Legal

Privacy Policy

This policy explains how Joe AI collects, uses, stores, shares, and protects personal data when you use joe-ai.com, Joe applications, connected services, APIs, and related business tools.

Last updated: July 23, 2026Effective date: July 23, 2026joe-ai.com

1. What this policy covers

This policy applies to visitors, registered users, workspace members, developers, administrators, prospects, and business contacts who interact with Joe AI.

Joe is built for teams. Users can express an intention, turn it into tasks, connect applications, and authorize Joe to perform work on their behalf.

2. Personal data we collect

Account and identity data

We may collect your name, professional email address, role, company, workspace permissions, account settings, authentication method, and related account lifecycle events.

Subscription and billing data

We may collect your subscription plan, billing contact details, transaction history, invoice data, tax information, and payment status. Full payment card details are usually handled by our payment provider.

Content you submit

We process prompts, intentions, instructions, conversations, uploaded files, imported content, generated tasks, execution plans, outputs, and feedback you submit to the service.

Connected service data

If you connect external apps, we may process identifiers, tokens, files, messages, documents, calendar data, emails, records, or other content needed to complete the task you requested.

Usage and technical data

We automatically collect IP address, device information, browser type, session identifiers, region, page interactions, usage volumes, error logs, and security events.

3. How we use data

We use personal data to:

  • create and manage accounts;
  • provide subscriptions, billing, and customer support;
  • interpret intentions, structure tasks, and execute requested actions;
  • connect third-party services and return results to you;
  • protect the platform from abuse, fraud, and unauthorized access;
  • measure performance, fix errors, and improve reliability;
  • send service, security, and account communications.
By default, business customer prompts, files, outputs, and connected-service data are not used to train general-purpose AI models unless the customer explicitly opts in or instructs us to do so.

4. Legal bases

Depending on the processing activity, we rely on one or more of the following bases:

  • performance of a contract;
  • legitimate interests;
  • consent where required;
  • legal obligation.

Contract performance covers account creation, the services themselves, task execution, and support. Legitimate interests cover security, fraud prevention, service improvement, and business continuity.

5. Sharing personal data

We may share data with:

  • cloud, hosting, database, storage, and observability providers;
  • model and automation providers used to complete your request;
  • authentication, payment, invoicing, support, and analytics vendors;
  • workspace administrators, if your account belongs to an organization;
  • professional advisers, regulators, or authorities when required by law;
  • third-party services that receive information at your request.

We do not sell personal data or provide customer prompts or confidential business content for targeted advertising.

6. Data retention

We keep data only as long as needed for the purposes described in this policy, unless a longer period is required by law.

  • Account information: generally retained for the life of the account and up to three years after termination.
  • Prompts, conversations, and outputs: retained until deleted or until workspace retention rules say otherwise.
  • Files and imports: retained while needed to provide the service or until removed.
  • Logs and security records: generally retained up to 12 months.
  • Billing records: retained for tax and accounting purposes, which may require up to 10 years.

7. Security

We use access controls, authentication, encryption, logging, monitoring, and incident-response procedures designed to protect personal data. No online service is perfectly secure, so we also ask users to protect their credentials and report suspicious activity promptly.

8. Your choices and rights

Depending on your location and account type, you may have the right to access, correct, delete, restrict, or port your data; object to some processing; withdraw consent; and lodge a complaint with a supervisory authority.

You may also disconnect integrations, manage cookies, and unsubscribe from marketing messages.

9. Children

Joe is a professional service for businesses and teams and is not intended for anyone under 18.

10. Contact

For privacy questions, contact privacy@joe-ai.com.

For formal notices, use the business contact details published on joe-ai.com.

11. Changes to this policy

We may update this policy to reflect new features, legal requirements, service providers, or business practices. The revised version will show the updated effective date on this page.