) where legally required. If your browser sends a GPC signal, we treat it as a valid opt-out of any "sale" or "sharing" of personal information as defined by CPRA.
How to clear cookies in major browsers
- Chrome: Settings → Privacy and security → Cookies and other site data → See all cookies and site data → Remove all.
- Safari: Preferences → Privacy → Manage Website Data → Remove All.
- Firefox: Preferences → Privacy & Security → Cookies and Site Data → Clear Data.
- Edge: Settings → Cookies and site permissions → Cookies and site data → See all cookies and site data → Remove all.
§A.9 Children's privacy
Our apps and the website are not directed to children under the age of 13, and we do not knowingly collect personal data from children under 13.
COPPA (United States)
We do not target children under 13. If we learn we have collected data from a child under 13 without verifiable parental consent, we delete it within a reasonable timeframe.
GDPR-K (European Union / United Kingdom)
For users under 16 (default; member-state law may lower to 13), we require parental consent. We make a reasonable effort to verify.
UK AADC (Age-Appropriate Design Code)
Where any feature is plausibly accessible to children, we apply high-privacy defaults: geolocation off by default, no profiling, no nudge techniques, no third-party tracking in child-directed contexts.
Brazil LGPD — children and adolescents
For users under 18, processing requires verifiable parental consent; we apply the highest protection standard available.
What happens if a child signs up
The account is suspended, associated data is purged from production systems within 30 days, backups within 90 days, and we notify the parent or guardian if we can contact them. Contact: dpo@joicettech.com.
§A.10 International data transfers
Data may be transferred from the EEA / UK to the United States, Singapore, Hong Kong, and other jurisdictions where our vendors operate. The mechanisms we rely on:
- EU → UK: EU adequacy decision for the UK (in force from 28 June 2021, subject to periodic review).
- EU / UK → United States: Standard Contractual Clauses (EU 2021/914) and the UK International Data Transfer Addendum. Where a vendor is certified under the EU–US Data Privacy Framework, we rely on that certification. We conduct transfer impact assessments for each vendor.
- EU / UK → Hong Kong / Singapore: Standard Contractual Clauses plus supplementary technical measures.
- PIPL (China): Because the controller is Hong Kong-based, PIPL applies where processing concerns mainland China natural persons. We apply PIPL cross-border transfer mechanisms (security assessment / SCC / certification) where required.
- Singapore PDPA: Cross-border transfer notification. We notify the PDPC where required.
- Brazil LGPD: International transfer on a lawful basis (standard contract clauses or cooperation agreement with a Brazilian authority).
List of countries where major vendors process data is published in our vendor list, available on request to dpo@joicettech.com.
§A.11 Data retention
We retain Personal Data only as long as necessary for the purposes for which it was collected, plus the periods below. After the retention period ends, data is deleted from production systems and backups.
- Account data: Account life + 30 days, then deleted from production. Backups: 90 days.
- Contact-form data: 24 months from last interaction.
- Device & usage: 13 months from collection.
- Advertising identifiers: Per vendor, maximum 13 months.
- Purchase / IAP receipts: 7 years (tax and accounting obligations).
- Support correspondence: 24 months after ticket closure.
- Cookies: Per §A.8 (session to 30 days).
Where we are legally required to retain data for longer (for example, tax records), the data is isolated from marketing and analytics systems and only accessed to comply with the legal obligation.
§A.12 Security
We apply industry-standard security controls to Personal Data:
- TLS in transit. All web and API endpoints enforce HTTPS.
- Encryption at rest where commercially reasonable, including full-disk encryption on production databases and encrypted backups.
- Access controls. Least-privilege role-based access to production systems. Production access requires hardware-backed multi-factor authentication.
- Audit logging. Production access is logged and reviewed.
- Vendor due diligence. Every vendor that processes Personal Data on our behalf is bound by a Data Processing Agreement and answers a security questionnaire before onboarding.
- Incident response. In the event of a Personal Data breach affecting your rights, we notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and notify affected users where required by applicable law.
No security measure is perfect. We do not guarantee absolute security. If you discover a vulnerability, please email dpo@joicettech.com with the subject "Security disclosure".
§A.13 Your rights — by region
EU / UK (GDPR / UK GDPR)
You have the right to: access your personal data, rectify inaccurate data, erase your data (right to be forgotten), restrict processing, portability (machine-readable export), object to processing based on legitimate interest, opt out of automated decision-making, withdraw consent at any time, and lodge a complaint with a supervisory authority.
To exercise any of these rights, email dpo@joicettech.com. We acknowledge within 7 days and respond substantively within 30 days.
California (CCPA / CPRA)
You have the right to: know what personal information we collect and how it is used, delete your personal information, correct inaccurate personal information, opt out of sale or sharing (we do not sell; we share for advertising — see §A.6), limit use of sensitive personal information (we do not collect), and non-discrimination for exercising your rights.
We honor Global Privacy Control (GPC) as a valid opt-out signal.
Brazil (LGPD)
You have the right to: confirmation of the existence of processing, access to your data, correction of incomplete or inaccurate data, anonymization, blocking, or elimination of unnecessary or excessive data, portability of your data, deletion of data processed with consent, and information about sharing with third parties.
Canada (PIPEDA + Quebec Law 25)
You have the right to: access your personal information held by us, correction of inaccurate information, withdraw consent at any time (subject to legal or contractual restrictions), and lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC).
Australia (Privacy Act 1988 + AU Children's Online Privacy)
You have the right to: access your personal information, correction of inaccurate information, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
Singapore (PDPA)
You have the right to: access your personal data, correction of your personal data, withdraw consent, opt out of marketing communications, and lodge a complaint with the Personal Data Protection Commission (PDPC).
China (PIPL, where applicable to mainland users)
You have the right to: 知情权 (right to be informed), 决定权 (right to decide), 查询权 (right to query), 复制权 (right to copy), 更正权 (right to correct), 删除权 (right to delete), and 解释权 (right to an explanation of processing rules).
To exercise any of these rights across any region, email dpo@joicettech.com. We acknowledge within 7 days and respond substantively within 30 days. We will not charge you for exercising your rights unless the request is manifestly unfounded or excessive.
§A.15 Account deletion
In line with Apple App Store Review Guideline 5.1.1(v), JOICE.AI apps provide account deletion inside the app.
How to delete your account
- In-app: Settings → Privacy → Delete Account (path may vary slightly per app).
- By email: Email dpo@joicettech.com with the subject "Delete my account".
What is deleted
Account and associated personal data are deleted from production within 30 days; backups within 90 days. Where we are legally required to retain specific data (for example, purchase receipts for tax), the retained data is isolated from marketing and analytics systems and used only to comply with the legal obligation.
Confirmation
A confirmation email is sent when deletion from production completes.
§A.16 Apple App Store disclosures
Our apps comply with the following Apple App Store Review Guidelines:
- Guideline 1.4.3 / 5.1.4 — Kids Category. JOICE.AI apps are not currently in the Designed for Families (Kids) category. If we later add a Kids-category app, we will use only neutral age gates and only approved SDKs.
- Guideline 5.1 — Privacy. We collect only data necessary for the functionality of the app and disclose it accurately on the product page.
- Guideline 5.1.1(v) — Account deletion. We provide account deletion inside the app. See §A.15.
- Guideline 5.1.2 — Data used to track you (ATT). We request user permission via Apple's App Tracking Transparency prompt before accessing IDFA for tracking purposes. If the user declines, we serve contextual ads only.
Privacy nutrition labels
For each app, we accurately declare the data types collected (contact, identifiers, usage data, diagnostics, purchases), the purposes (analytics, advertising, product personalization), and whether the data is linked to the user or not. We update the nutrition labels whenever our data practices change.
§A.17 Google Play disclosures
Our apps comply with the following Google Play policies:
- Developer Program Policy — Data Safety form. Every data type declared, every purpose declared, sharing vs. collection declared, security practices declared. We update the Data Safety form whenever our data practices change.
- Families Policy. JOICE.AI apps are not currently in the Designed for Families program. If we later add a Designed for Families app, we will use only neutral age gates and only approved SDKs.
- Ads policy. Ads are not deceptive, are appropriate to the audience, allow opt-out, and clearly disclose when an ad is being shown.
- User Data policy. We access, collect, use, and share personal and sensitive information only as necessary for the functionality of our apps and the purposes disclosed in our Privacy Policy.
§A.18 "Do Not Sell or Share My Personal Information"
JOICE.AI does not sell personal information as that term is defined by the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). We may share limited information with the ad vendors listed in §A.6 for the purpose of serving advertising. You can opt out of such sharing at any time:
- In-app: Settings → Privacy → toggle "Personalized ads" off.
- OS-level: iOS Settings → Privacy → Tracking → toggle off; Android Settings → Google → Ads → Opt out of Ads Personalization.
- Global Privacy Control: We honor GPC as a valid opt-out signal where your browser or extension sends it.
- By email: dpo@joicettech.com with the subject "Do Not Sell or Share".
§A.19 Third-party links
This website and our apps contain links to third-party sites (for example, links to vendor privacy pages in §A.6, links to the Apple App Store or Google Play Store, links to social profiles). We do not control those sites. Their privacy policies apply, not ours. We encourage you to read the privacy policies of every site you visit.
§A.20 Changes to this policy
We post updates with a new "Last updated" date at the top of this page. For material changes, we will show an in-app notice and email you at the address on file (if any). An archive of prior versions is available on request to dpo@joicettech.com.
§A.21 Contact & DPO
Privacy / DPO: dpo@joicettech.com (operational alias routing to support@joicettech.com)
General support: support@joicettech.com
Key accounts: shaoyixin@joicettech.com
Postal: JOICE.AI CO., LIMITED, Rm 701(108B) 7/F NEW MANDARIN PLZ TWR B, 14 SCIENCE MUSEUM RD, Tsim Sha Tsui East, HK
Response target: We acknowledge within 7 days and respond substantively within 30 days.
This Privacy Policy is governed by the laws of Hong Kong SAR, without prejudice to mandatory consumer protection laws of your country of residence.