Privacy
Approval Studio for Asana · last updated 25 September 2026
Approval Studio for Asana sends files attached to tasks in the Asana projects you link to your Approval Studio account, and posts review outcomes back to those tasks. This page sets out what it stores, what it can reach, and how to stop it.
What we store
- An access token for Approval Studio and an access and refresh token for Asana, so the service can act on your behalf without holding your password. We never see or store either password.
- Your name and email address as reported by Asana and by Approval Studio, and the names of your Asana workspaces, so the page can show which accounts are connected.
- The Asana projects you linked, and for each task that has sent files: the matching Approval Studio project and the names of the attachments already sent. That list is how the service tells a new file from one it has already delivered.
- A short activity list (the last 100 entries) and your settings.
What the service can do in Asana
It reads the projects you link: their tasks and attachments. On those tasks
it only adds comments and marks the task complete or incomplete.
It never edits, reassigns or deletes tasks, and it never touches projects you
have not linked. It holds only the Asana permissions those actions need:
workspaces:read, projects:read, users:read,
tasks:read, tasks:write, attachments:read,
stories:write and webhooks.
What it does in Approval Studio
It creates one project for each Asana task that has files, uploads those files, and optionally starts the workflow you choose. It subscribes to your account's events so review outcomes can be passed back to Asana. It only relays events for projects it created.
How tokens are protected
Tokens are encrypted at rest with AES-256-GCM. The key is kept in the service's configuration, not alongside the data, so a copy of the stored data cannot be used on its own to reach your accounts. Tokens are never sent to your browser and never appear in logs. Incoming Asana and Approval Studio events are checked against a per-connection signing secret before anything is done with them.
Who else sees it
Nobody. Data is not sold, shared or used for advertising, and there are no third-party analytics or trackers on these pages. The service talks only to Asana and to Approval Studio.
Deleting your data
Disconnect and erase this connection on your connection page removes the tokens, links, history and settings immediately and permanently. It also removes the event subscriptions the service created in Asana and in Approval Studio. Files and comments already delivered stay where they are, in your own accounts.
You can also revoke access from Asana at any time, under My settings → Apps → Deauthorize.
Retention
Records are kept while the connection exists. A setup that is never completed is deleted automatically within 24 hours.
Contact
Questions about this service or your data: support@approval.studio.