Privacy Policy
Asan HQ · Asan Digital LLC · Last updated 21 August 2026
What this is
Asan HQ is an internal operations dashboard for Asan Digital LLC. It is not a consumer product and it is not open to the public. Access is restricted to an explicit allow list of accounts.
What we collect
When you sign in with Google, we receive from Google only:
- Your email address — used to decide whether you are on the allow list, and shown in the header so you know which account you are using.
- Your name and profile picture URL — used for display only.
- Your Google account identifier — used to keep you signed in.
These come from the openid, email and profile scopes. We request no other scopes. Asan HQ cannot read your Gmail, your Drive, your Calendar or your Contacts, because it never asks for permission to.
What we do not collect
- No passwords. Authentication is handled entirely by Google.
- No analytics, no advertising identifiers, no third-party trackers.
- No location data.
- No contents of your Google account beyond the three fields listed above.
How it is stored
Your email, name and picture URL are held in a signed, encrypted session cookie in your own browser. Asan HQ keeps no user database and writes no user records to disk. The session expires after seven days, and signing out discards it immediately.
Business data shown in the app
Asan HQ displays Asan Digital’s own operational data — infrastructure inventory, project status and revenue figures — read from systems the company already owns. This is company data, not personal data about you, and it is fetched on the server and rendered to authorised users only.
Sharing
We do not sell, rent, trade or share your information with anyone. There are no third-party recipients. Data obtained from Google APIs is not used to develop, improve or train generalised artificial intelligence or machine learning models.
Retention and removal
Because we store nothing server-side, there is nothing to delete on request beyond removing your address from the allow list, which ends your access at the next sign-in attempt. You can revoke Asan HQ’s access to your Google account at any time at myaccount.google.com/permissions.
Security
All traffic is served over HTTPS. Sign-in is restricted to an explicit allow list enforced on the server before any session is issued. Credentials for connected systems are held server-side and are never sent to the browser.
Contact
Asan Digital LLC — stef@asan.digital