← Snapshot Ledger

Snapshot Ledger privacy

Effective September 1, 2026

Data processed and stored

We store the connected Asana user and workspace identifiers; encrypted OAuth tokens; selected project identifiers and names; canonical task identifiers, names, completion state, assignee, dates, section, and custom-field values in compressed snapshots; generated report metadata; delivery preference; and Cazimedia billing identifiers.

Purpose

We use this data only to capture the selected projects, compare retained states, generate requested reports, deliver opted-in reports, enforce limits, authenticate the account, and manage the Snapshot Ledger subscription.

Retention and deletion

Snapshots expire after 90 days. Generated downloads expire after 15 minutes. Authenticated deletion removes the Asana connection, snapshots, reports, schedules, and account records after any active subscription is cancelled.

Processors

Cloudflare hosts the Worker, D1 database, Queue, Durable Object limiter, R2 archive, and operational logs. Asana supplies the selected workspace data. Stripe processes subscription billing. Microsoft Graph delivers opted-in reports from Cazi Media only to the connected user's verified Asana email. Turnstile protects connection activation. We use no analytics, advertising, or AI service.

Security

OAuth uses PKCE and single-use state. Tokens are encrypted with AES-GCM, records are isolated by account and installation, database queries are parameterized, downloads are signed and short-lived, Stripe webhooks require signatures, and all Asana scopes are read-only.

Use the Cazi Media contact link for privacy requests.