Joint

Privacy Policy

Last updated: 2026-08-27

1. Who we are

JointDesign Inc. ("we", "us") operates the Joint web editor ("Service"). This policy explains what data we collect, why we collect it, and how we use it.

2. Core service data

2.1 Account data (if you sign in)

  • Email address, display name, and avatar URL from your auth provider (Google, etc.)
  • Account creation date and last login date

2.2 Project data

  • Project files you create or upload (stored in Amazon S3)
  • Asset files (GLB / DXF / thumbnail images)
  • User preferences and shortcut settings

2.3 Operational and security data

We may process request metadata, authentication/session records, server logs, IP address, timestamps, device/browser metadata, and error records when needed to provide, secure, debug, and prevent abuse of the Service.

2.4 Cookies and local storage

We use cookies and browser local storage to operate the Service:

  • Authentication and session cookies that keep you signed in.
  • A first-touch attribution cookie (jd_attr) that records which advertisement or referral brought you to Joint, so we can measure where sign-ups come from. If you sign in, it may be associated with your account once to attribute the sign-up. It is not used to build advertising profiles and is not shared with advertisers.
  • A browser signal reflecting whether the current telemetry journey is signed-in and linked or signed-out and identity-unlinked. You can remove it by clearing your browser storage.

3. Usage telemetry

We record the same telemetry categories whether you are signed in or signed out. Your authentication state determines whether a telemetry journey is identity-unlinked or linked to your account and project context; it does not change the event categories collected.

3.1 Identity-unlinked telemetry

When you are not signed in, we record editor workflow data in a session that is not linked to your account, persistent browser anonymous ID, or project record. It may include command history, event payloads, command parameters, coordinates, dimensions, error messages, timing data, model snapshots, session replay, and AI conversation text and execution outcomes. The first-party telemetry session does not store user IDs, persistent anonymous browser IDs, project IDs, or user-agent strings. Third-party replay tools are instructed to use non-persistent identity where their platforms support it.

3.2 Identity-linked telemetry

When you are signed in, we record the same in-app data and may associate the journey with account and project context. The telemetry data may include:

  • Commands you invoke (e.g. "create wall", "move vertex") with their parameters such as coordinates and dimensions
  • Tool switches, undo / redo, view changes, and errors
  • Timing information (when the command was issued, how long it took)
  • Periodic snapshots of the in-editor model state
  • AI questions, responses, tool plans, confirmations, execution results, and related performance or cost metadata
  • For linked journeys, project ID, client version, browser user-agent, and account ID

We do not intentionally record raw mouse movement, keystrokes outside of shortcuts, or filenames as plain text. Some project-context fields, such as editor object names or model state, may be included in diagnostic snapshots when telemetry is enabled.

4. Why we collect this data

  • To provide and operate the Service (project storage, sharing)
  • To diagnose and reproduce bugs reported by users
  • To secure accounts, prevent abuse, and troubleshoot service reliability
  • To analyze usage patterns and prioritize improvements across identity-unlinked journeys
  • For signed-in journeys, to add account and project context to that analysis

5. Legal basis (GDPR)

Where GDPR applies, this draft identifies legitimate interestas the basis for product telemetry, security, abuse prevention, and core service operation, including account and project context while you are signed in. You may object to this processing as described in Section 8. This draft must be reviewed by counsel before public release.

6. Sharing and third parties

We share data only with the following processors:

  • Amazon Web Services (hosting, database, file storage)
  • Google (authentication, if you sign in with Google)
  • PostHog (product analytics and session replay)
  • Microsoft Clarity (usage analytics and session replay)

We do not sell personal data. We do not share telemetry with advertisers.

7. Retention

  • Account data: kept while your account is active.
  • Project files: kept while your account is active, or until you delete them.
  • Operational and security logs: kept only as long as necessary to operate, secure, and troubleshoot the Service, and to investigate abuse or comply with law.
  • Telemetry events: kept only as long as necessary for the purposes described above, then deleted or anonymized.
  • If you delete your account, your account is marked deleted and we remove or de-identify your personal identifiers within a reasonable period; aggregated and anonymized telemetry may be retained for analytics.

8. Your rights

You can request to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated personal identifiers
  • Export your project data
  • Object to telemetry processing or ask us to unlink subsequent telemetry from your account

To exercise these rights, email us at support@joint.design.

9. Security

We use industry-standard measures to protect your data, including HTTPS in transit and encryption at rest in AWS, and we limit internal access to those who need it to operate the Service.

10. Changes to this policy

We may update this policy from time to time. The latest version will always be available on this page.

11. Contact

JointDesign Inc. support@joint.design