Back to the site

Trust and data handling

Theruka holds programme plans - milestones, dates, risks, and the decisions taken about them. This page says where that data lives, who else touches it, what is sent to an AI provider and when, and how to get it back or have it destroyed. It is written to be read by a security reviewer, so it states limits as plainly as capabilities.

Last reviewed 10 August 2026.

What we store

Your workspace: portfolios, projects, milestones and their full date history, risks and their mitigations, decisions and the outcomes recorded against them, uploaded plan files, report and share links, and account and billing records.

Sign-in identity is an email address, from Google Sign-In or a magic link. We do not ask for or store a password. Sessions are a signed cookie holding an email address and an expiry - there is no server-side session store.

Sub-processors

Everyone outside Theruka who can hold or handle your data, and what for.

ProviderWhat it handlesWhere
Railway Runs the application. All request traffic passes through it. United States
Neon The Postgres database. Your workspace is stored here. United States
OpenAI The AI features only, and only the content described below. Never the whole workspace. United States
Google Sign-in. Google confirms an email address; we receive no other profile data. United States
Resend Transactional email: magic-link sign-in and the weekly digest. United States
Lemon Squeezy Payment and subscription billing. Card details go to them, never to us. United States

We do not sell data, and we do not share it with anyone not on this list.

AI, and what is sent

AI features run on OpenAI's API. Each feature sends only what that feature needs, and each one is triggered by a person clicking something - nothing is sent in the background.

Uploaded files are parsed by us, not by the AI provider. Billing records, email addresses and sign-in data are never sent to it.

Turning it off

Every account has a data mode. An account set to test sends nothing to the AI provider at all - every AI feature is disabled - unless someone with owner rights explicitly opts that account in. An account set to production has AI available on the plans that include it. The setting is on the account page and takes effect immediately.

OpenAI states that data submitted through its API is not used to train its models. We do not fine-tune, and we do not send your data to any other model provider.

Access and sharing

A workspace is reachable only by its members. Roles are owner, admin, editor and viewer, and they are enforced on the server for every request, not in the browser.

Reports and program reviews can be shared by link with people who have no account. Those links are frozen snapshots, not live windows: someone opening one next month sees what was sent, not today's plan. Every share link can be given an expiry and can be revoked.

Getting your data back

Plans export as CSV, and reports as branded PDF, from inside the product on the plans that include exports.

Not available yet: there is no customer-facing API for programmatic export. If you need a full machine-readable extract of an account, ask us and we will produce one. Outbound webhooks exist for notifications, but they push events - they are not a way to read your data back.

Deletion and retention

Deleting a workspace marks it immediately: it disappears from the product and nobody can reach it. The data itself is destroyed 30 days later by a scheduled purge. That gap exists so an accidental deletion can be undone, and it is the only path by which workspace data is permanently removed.

Ask us at any point in those 30 days and we will restore it, or destroy it immediately instead of waiting.

Security

What we do not have yet

Stated plainly, because a security review will find it anyway: no SOC 2 report, no ISO 27001, no SAML single sign-on, and no SCIM provisioning. Sign-in is Google or a magic link, and members are added and removed by hand. If any of those is a condition of purchase for you, tell us - it changes what we build next, and we would rather hear it than guess.

Contact

Security questions, data requests, deletion requests, or a DPA: sales@theruka.com. We answer security reviews directly - there is no portal to fill in.