Privacy Policy
This explains what Asire collects when you use the product, why, who we share it with, and the choices you have. It applies to the web app, the iOS and Android apps, and the desktop app alike.
1. Who we are
Asire is a workspace, project, and task collaboration product — built by Robinson March, operating from Nigeria ("Asire", "we", "us", "our"). This policy covers every surface we ship: the web app, the iOS and Android apps, and the desktop app, all of which talk to the same backend.
Asire is built for internal teams: an organization creates a workspace, invites its people into it, and everyone in that workspace works on shared projects, tasks, and conversations together. A lot of what we collect is therefore shared workspace content you and your teammates create together, not just data about you individually — see "Content you and your team create" below for what that means for deletion.
2. Information we collect
Account and profile information
- Identity and contact details: your name and email address, collected when you sign up or when a workspace owner invites you by email.
- Authentication data: sign-in is handled by Firebase Authentication. If you sign in with a password, Firebase stores it in hashed form — we never see or store your raw password. If you sign in with Google or Sign in with Apple, we receive your name, email address, and a stable account identifier from that provider, not your password.
- Profile photo, if you choose to upload one (JPEG/PNG/WebP, 5MB max).
- Profile-completion state (whether you've set a name and avatar), used only to show you a setup prompt.
Content you and your team create
- Workspaces, projects, and tasks: names, descriptions, due dates, statuses, priorities, tags, and who's assigned.
- Subtasks and comments, including timestamps and who wrote them.
- Attachments: files you upload to a task, stored in Firebase Storage and served back to authorized workspace members via short-lived signed links.
- Chat messages, in 1:1 and group conversations scoped to a workspace, including text, images, and voice notes (25MB max per voice note).
This category of data belongs to the workspace, not to you alone — it's the same model as Slack, Asana, or any team tool. A workspace Owner or Admin can see everything in workspaces they administer, including content other members created. Deleting your personal account does not remove content you contributed to a shared workspace; see the Account & Data Deletion page for the specifics.
Calls
- Audio and video calls between teammates are routed through LiveKit, our real-time media infrastructure provider, using WebRTC. Call media (audio/video) is not recorded or stored by Asire — it's relayed live and discarded.
- We do process call signaling and metadata needed to connect a call: who called whom, in which workspace, when the call started and ended, and short-lived connection credentials.
- Camera and microphone access is requested only when you place or answer a call, or record a voice note, and is used solely for that purpose in the moment — we don't access the camera or microphone in the background.
Device, usage, and diagnostic data
- Push notification tokens (Firebase Cloud Messaging device tokens on mobile, or web push subscriptions in-browser), so we can deliver notifications for things like task assignments and new messages.
- Device and app information: device model, OS version, app version, and locale, primarily for diagnosing bugs.
- Log and network data: IP address, request timestamps, and error/crash logs, generated as a normal part of running the service and kept for a limited time for security and debugging.
3. How we use this information
- To provide the core product: authenticate you, show you the workspaces and projects you belong to, sync tasks and chat in real time, and route calls.
- To send notifications you'd expect: someone assigned you a task, commented, mentioned you, invited you to a workspace, or a call is coming in.
- To keep the service secure and working: detect abuse, debug crashes, and enforce workspace role permissions (Owner/Admin/Member/Viewer) so people only see what they're meant to.
- To respond to you when you contact support, and to act on feedback or bug reports you send us.
- To meet legal obligations, for example retaining records where the law requires it.
We do not use your data to serve you ads, and we do not sell personal information to third parties, ever.
4. Who we share it with
We share data only with the service providers that make Asire work, and only to the extent each one needs to do its job. We don't sell data, and we don't share it with anyone for their own marketing purposes.
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Messaging) — account sign-in, the application database, file/attachment storage, and push delivery.
- Google Cloud Run — hosts the Asire backend API (in the
europe-west1region). - LiveKit — routes live audio/video call media between call participants.
- ZeptoMail (Zoho) — sends transactional email on our behalf, such as workspace invitations and notification digests.
- Google / Apple, only when you choose to sign in with Google or with Sign in with Apple — they authenticate you and pass us the profile fields described above.
- Other members of your workspace, per the roles and visibility described in "Content you and your team create" above — this is inherent to a collaboration product, not third-party sharing in the usual sense.
- Law enforcement or regulators, only where we're legally compelled to disclose information, and only to the extent required.
- A successor entity, if Asire is ever involved in a merger, acquisition, or asset sale — we'd tell you before your data is transferred and becomes subject to a different privacy policy.
5. How long we keep it
- Account and profile data: for as long as your account exists, plus a limited grace period after deletion to reverse accidental requests and complete removal.
- Workspace content (projects, tasks, comments, chat, attachments): for as long as the workspace exists, or until a workspace Owner/Admin removes it, since this content is owned collectively by the workspace, not by any one member.
- Call media: never stored — it's relayed live and not retained after the call ends. Call signaling metadata (who/when/how long) is kept briefly for reliability and abuse investigation.
- Logs and diagnostic data: kept for a limited rolling window, then deleted, unless we need to retain specific records longer to investigate abuse or security incidents.
6. Security
- All traffic between the apps and our backend is encrypted in transit (HTTPS/TLS).
- Passwords are never stored by us directly — Firebase Authentication stores them hashed.
- Access to workspace content is enforced by role (Owner/Admin/Member/Viewer): Members and Viewers only see projects they've been explicitly added to.
- File attachments are served through short-lived, signed URLs rather than permanent public links.
No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but we design the system, and choose vendors, to minimize risk at every layer we control.
7. International data transfers
We're based in Nigeria, but our infrastructure providers (Google Cloud, Firebase, LiveKit, Zoho) operate data centers in other countries — our backend currently runs in the European Union (europe-west1). Using Asire means your data may be processed outside Nigeria. Where that happens, we rely on our providers' own safeguards (such as encryption in transit and at rest, and their standard data-processing terms) to protect it in line with this policy.
8. Your rights and choices
Under the Nigeria Data Protection Act 2023 (NDPA), and under comparable laws if you're located elsewhere (such as the EU/UK GDPR or a US state privacy law), you generally have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data — most of this you can edit directly in your profile.
- Delete your account and personal data — see the dedicated Account & Data Deletion page for exactly how and what's retained.
- Export your data in a portable format.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
To exercise any of these, email us at [email protected]. We'll verify it's really you (using your account's registered email) and respond within a reasonable time — normally within 30 days.
9. Children's privacy
Asire is a workplace collaboration tool, not directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll remove it.
10. Changes to this policy
If we make a material change to how we handle your data, we'll update the "last updated" date below and, where the change is significant, notify you in the app or by email before it takes effect.
11. Contact us
Questions about this policy or how we handle your data: [email protected].