Asana
asana.comAsana is a team productivity and work-management SaaS platform with substantial AI/agentic features. Its consumer-facing Terms and Privacy Statement are recently updated (Privacy Statement effective January 1, 2026) and address AI/ML processing, third-party LLM providers, and privacy rights in reasonable detail. Key concerns for professional/consumer-tier users: Asana trains its own machine learning models on metadata from domains where Asana AI is enabled, with models potentially powering features across other Asana domains; the free/individual tier grants Asana a broad license to Free User Content; liability is capped at $100; and data is shared with advertising partners and channel partners for the individual/website-visitor context. Managed (paid) users are governed by a separate Customer Agreement not supplied here, so many protections that would matter to enterprises cannot be verified. No SOC 2/ISO certification is asserted in the supplied text (only a Trust Center reference and DPF certification), which limits verifiable compliance assurance.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Free Users retain ownership of the content they submit, and Managed (paid) User content is treated as Customer Data owned and controlled by the customer organization. However, Free Users must grant Asana a broad operational license over their content, which slightly qualifies their ownership.
Output Data Ownership
The Terms do not explicitly assign ownership of AI-generated outputs. AI outputs would fall under the general 'User Content' framework (owned by Free Users or the Customer), but the documents never directly address who owns generated content, leaving some ambiguity, and require users to disclose that AI outputs are AI-generated.
Training Data Usage
When Asana AI is enabled in a domain, Asana uses metadata from that domain to train machine learning models that can power features in other Asana domains — a cross-tenant training use. Third-party LLM providers are contractually barred from training on customer data, but Asana's own model training on domain metadata is broad, and control is only at the admin/domain level, not the individual consumer level.
Data Retention & Deletion
The Privacy Statement provides deletion rights and a purpose-based retention principle but states no specific retention schedule or deletion SLA. Retention is defined only as 'the period necessary,' which is vague and offers no concrete timeline or audit-log retention commitments in the supplied text.
Third-Party Data Sharing
Asana discloses information to subprocessors, channel partners, and advertising partners, and shares website-visitor data (including email addresses in de-identified matched form) with advertising providers for targeted ads. It states it does not sell data or share for third parties' own direct marketing, and provides opt-out mechanisms, but the advertising-partner disclosure and cross-context behavioral advertising raise moderate risk for the individual tier.
Opt-Out Rights
The Privacy Statement provides multiple concrete opt-out mechanisms: unsubscribing from marketing, a cookies preference/settings center, honoring Global Privacy Control, opt-out of cross-context behavioral advertising, and domain-level AI preference controls for admins. These are explicit and actionable.
Compliance & Certifications
The supplied documents affirm certification under the EU-US Data Privacy Framework (and UK/Swiss extensions) with the US Department of Commerce, and reference a Trust Center and a HIPAA Business Associate Addendum in the document menu. However, no SOC 2, ISO 27001/27018, or other baseline security certifications are asserted with evidence in the supplied text, and GDPR/CCPA are addressed as legal obligations rather than attested frameworks.
Model Explainability & Auditability
The Terms require users to apply human oversight and evaluate AI outputs, and the Privacy Statement points to admin AI controls and a Trust Center. However, the supplied documents provide no substantive commitments to model transparency, explainability, or enterprise auditing of AI behavior in the consumer-facing text.
Security Practices & Breach History
Asana states it takes technical and organizational security measures and references a Trust Center and a Data Security Standards document, but the supplied privacy text provides no specifics on encryption, access controls, penetration testing, or incident response. No breach history is disclosed. The security detail is high-level and caveated.
Enterprise vs. Consumer Risk Delta
There is a material difference between tiers: Free Users grant Asana a broad content license and are the controller of their own data, while Managed (paid) Users' content is Customer Data governed by a separate Customer Agreement where the organization is the controller. The enterprise Customer Agreement is not supplied, so the exact protections cannot be verified, but the documents make clear paid users receive a distinct, contract-governed posture.
Human Review of User Inputs
Asana reserves the right to store and process AI chatbot chat transcripts for staff training and quality assurance, and admins can access user workspace content. It may also review content for Terms violations. These are disclosed rights of human/staff access to certain user-provided content.
Regulatory & Litigation Exposure
The documents disclose a clear, user-favorable process for responding to legal/law-enforcement requests, referencing Law Enforcement Guidelines and committing to notify users of requests except where legally prohibited or in emergencies. No active litigation is referenced. This is a reasonably transparent posture.
PII & SPI Data Inventory
Asana collects extensive PII (name, email, IP, device IDs, geolocation, usage metadata, billing/financial info, video/audio recordings and transcripts) and may collect biometric and sentiment data in user research sessions with consent. SPI collection is disclosed with consent-based controls and the Terms restrict submitting sensitive data into content without prior written consent, so disclosure is adequate but the breadth is significant.
Policy–Product Currency
The Privacy Statement was updated December 3, 2025 and is effective January 1, 2026 — well within 12 months of the analysis date and future-dated. It substantively addresses AI/ML processing, third-party LLM providers, and admin AI controls, which align with the AI-first, agentic product surface (AI Teammates, Work Graph, StackAI). The Terms of Service are dated January 1, 2024 (older) but also address AI use, so coverage of shipped AI capabilities is demonstrated.
Cross-Document Consistency
Two documents were supplied — the Terms of Service and the Privacy Statement — and no contradictions were found between them. They are complementary: the Terms address content licensing and ownership while the Privacy Statement addresses data processing, and both consistently distinguish Free Users from Managed/Customer-governed users and both address AI use.
You've read all 15 risk ratings for Asana. Create a free account to see the exact policy wording behind each rating.