Privacy policy
Privacy policy
Effective date: 2026-09-30
Service: Slipstream (Asana integration)
Operator: Arnon Labs / Gilad Arnon
Legal entity name / registered address: TBD
Product: https://slipstreamapp.dev
Webhooks and ops: https://slipstream.arnonlabs.dev
Company: https://arnonlabs.dev
This policy explains what Slipstream does with data when you connect it to Asana. It is written in plain English for a private app and for Asana App Directory listing readiness. It is not legal advice and does not claim certifications, jurisdictions, or guarantees we have not set up yet.
1. What Slipstream is
Slipstream is a scheduling / Gantt-style automation for Asana. After you authorize it, Slipstream:
- Connects to your Asana workspace via OAuth
- Registers and receives Asana webhooks for connected projects
- Reads task and project fields needed to keep dates and Effort in sync (for example start date, due date, Effort Estimation custom field, dependencies/blockers, and related task metadata)
- Writes updates back to Asana when automation rules apply (for example deriving start/due from Effort, seeding start after a blocker, optional overdue auto-extend)
- Shows connection and run information in a Status view / logs so you can see what the app did
Slipstream only acts on projects and data you connect. It is not a general Asana backup, CRM, analytics platform, or ad network.
2. Data we collect and process
We collect and process only what is needed to run the integration you enable.
2.1 Account and connection data
- Asana OAuth tokens (access / refresh as issued by Asana) and related connection identifiers
- Asana user / workspace / project identifiers needed to scope the connection
- Settings you choose in Slipstream (for example calendar / working-day preference, auto-extend options)
2.2 Asana project and task metadata (operational)
To automate Effort and dates, we may process:
- Task GIDs, names (as needed for Status / debugging), assignees if returned by Asana for the connected scope
start_on/due_on(and related date fields Asana provides for the automation)- Effort Estimation (or equivalent custom field) values and field GIDs
- Dependency / blocker relationships and their due dates when needed to seed or adjust schedule
- Project webhook registration details and delivery health
- Event payloads Asana sends to our webhook endpoint (change notifications)
We do not intentionally pull your full Asana history, unrelated projects, attachments, comment threads, or unrelated custom fields beyond what the automation and Status path need.
2.3 Status logs and operational records
- Run / Status logs describing webhook receipt, planner steps, successes, skips, and errors
- Timestamps, project/task identifiers, and short diagnostic messages needed to operate and support the service
- Basic technical logs from hosting (for example request timing, error stacks) used for reliability and security
2.4 Contact / support data
If you email us, we receive whatever you send (name, email address, message content, and any screenshots or Asana GIDs you include).
2.5 What we do not collect for ads or sale
- We do not sell your Asana data
- We do not use your Asana content for advertising
- We do not build ad profiles from your workspace
- We do not share your data with data brokers
3. How we use the data
We use the data above to:
- Authenticate to Asana on your behalf within the OAuth scopes you approve
- Receive and process webhooks and (where enabled) scheduled checks such as overdue polling
- Compute and write schedule-related field updates (Effort / dates / related automation)
- Show Status and help you troubleshoot
- Maintain security, prevent abuse, and keep the service running
- Respond to support requests you send us
We process data because you asked us to run Slipstream on your connected Asana projects (contract / service delivery). Where a specific privacy law requires a named legal basis, treat that as the primary basis; we will refine this section if we expand to a broader commercial launch.
4. How we share data
We share data only as needed to operate the service:
| Recipient | Why |
|---|---|
| Asana | Slipstream calls Asana’s API and receives webhooks. Asana’s own terms and privacy policy apply to your Asana account. |
| Hosting / infrastructure subprocessors | Cloud host(s) that run the API, database, and logs. Provider names: TBD. Infrastructure is operated by Arnon Labs. The product site is https://slipstreamapp.dev. Webhooks and ops are on https://slipstream.arnonlabs.dev. |
| You / your workspace admins | Via Status, your own Asana UI, and support replies. |
| Legal / safety | If required by law, valid legal process, or to protect users and the service from abuse or security threats. |
We do not sell personal data. We do not share Asana content with advertisers.
If we add named third-party subprocessors (email, error tracking, analytics, payments), we will update this policy and list them here.
5. Retention
- OAuth tokens and connection settings: kept while your Slipstream connection is active; deleted or invalidated when you disconnect / revoke access (and as soon as practical afterward)
- Operational / Status logs: kept for a limited period needed for debugging and reliability (target: TBD days/weeks; not an indefinite product analytics warehouse)
- Webhook and event processing data: retained only as long as needed to process events and diagnose failures
- Support emails: retained as needed to handle your request and basic records
When you disconnect Slipstream or revoke the Asana app, we stop new processing for that connection and remove or disable stored tokens. Residual logs may remain for a short retention window, then are deleted or anonymized in the ordinary course of operations.
Exact automated purge schedules are TBD.
6. Security
We use reasonable technical and organizational measures appropriate for a small private integration, including:
- OAuth instead of collecting Asana passwords
- HTTPS for the product site, API, and webhook endpoints
- Access controls on the hosting environment
- Secrets and tokens stored as credentials, not in public repos or client-side code
No method of transmission or storage is 100% secure. If you believe there is a security issue, contact us promptly at the email below.
7. Your choices and rights
You can:
- Disconnect Slipstream from Asana (revoke the app in Asana and/or remove the project connection in Slipstream)
- Limit which projects you connect
- Email us to ask what connection data we hold, to request deletion of connection data after disconnect, or to correct something we got wrong in Status/support records
Depending on where you live, you may have additional rights (access, deletion, restriction, objection, portability, complaint to a regulator). We will not invent a fake compliance program here. If you make a request, we will handle it in good faith for this private app. Contact: gilad@arnonlabs.dev. A separate support mailbox is not set up yet.
We do not knowingly market Slipstream to children. The app is intended for workplace Asana users.
8. International processing
Slipstream may be hosted and processed in regions where our infrastructure runs (hosting region: TBD). If you are in the EEA/UK or another region with cross-border rules, connecting the app means your operational data may be processed outside your country under the host’s arrangements. We will update this section when the production region and any transfer mechanism are fixed.
9. Asana Platform specifics
- Slipstream uses Asana OAuth and webhooks under Asana’s developer / platform terms
- Data obtained from Asana is used only to provide and improve Slipstream’s scheduling automation and Status for your connected projects
- We do not use Asana APIs to exfiltrate data for unrelated products
- Directory listing materials can point at this page: https://slipstreamapp.dev/privacy
10. Changes
We may update this policy as Slipstream evolves (named subprocessors, retention automation, commercial entity details). Material changes will get a new effective date on this page. Continued use after the new date means you accept the updated policy for that version of the service.
11. Contact
Privacy / support: gilad@arnonlabs.dev
Operator: Arnon Labs / Gilad Arnon
Legal entity / postal address: TBD
Product: https://slipstreamapp.dev
Webhooks and ops: https://slipstream.arnonlabs.dev
Company: https://arnonlabs.dev
If this policy and a future Terms of Service disagree on a narrow point, the newer dated document controls for that point once published.