Asana Exporter, published by Cody Labs. Effective 14 August 2026.
Asana Exporter (the "add-on") moves your Asana project and portfolio data into your own Google Sheets. This policy explains what the add-on accesses and how that data is handled. The short version: your data flows directly between your Asana account and your Google Sheet — Cody Labs operates no servers and never receives, stores, or transmits your project data or your Asana credentials.
spreadsheets.currentonly scope). The add-on cannot see your other files in Google Drive.All processing happens inside Google's Apps Script runtime, in your Google account. Project data is fetched from your Asana account and written into your spreadsheet. It is not sent to Cody Labs or any third party. We have no database and no server that could receive it.
Your Asana personal access token is stored using Google's PropertiesService (user properties), scoped to your Google account. It is never written into the spreadsheet and is not visible to other people you share the sheet with. It remains until you disconnect or uninstall the add-on, at which point it is removed.
If you enter a license key to unlock paid features, the add-on sends only that license key and the Cody Labs organization identifier to our payment processor, Polar, to confirm your subscription is active. No project data or Asana credentials are involved. See Polar's privacy policy. A disabled legacy Gumroad verifier remains in the release only as a rollback path and is not called during normal use.
The add-on keeps aggregate counts of seven one-time milestones in Google Apps Script Properties: install, first connection, first successful run, free-limit reached, checkout opened, portfolio-template opened, and license activation. The counters contain no account identifier, email, personal access token, project data, spreadsheet content, or license key. Per-user markers in your Google account prevent duplicate counting and ensure a Marketplace review is requested only after the first successful export.
The only Google user data the add-on accesses is the content of the single Google Sheets spreadsheet you open it in, through the spreadsheets.currentonly scope. It uses that data for one purpose only: to write the Asana tasks and fields you export from a project or portfolio into that same spreadsheet, to read the saved export settings you enter so it can refresh those exports on your schedule, and to record a last-refreshed time and row count. The add-on:
spreadsheets.currentonly scope makes this technically impossible);The add-on's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We protect your data — including any sensitive data — with the following mechanisms:
PropertiesService user-property store — encrypted at rest by Google and scoped to your own Google account. It is never written into the spreadsheet and is never exposed to other people you share the sheet with.spreadsheets.currentonly, script.container.ui, script.external_request, and script.scriptapp (for the scheduled-refresh triggers you create) scopes — so it can only ever touch the active spreadsheet and the endpoints described above, never your wider Google Drive or account.Because we store nothing on our own systems, there is nothing for us to retain or delete. Credentials and settings live in your Google account's add-on storage and are removed when you disconnect or uninstall. Project data lives in your spreadsheet, under your control.
We may update this policy; material changes will be reflected by the effective date above.
Questions about this policy: [email protected].
Asana is a trademark of Asana, Inc. Google Sheets is a trademark of Google LLC. This add-on is independent and not affiliated with or endorsed by either.