Snapshot Ledger privacy
Effective September 1, 2026
Data processed and stored
We store the connected Asana user and workspace identifiers; encrypted OAuth tokens; selected project identifiers and names; canonical task identifiers, names, completion state, assignee, dates, section, and custom-field values in compressed snapshots; generated report metadata; delivery preference; and Cazimedia billing identifiers.
Purpose
We use this data only to capture the selected projects, compare retained states, generate requested reports, deliver opted-in reports, enforce limits, authenticate the account, and manage the Snapshot Ledger subscription.
Retention and deletion
Snapshots expire after 90 days. Generated downloads expire after 15 minutes. Authenticated deletion removes the Asana connection, snapshots, reports, schedules, and account records after any active subscription is cancelled.
Processors
Cloudflare hosts the Worker, D1 database, Queue, Durable Object limiter, R2 archive, and operational logs. Asana supplies the selected workspace data. Stripe processes subscription billing. Microsoft Graph delivers opted-in reports from Cazi Media only to the connected user's verified Asana email. Turnstile protects connection activation. We use no analytics, advertising, or AI service.
Security
OAuth uses PKCE and single-use state. Tokens are encrypted with AES-GCM, records are isolated by account and installation, database queries are parameterized, downloads are signed and short-lived, Stripe webhooks require signatures, and all Asana scopes are read-only.
Use the Cazi Media contact link for privacy requests.