Last updated: 14 July 2026
This Privacy Policy explains how the EA Dashboard (“the Service,” “we,” “us”) collects, uses, stores, and protects information when an executive assistant (“you,” “the user”) connects the accounts of the executives they support.
The EA Dashboard is operated by Katharine Everett, an individual (sole operator), trading as KE Copywriting. For any privacy question or request, contact us at ke@katharineeverett.com.
Plain-English summary
- We help an executive assistant manage several executives’ Google Calendar, Google Drive, and Asana from one dashboard.
- To do that, each executive signs in once and grants access. We store a secure “refresh token” — a key that lets the dashboard act on their behalf — in an encrypted vault. We do not copy or warehouse the contents of their calendars, files, or tasks.
- We only request the narrowest access needed to do the job.
- We never sell data, never use it for advertising, and never let anyone but the assigned executive assistant see an executive’s information.
Who this Service is for
The EA Dashboard is a private tool used by an executive assistant to support a small number of executives (“managed accounts”). It is not a public consumer product. Each executive grants access to their own accounts so the assistant supporting them can view and manage their schedule, files, and tasks in one place.
Information we access
When an executive connects an account, we request permission for the following, and nothing more:
Google account data
- Google Calendar (calendar.events) — to read, create, reschedule, and cancel calendar events on the executive’s behalf.
- Google Drive (drive.file) — limited to files the dashboard itself creates and specific files or folders the executive explicitly designates through Google’s file picker. We cannot see or browse the rest of the executive’s Drive.
- Basic profile and email (openid, email) — to identify which account was connected.
Asana account data
- Tasks and projects (read and write), plus basic user and workspace information — to view and manage tasks alongside the executive’s calendar. We request only granular, least-privilege scopes and do not request permission to delete projects.
How we use this information
We use the access granted solely to provide the dashboard’s features to the executive assistant supporting that executive:
- Display upcoming calendar events, tasks, and designated Drive files.
- Create and edit calendar events, Asana tasks and projects, and Google Docs on the executive’s behalf when the assistant (or an automation acting for the assistant) requests it.
- Run authorized background automations (for example, turning meeting notes into Asana tasks, or generating a document and filing it into a designated Drive folder).
We do not use this information for advertising, profiling, resale, or any purpose unrelated to operating the dashboard.
How we store and protect information
- Tokens, not content. We store each connection’s encrypted refresh token in a secure secrets vault. We do not maintain our own copies of calendar events, files, or task contents — that data is read live from Google or Asana each time it’s shown and is not retained afterward.
- Encryption. Refresh tokens are encrypted at rest. All connections between your browser, our servers, and Google/Asana use encrypted (HTTPS/TLS) transport.
- Access control. Each executive assistant can only ever see and act on the executives they personally connected. This isolation is enforced at the database level, so one user’s data can never be reached by another.
- Least-privilege keys. Administrative credentials are held server-side only and are never exposed to the browser.
- Access logging. Actions taken through the connector are recorded in an internal audit log for security and troubleshooting.
How we share information
We do not sell, rent, or trade any data. We do not share it with third parties for their own purposes. Information is only ever transmitted between the executive’s Google and Asana accounts (the source of the data), our secure server infrastructure, and the authorized executive assistant using the dashboard. We may disclose information if required by law, or to protect the security and integrity of the Service.
Google API Limited Use disclosure
The EA Dashboard’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the dashboard’s user-facing features.
- We do not transfer or sell Google user data for advertising, marketing, or any other purpose.
- We do not allow humans to read Google user data unless (a) the connected executive has given consent for specific data, (b) it is necessary for security purposes or to comply with applicable law, or (c) the data has been aggregated and anonymized.
- We do not use Google user data to train generalized or third-party AI/ML models.
Data retention and deletion
- We retain an executive’s refresh token only for as long as their account remains connected to the dashboard.
- An executive (or the assistant, or we as operator) can disconnect an account at any time. On disconnection, the stored refresh token is deleted from the vault and access ends.
- To request deletion of any stored data, or to have an account fully removed, contact ke@katharineeverett.com and we will action it promptly.
- Executives can also revoke the dashboard’s access directly from their Google Account permissions and their Asana app settings at any time.
Children’s privacy
The EA Dashboard is a professional tool intended for business use by adults and is not directed to anyone under 18.
Changes to this policy
We may update this policy as the Service evolves. The “Last updated” date at the top reflects the most recent revision. Material changes will be communicated to active users.
Contact
Katharine Everett (trading as KE Copywriting)
ke@katharineeverett.com