TEAM SOLUTIONS
WORKFLOW SOLUTIONS
REVIEW TOOL
PROJECT MANAGEMENT
TOOLS & INTEGRATIONS
TEAM SOLUTIONS
WORKFLOW SOLUTIONS
<!–
–>
<!–
–>
REVIEW TOOL
PROJECT MANAGEMENT
TOOLS & INTEGRATIONS
Effective date: June 3 2026
Last updated: June 3 2026
AIndrew (“the Extension”, “we”) is a browser extension for Chromium-based browsers (Google Chrome, Microsoft Edge) that acts as an AI copilot for users of Approval Studio (“AS”). This policy explains what data we collect, how we use it, and your rights.
Questions about this policy? Contact [email protected]
The Extension processes the following categories of data:
| What | Where stored | How long |
|---|---|---|
| Your AS bearer token (JWT) | chrome.storage.local on your device |
Until you sign out or uninstall the Extension |
Your AS account email (decoded from the token's sub claim) |
chrome.storage.local on your device |
Until you sign out or uninstall the Extension |
The token is provided by AS when you complete the in-Extension sign-in flow. The Extension uses it to call AS APIs on your behalf.
To produce daily briefings and real-time suggestions, the Extension reads:
The Extension reads only data that your AS account already has permission to see. It does not bypass AS access controls.
When you enable real-time alerts:
These are stored on the AIndrew backend (reporter.approval.studio) in an encrypted key-value store, keyed by a random registration ID generated at subscription time.
A capped FIFO list of the actions you applied through the Extension (mutation name, parameters, success/failure, timestamp). Stored in chrome.storage.local on your device only — never transmitted off-device unless you explicitly share a debug log.
Your timezone, daily briefing time, alert toggles, text size, and similar in-app preferences. Stored in chrome.storage.local on your device.
The AIndrew backend keeps a short-lived ring-buffer log of recent webhook deliveries, push send attempts, and API errors to support debugging. Logs are bounded in size, redact bearer tokens, and rotate out within hours. They are not used for analytics or marketing.
*.approval.studio and our own backend| Purpose | Data used |
|---|---|
| Authenticate you to AS APIs | AS bearer token |
| Produce your daily AI briefing | Project / asset / task / timeline data, sent to Anthropic via our backend |
| Deliver real-time alerts | Push subscription endpoint + AS webhook events |
| Apply actions on your behalf | AS bearer token + your explicit click |
| Remember your preferences | Settings/preferences |
| Show your action history | Local action history |
| Debug issues | Operational logs (server-side, transient) |
The Extension communicates with the following third parties:
graphql.approval.studio, api.approval.studioreporter.approval.studio| Data | Retention |
|---|---|
Local data in chrome.storage.local | Until you sign out, click “Reset everything,” or uninstall the Extension |
| Push subscription on backend | Until you sign out, uninstall the Extension (auto-cleanup hook), or 30 days of inactivity |
| AS webhook registration | Mirrored to push subscription lifetime — removed when registration is removed |
| Operational logs | Bounded ring buffer; rotates out within hours |
| Anthropic-side data | Per Anthropic's standard retention; not retained for training |
Clears your AS token and email from local storage and unsubscribes you from push. Other preferences and local action history are preserved (so signing back in is fast).
A button in the Extension's settings that fully tears down all local state and unsubscribes from push delivery on the backend.
Removing the Extension triggers a backend cleanup webhook that removes your push subscription and AS webhook registration. If the cleanup fails (e.g. backend unreachable at uninstall time), the same record auto-cleans on the 30-day idle pass.
The Extension's settings let you disable any combination of: assetUploaded, assetApproved, assetRejected, fileMoved, projectStalled, noActivity24h. Disabled alerts are dropped server-side and on-device.
For data we hold on the AIndrew backend, email [email protected] to request access or deletion. For data held inside AS, follow AS's standard data-subject request process.
If your AS token is compromised (e.g. shared device lost, suspected exposure), revoke it from AS directly. Currently AS token revocation is performed by AS support; reach out to [email protected].
The Extension is a business tool for Approval Studio account holders. It is not directed at children under 13 and we do not knowingly collect data from children.
We will update this page when the policy changes and note the new “Last updated” date at the top. For material changes (new data categories, new third parties), we will surface an in-Extension notice at next popup open.
Questions about this policy, data deletion requests, or other privacy concerns: [email protected]