← Back to ROASt Labs

Privacy Policy

How ROASt Labs handles your data

Last updated: 27 August 2026 · Effective: 27 August 2026

ROASt Labs (app.roast-labs.com) is a multi-platform paid-media portfolio management and budget optimisation tool covering Google Ads, Microsoft Advertising, Meta Ads, TikTok Ads, and OpenAI Ads, operated by Thomas Edward Johnson, trading as ROASt Labs (“we”, “us”, “our”). This Privacy Policy explains how we collect, use, store, and protect your data when you use the ROASt Labs service.

By connecting any advertising or analytics account to ROASt Labs, you consent to the data practices described in this policy. The service is available at roast-labs.com (marketing site) and app.roast-labs.com (application).

1. What Data We Collect

1a. Advertising Platform Data

When you connect a Google Ads, Microsoft Advertising, Meta Ads, or TikTok Ads account via OAuth 2.0, ROASt Labs accesses the following data through the relevant platform’s API:

When you connect an OpenAI Ads account (using an API key you generate in OpenAI’s Ads Manager rather than OAuth — see Section 3a), ROASt Labs accesses your ad account name, currency, timezone, and review status, campaign names, IDs, statuses, bidding types, and lifetime budgets, and daily performance metrics (spend, clicks, impressions) through the OpenAI Ads API. OpenAI’s API does not currently report conversion or revenue data.

We do not collect personal information about your ad viewers, click-level data tied to identifiable individuals, or any personally identifiable information (PII) from your advertising accounts.

1b. Goal-Source Data (Optional Integrations)

If you choose to route a portfolio’s success metric to one of the following sources, ROASt Labs accesses the data required to compute that goal:

Each integration is opt-in. You can revoke any goal-source connection at any time from the Accounts tab.

1c. Account and Authentication Data

1d. Billing Data

1e. Locally Stored Data

2. How We Use Your Data

Your advertising and goal-source data is used solely to:

We do not use your connected advertising-platform or goal-source data for advertising, profiling, remarketing, creditworthiness assessment, or any purpose other than providing the ROASt Labs service to you. (Separately, and only with your consent, our marketing site uses Meta and OpenAI pixels to measure the ads that bring visitors to us — see Section 6b. That involves marketing-site visit data only, never your connected advertising-account or goal-source data.)

2a. Autonomous Mode Disclosure

ROASt Labs offers an optional autonomous mode in which the optimisation engine runs nightly and applies recommended changes without per-change approval. This mode is disabled by default. When you enable it:

You remain responsible for the performance of your advertising campaigns. See our Terms of Service for the full responsibility allocation.

3. Platform API Compliance and OAuth Scopes

3a. OAuth Scopes Requested

ROASt Labs requests only the OAuth scopes needed to provide the service. By platform:

You can revoke any platform’s OAuth grant at any time from the relevant platform’s account settings (e.g. Google permissions) or by disconnecting the account from the ROASt Labs Accounts tab.

3b. Google API Services User Data Policy — Limited Use Disclosure

ROASt Labs’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

4. Data Sharing and Sub-Processors

4a. General Position

We do not sell, rent, or share your advertising or goal-source data with any third parties for their own marketing or commercial purposes. There is one opt-in exception, always under your control: if a workspace administrator switches on OpenAI conversion sharing (Section 4f), hashed conversion events derived from your Shopify order data are sent to OpenAI to improve the delivery of your own OpenAI Ads campaigns. Beyond that, your data is accessible only to:

4b. Sub-Processors

We use the following sub-processors. Each is bound by a written agreement that requires them to process your data only on our instructions and to apply appropriate security measures. (Two exceptions: for the consent-gated marketing-site pixels, Meta and OpenAI each act as an independent controller of the page-visit data under their own terms rather than as a processor acting solely on our instructions — see Section 6b; and for opt-in conversion sharing, OpenAI acts as an independent controller of the conversion events you choose to send it — see Section 4f.)

Sub-processor Purpose Location
RenderApplication hosting and managed Postgres databaseEU (Frankfurt)
StripeSubscription billing and payment processingUSA / Ireland
AnthropicAI agent (Flume) and report generationUSA
Google (Analytics)Consent-gated sign-up / trial / purchase conversion measurement (see Section 6a)USA
Meta (Facebook)Consent-gated advertising measurement on the marketing site (Meta pixel) — see Section 6bUSA / EU
OpenAIConsent-gated advertising measurement on the marketing site (OpenAI pixel) — see Section 6bUSA
CloudflareMarketing site hosting (Pages), DNS, CDN, R2 encrypted backupsGlobal edge / EU

We will provide reasonable advance notice via the ROASt Labs interface before adding any new sub-processor that materially changes how your data is processed.

4c. AI Processing (Anthropic)

ROASt Labs includes an in-app AI agent (Flume) and AI-generated reports. When you use these features, the following data may be sent to Anthropic’s API to generate the response or report:

These requests:

Scheduled AI processing (opt-in). Some AI features can also run on a schedule rather than only when you ask — for example the weekly context-hint scan, which writes suggested targeting for your ChatGPT (OpenAI Ads) ad groups. These are off by default: each one is tied to a named agent in the Agents tab that a workspace administrator must switch on, and switching it on is what starts the scheduled processing. While enabled, the same categories of data listed above — including your Context Hub notes — may be sent to Anthropic’s API on that schedule, under the same terms, without a person initiating each request. Switching the agent off stops it immediately. Content generated this way is only ever proposed to you for review; nothing is applied to your advertising accounts without a person approving it.

If you do not wish to use AI features, simply do not invoke the Flume agent or AI-generated reports, and leave the scheduled agents switched off. The rest of the service operates independently.

4d. International Transfers

Some of our sub-processors (Stripe, Anthropic, Google, Meta, OpenAI) are located in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR Article 46, including the UK International Data Transfer Agreement (IDTA) and/or the European Commission’s Standard Contractual Clauses (SCCs), supplemented by the UK Addendum where applicable. Our sub-processors offer these mechanisms as standard. For the Meta pixel specifically, marketing-site measurement data transferred to Meta Platforms in the US relies on the EU–US Data Privacy Framework and its UK Extension. You can request copies of the relevant agreements by contacting us at the address in Section 11.

4e. Infrastructure Security

All data in transit is encrypted via HTTPS (TLS). The application database (Postgres on Render) is encrypted at rest. Encrypted backups are stored in Cloudflare R2 with AES-256-GCM application-side encryption (the encryption key is held only by us, not by the storage provider). See Section 7 for full security details.

4f. OpenAI Conversion Sharing (Opt-In)

If you run OpenAI Ads campaigns, a workspace administrator can optionally switch on conversion sharing with OpenAI (OpenAI’s Conversions API). This is off by default. Switching it on requires the administrator to explicitly confirm, at that moment, that your business has obtained the consents and has the legal bases needed to share the data below with OpenAI — this confirmation is recorded (who and when) before anything is set up.

When enabled, ROASt Labs creates conversion-tracking resources on your own OpenAI ad account (a measurement pixel, a purchase event definition, and a dedicated access key, each named “ROASt Labs …” so you can identify them in OpenAI’s Ads Manager), and then sends OpenAI conversion events daily for orders attributed to your campaigns. Each event contains at most: a one-way hashed (SHA-256) customer email address and customer ID, the order amount and currency, the order time, the landing-page address, and OpenAI’s own click reference. Never plaintext names, email addresses, or payment details.

For this data, OpenAI acts as an independent controller under its own terms and privacy policy (see OpenAI’s Privacy Policy), using it to measure and improve the delivery of your advertising. You can switch conversion sharing off at any time from the Accounts tab — ROASt Labs then deletes its stored copy of the access key and sends nothing further. Because OpenAI’s API offers no key-deletion endpoint, fully revoking the key also requires deleting it in OpenAI’s Ads Manager; the in-app confirmation walks you through this.

5. Data Storage and Retention

Data deletion: You can disconnect any platform (Google Ads, Microsoft Advertising, Meta Ads, TikTok Ads, OpenAI Ads, GA4, Shopify, HubSpot) at any time from the Accounts tab. Disconnecting a platform removes that platform’s OAuth tokens (or, for OpenAI Ads, the stored API key) and the synced data scoped to that platform (campaigns, daily metrics, conversion actions, account configuration). Disconnecting OpenAI Ads also removes the conversion-sharing configuration and ROASt Labs’s stored copy of the Conversions API key (Section 4f); disconnecting Shopify removes the stored order-attribution records, including the hashed email and customer-ID values. Other connected platforms in the same workspace stay intact. Once you disconnect the last remaining platform on a workspace, all per-workspace synced data is wiped from our servers. To erase your entire account at once instead, use the self-service deletion flow described in Section 8.

6. Cookies and Tracking

6a. Inside the Application (app.roast-labs.com)

The application uses the following strictly-necessary browser storage at all times:

With your consent, the application also uses Google Analytics 4 (measurement ID G-WQJHG1ZPSD, the same property as the marketing site) to measure how people sign up, start a trial, and subscribe, so we can understand which marketing efforts work and improve the product. The analytics tag loads only after you accept analytics cookies — either via the marketing-site banner or the consent banner shown in the application if you have not already chosen. If you reject or have not yet decided, no analytics tag loads and no analytics cookies are set.

The application loads no advertising or retargeting pixels, sets no advertising cookies of its own, and uses no browser fingerprinting. (The shared roast_consent cookie records your marketing-site Advertising choice; it is a strictly-necessary preference cookie, not a tracking cookie.)

Sign-up conversion to OpenAI (server-side, Advertising consent only): We advertise ROASt Labs on ChatGPT (OpenAI Ads). If — and only if — you accepted the Advertising cookie category on the marketing site, then when you complete sign-up with a verified email address (by verifying your email address after signing up, or by signing up with a Google account — which Google has already verified) we send OpenAI a single server-side “lead” conversion event so we can measure whether our own ChatGPT advertising leads to sign-ups. The event contains a one-way hashed (SHA-256) form of your email address and, where present, OpenAI’s own click reference — never your name, plaintext email, or account details. OpenAI acts as an independent controller of this event under its own privacy policy (see Section 6b). If you did not accept Advertising cookies, no such event is ever sent.

6b. Marketing Site (roast-labs.com)

The marketing site offers two optional cookie categories, controlled by the consent banner shown on first visit and re-openable at any time via the “Cookie settings” link in the footer:

7. Security

7a. Incident Response

In the event of a data breach affecting your Google Ads data or account credentials, we will:

8. Your Rights

You can at any time:

8a. Legal Basis for Processing (UK GDPR / EU GDPR)

We process your Google Ads data under the following legal bases:

9. Children’s Privacy

ROASt Labs is a business-to-business tool designed for professional advertisers and agencies. The service is not directed at children under the age of 16 (or 13 where applicable). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes to how we use your Google Ads data, we will notify you via the ROASt Labs interface and prompt you to consent to the updated policy before continuing to use your data in any new way.

We encourage you to review this page periodically. The “Last updated” date at the top indicates when the policy was most recently revised.

11. Contact

For privacy questions, data access requests, or concerns about how we handle your data, contact us at:

If you are located in the UK or EU and are unsatisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO).