Privacy policy

Last updated 29 September 2026

Lasso is run by Weekend Devs. This policy covers the Lasso web app at lasso.tools (including its Slack and Gmail connections), the Lasso Chrome extension, and Lasso's command-line tool and MCP server. It explains what we collect, why, and what we do with it. Questions or requests: aedmundson@weekenddevs.com.

What we collect

  • Your account. Your email address and name, and which organizations and projects you belong to.
  • What you put in Lasso. Tickets, comments, screenshots and other files, board settings, and the integrations you connect.
  • What the extension sends when you file a ticket. Your comment; a screenshot of the visible page and a close-up of the element you picked; where that element is on the page; the page's address and title; your browser, operating system, window size, colour scheme, language and time zone; any text you had selected; and the page's recent console messages (up to 50, each shortened) and failed network requests (the address without its query string, the method and the status code, never the request or response body, cookies or headers).
  • Reviewers who use a reviewer link. An optional name, if you type one, and a reviewer ID we issue so your comments stay yours on later visits.
  • Agent tokens. If you connect a coding agent, we store only a one-way hash of its token.
  • Service logs. IP addresses and request details, used briefly for rate limiting, security and fixing problems.

How the Chrome extension behaves

  • It only runs on a site after you turn it on for that site, and you can turn it off from its side rail.
  • It watches the page's console and failed requests only on sites where it is on, and sends them to Lasso only as part of a ticket you submit. Nothing is sent while you browse.
  • On your device it stores which sites it is on for, the reviewer link you arrived with and your reviewer ID. That stays in your browser's extension storage.
  • It does not read your cookies, passwords or form contents, and it does not track the pages you visit.
  • All of its code ships inside the extension. It does not download or run code from anywhere else.

Slack and Gmail (Triage)

Triage is optional. It only reads anything after an admin of your organization connects Slack or a Gmail mailbox, and a project chooses which channels or mail to watch.

  • Slack. Lasso reads messages, their authors' names and links to attached files in the public channels a project picks and that Lasso's bot has been added to. It does not read private channels or direct messages. If you connect your own Slack account, Lasso uses it only to post the replies you write in Lasso, as you, in the thread you are replying to.
  • Gmail. Lasso reads the messages in the mailbox your organization connects (or only those matching the addresses or labels a project picks). Access is read-only: Lasso never sends, deletes, labels or otherwise changes your mail. Replies to email are written in Gmail itself.
  • What happens to it. Messages are grouped into threads in your project's Triage tab, where members of the project decide which become tickets. Lasso keeps the text of the threads it has read, and file names and links, not the files themselves.
  • Sorting. To sort threads, Lasso sends each thread's text, and the titles of your project's open tickets, to Jev, a scoring service run by TypeSafe, which returns how likely the thread is to be product work, its likely priority and type, and whether it matches an existing ticket.
  • Summaries and drafts, only if you add a key. If your organization adds its own Claude API key, Lasso also sends thread text to Anthropic, under your organization's own account, to write a summary, a ticket title and a draft reply. Without a key, nothing is sent to Anthropic.
  • Turning it off. An admin can disconnect Slack or Gmail at any time, and you can disconnect your own Slack account. Lasso stops reading immediately and deletes the stored access tokens. Access tokens are always stored encrypted.

Lasso's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide the Triage features you see, we do not use it for advertising or to train AI models, and people at Weekend Devs do not read it unless you ask us to (for support), it is needed for security or to comply with the law.

How we use it

Only to run Lasso: to show tickets to the people in your workspace, to deliver them to the tools and agents you connect, to keep your account secure, and to fix problems. We do not sell your data, use it for advertising, or build profiles of you. Apart from the Triage sorting and optional summaries described above, Lasso does not run AI models on your data; if you connect your own agent, it receives the tickets you give it access to.

The extension's use of data follows the Chrome Web Store User Data Policy, including its Limited Use requirements.

Who else handles it

  • Supabase stores the database, sign-in and uploaded files.
  • Vercel hosts the web app.
  • GitHub receives ticket data only if you connect a repository to a project.
  • Any webhook address you add receives the ticket events you choose.
  • Slack and Google hold the messages Lasso reads if you connect them, and Slack posts the replies you write in Lasso.
  • TypeSafe (Jev) receives triage thread text and open ticket titles to sort threads, if Triage is on.
  • Anthropic receives triage thread text only if your organization adds its own Claude API key.

We don't use third-party analytics or advertising services.

How long we keep it

We keep workspace data for as long as the workspace exists. To have your account or your workspace's data deleted, email aedmundson@weekenddevs.com and we will delete it within 30 days. Uninstalling the extension removes what it stored on your device.

Your choices

You can see and change your account details in Lasso, turn the extension off for any site, and ask us for a copy of your data or for it to be corrected or deleted. Lasso is not meant for children under 13.

Changes

If we change this policy we will update the date above, and for significant changes we will tell account holders by email.