← Back to ROASt Labs

Privacy Policy

How ROASt Labs handles your data

Last updated: 30 June 2026 · Effective: 30 June 2026

ROASt Labs (app.roast-labs.com) is a multi-platform paid-media portfolio management and budget optimisation tool covering Google Ads, Microsoft Advertising, Meta Ads, and TikTok Ads, operated by Thomas Edward Johnson, trading as ROASt Labs (“we”, “us”, “our”). This Privacy Policy explains how we collect, use, store, and protect your data when you use the ROASt Labs service.

By connecting any advertising or analytics account to ROASt Labs, you consent to the data practices described in this policy. The service is available at roast-labs.com (marketing site) and app.roast-labs.com (application).

1. What Data We Collect

1a. Advertising Platform Data

When you connect a Google Ads, Microsoft Advertising, Meta Ads, or TikTok Ads account via OAuth 2.0, ROASt Labs accesses the following data through the relevant platform’s API:

We do not collect personal information about your ad viewers, click-level data tied to identifiable individuals, or any personally identifiable information (PII) from your advertising accounts.

1b. Goal-Source Data (Optional Integrations)

If you choose to route a portfolio’s success metric to one of the following sources, ROASt Labs accesses the data required to compute that goal:

Each integration is opt-in. You can revoke any goal-source connection at any time from the Accounts tab.

1c. Account and Authentication Data

1d. Billing Data

1e. Locally Stored Data

2. How We Use Your Data

Your advertising and goal-source data is used solely to:

We do not use your connected advertising-platform or goal-source data for advertising, profiling, remarketing, creditworthiness assessment, or any purpose other than providing the ROASt Labs service to you. (Separately, and only with your consent, our marketing site uses a Meta pixel to measure the ads that bring visitors to us — see Section 6b. That involves marketing-site visit data only, never your connected advertising-account or goal-source data.)

2a. Autonomous Mode Disclosure

ROASt Labs offers an optional autonomous mode in which the optimisation engine runs nightly and applies recommended changes without per-change approval. This mode is disabled by default. When you enable it:

You remain responsible for the performance of your advertising campaigns. See our Terms of Service for the full responsibility allocation.

3. Platform API Compliance and OAuth Scopes

3a. OAuth Scopes Requested

ROASt Labs requests only the OAuth scopes needed to provide the service. By platform:

You can revoke any platform’s OAuth grant at any time from the relevant platform’s account settings (e.g. Google permissions) or by disconnecting the account from the ROASt Labs Accounts tab.

3b. Google API Services User Data Policy — Limited Use Disclosure

ROASt Labs’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

4. Data Sharing and Sub-Processors

4a. General Position

We do not sell, rent, or share your advertising or goal-source data with any third parties for their own marketing or commercial purposes. Your data is accessible only to:

4b. Sub-Processors

We use the following sub-processors. Each is bound by a written agreement that requires them to process your data only on our instructions and to apply appropriate security measures. (The exception is Meta: for the consent-gated marketing-site pixel, Meta acts as an independent controller of the page-visit data under its own terms, rather than as a processor acting solely on our instructions — see Section 6b.)

Sub-processor Purpose Location
RenderApplication hosting and managed Postgres databaseEU (Frankfurt)
StripeSubscription billing and payment processingUSA / Ireland
AnthropicAI agent (Flume) and report generationUSA
Google (Analytics)Consent-gated sign-up / trial / purchase conversion measurement (see Section 6a)USA
Meta (Facebook)Consent-gated advertising measurement on the marketing site (Meta pixel) — see Section 6bUSA / EU
CloudflareMarketing site hosting (Pages), DNS, CDN, R2 encrypted backupsGlobal edge / EU

We will provide reasonable advance notice via the ROASt Labs interface before adding any new sub-processor that materially changes how your data is processed.

4c. AI Processing (Anthropic)

ROASt Labs includes an in-app AI agent (Flume) and AI-generated reports. When you use these features, the following data may be sent to Anthropic’s API to generate the response or report:

These requests:

If you do not wish to use AI features, simply do not invoke the Flume agent or AI-generated reports. The rest of the service operates independently.

4d. International Transfers

Some of our sub-processors (Stripe, Anthropic, Google, Meta) are located in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR Article 46, including the UK International Data Transfer Agreement (IDTA) and/or the European Commission’s Standard Contractual Clauses (SCCs), supplemented by the UK Addendum where applicable. Our sub-processors offer these mechanisms as standard. For the Meta pixel specifically, marketing-site measurement data transferred to Meta Platforms in the US relies on the EU–US Data Privacy Framework and its UK Extension. You can request copies of the relevant agreements by contacting us at the address in Section 11.

4e. Infrastructure Security

All data in transit is encrypted via HTTPS (TLS). The application database (Postgres on Render) is encrypted at rest. Encrypted backups are stored in Cloudflare R2 with AES-256-GCM application-side encryption (the encryption key is held only by us, not by the storage provider). See Section 7 for full security details.

5. Data Storage and Retention

Data deletion: You can disconnect any platform (Google Ads, Microsoft Advertising, Meta Ads, TikTok Ads, GA4, Shopify, HubSpot) at any time from the Accounts tab. Disconnecting a platform removes that platform’s OAuth tokens and the synced data scoped to that platform (campaigns, daily metrics, conversion actions, account configuration). Other connected platforms in the same workspace stay intact. Once you disconnect the last remaining platform on a workspace, all per-workspace synced data is wiped from our servers. To erase your entire account at once instead, use the self-service deletion flow described in Section 8.

6. Cookies and Tracking

6a. Inside the Application (app.roast-labs.com)

The application uses the following strictly-necessary browser storage at all times:

With your consent, the application also uses Google Analytics 4 (measurement ID G-WQJHG1ZPSD, the same property as the marketing site) to measure how people sign up, start a trial, and subscribe, so we can understand which marketing efforts work and improve the product. The analytics tag loads only after you accept analytics cookies — either via the marketing-site banner or the consent banner shown in the application if you have not already chosen. If you reject or have not yet decided, no analytics tag loads and no analytics cookies are set.

The application loads no advertising or retargeting pixels, sets no advertising cookies of its own, and uses no browser fingerprinting. (The shared roast_consent cookie records your marketing-site Advertising choice, but it is a strictly-necessary preference cookie, not a tracking cookie, and the application does not act on it.)

6b. Marketing Site (roast-labs.com)

The marketing site offers two optional cookie categories, controlled by the consent banner shown on first visit and re-openable at any time via the “Cookie settings” link in the footer:

7. Security

7a. Incident Response

In the event of a data breach affecting your Google Ads data or account credentials, we will:

8. Your Rights

You can at any time:

8a. Legal Basis for Processing (UK GDPR / EU GDPR)

We process your Google Ads data under the following legal bases:

9. Children’s Privacy

ROASt Labs is a business-to-business tool designed for professional advertisers and agencies. The service is not directed at children under the age of 16 (or 13 where applicable). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes to how we use your Google Ads data, we will notify you via the ROASt Labs interface and prompt you to consent to the updated policy before continuing to use your data in any new way.

We encourage you to review this page periodically. The “Last updated” date at the top indicates when the policy was most recently revised.

11. Contact

For privacy questions, data access requests, or concerns about how we handle your data, contact us at:

If you are located in the UK or EU and are unsatisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO).