Privacy

Privacy Policy

This policy explains the information handled by the public Just One API website, including visit attribution, visitor cookies, and your saved language preference.

Last updated: July 19, 2026

Scope

This policy focuses on information handled when you visit justoneapi.com and its localized pages. Account, billing, and API-request processing in other Just One API services may involve additional information and operational systems not described by this public website code.

Links on this website can take you to the Dashboard, documentation, GitHub, Telegram, email, and other external services. Those destinations may apply their own privacy notices.

Information collected

When a page loads, the website creates or reads random visitor identifiers and records visit-source and attribution information. Depending on how you arrived, this can include the destination hostname and path, the full landing URL, referrer information, source and campaign classifications, a capture timestamp, and whether the visit was attributed to campaign parameters, a click ID, an external referrer, or no referrer.

The landing URL can contain query parameters. Attribution fields can include utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid, and ttclid. The website preserves first-touch and last-touch attribution snapshots in browser cookies.

When you select a language, the website stores that preference in your browser. If you contact us through email, Telegram, WeChat, or another linked channel, you choose what information to provide and that communication also passes through the selected provider.

Cookies and browser storage

The website uses the first-party cookies visitor_id, joa_utm_visitor_id, joa_utm_attr_first, and joa_utm_attr_last. They identify a browser for source attribution and preserve first- and last-touch details.

These cookies are configured with a browser lifetime of up to 365 days, SameSite=Lax, and Secure when the page uses HTTPS. On Just One API hosts they can be scoped to .justoneapi.com. Your browser settings or manual deletion can remove them earlier. This browser lifetime does not state how long any server-side record is retained.

The website stores a language you explicitly select in the host-only first-party Cookie joa_website_locale. It is configured with a browser lifetime of up to 365 days, Path=/, SameSite=Lax, and Secure when the page uses HTTPS. If this Cookie is absent, a request to the root URL uses the browser's Accept-Language header to choose a localized page without saving the inferred language.

Earlier versions stored the language preference under justoneapi:preferred-language in localStorage. If that legacy value exists and no language Cookie has been set, the website can read it once, copy a valid preference to the Cookie, and remove the localStorage value after the Cookie is saved.

How information is used

Visit-source and attribution records are used to understand how visitors reach the website, associate a browser with first- and last-touch campaign information, distinguish direct and referred visits, and evaluate acquisition paths. The saved language value is used to choose or preserve your preferred localized experience.

The website also uses the destination path and attribution context to keep source records consistent as you navigate. This policy does not claim that the collected fields are used for purposes not reflected in the website behavior described above.

Data transmission and external services

The website sends visit-source and attribution payloads to API endpoints hosted at api.justoneapi.com. Cookies scoped to .justoneapi.com can be available to Just One API subdomains according to browser cookie rules.

When you follow an external link or use an external communication provider, that service receives the request and may receive referrer or other technical information according to your browser and the provider's rules. Review the relevant provider's privacy information before submitting sensitive data.

Retention

The client-side periods are described above: attribution cookies and the language-preference Cookie are configured for up to 365 days. A legacy localStorage language value is removed after it is successfully migrated. The public website code does not define a fixed server-side retention period for records sent to the attribution endpoints.

For current information about a server-side record or a retention request, contact support and include enough context to identify the relevant browser identifier or communication, without sending passwords or API tokens.

Your choices

You can block or delete cookies through your browser and clear localStorage to remove any legacy language preference. Blocking these storage features can reset attribution identifiers or prevent the website from remembering a language you selected.

Removing campaign or click-ID parameters before visiting limits what appears in a new landing URL, but it does not undo information already sent when a page loaded. Subject to applicable law, you may contact us to ask about access, correction, or deletion of information associated with you; we may need enough information to locate and verify the request.

Security

No browser storage, network transmission, or server system can be guaranteed completely secure. Do not place passwords, API tokens, or other secrets in landing-page query parameters or messages sent through an inappropriate channel.

Updates and contact

We may update this policy when the website or its information-handling behavior changes. The date at the top identifies the latest posted version.

For privacy questions or requests, contact support@justoneapi.com or use the contact page. You can also review the Terms of Service.