Privacy

Approval Studio for Asana · last updated 25 September 2026

Approval Studio for Asana sends files attached to tasks in the Asana projects you link to your Approval Studio account, and posts review outcomes back to those tasks. This page sets out what it stores, what it can reach, and how to stop it.

What we store

We do not keep your files. Attachments pass through the service in memory on their way to Approval Studio. They are not written to disk or kept afterwards. Task descriptions and comments are never stored.

What the service can do in Asana

It reads the projects you link: their tasks and attachments. On those tasks it only adds comments and marks the task complete or incomplete. It never edits, reassigns or deletes tasks, and it never touches projects you have not linked. It holds only the Asana permissions those actions need: workspaces:read, projects:read, users:read, tasks:read, tasks:write, attachments:read, stories:write and webhooks.

What it does in Approval Studio

It creates one project for each Asana task that has files, uploads those files, and optionally starts the workflow you choose. It subscribes to your account's events so review outcomes can be passed back to Asana. It only relays events for projects it created.

How tokens are protected

Tokens are encrypted at rest with AES-256-GCM. The key is kept in the service's configuration, not alongside the data, so a copy of the stored data cannot be used on its own to reach your accounts. Tokens are never sent to your browser and never appear in logs. Incoming Asana and Approval Studio events are checked against a per-connection signing secret before anything is done with them.

Who else sees it

Nobody. Data is not sold, shared or used for advertising, and there are no third-party analytics or trackers on these pages. The service talks only to Asana and to Approval Studio.

Deleting your data

Disconnect and erase this connection on your connection page removes the tokens, links, history and settings immediately and permanently. It also removes the event subscriptions the service created in Asana and in Approval Studio. Files and comments already delivered stay where they are, in your own accounts.

You can also revoke access from Asana at any time, under My settings → Apps → Deauthorize.

Retention

Records are kept while the connection exists. A setup that is never completed is deleted automatically within 24 hours.

Contact

Questions about this service or your data: support@approval.studio.