Trust and data handling
Theruka holds programme plans - milestones, dates, risks, and the decisions taken about them. This page says where that data lives, who else touches it, what is sent to an AI provider and when, and how to get it back or have it destroyed. It is written to be read by a security reviewer, so it states limits as plainly as capabilities.
Last reviewed 10 August 2026.
What we store
Your workspace: portfolios, projects, milestones and their full date history, risks and their mitigations, decisions and the outcomes recorded against them, uploaded plan files, report and share links, and account and billing records.
Sign-in identity is an email address, from Google Sign-In or a magic link. We do not ask for or store a password. Sessions are a signed cookie holding an email address and an expiry - there is no server-side session store.
Sub-processors
Everyone outside Theruka who can hold or handle your data, and what for.
| Provider | What it handles | Where |
|---|---|---|
| Railway | Runs the application. All request traffic passes through it. | United States |
| Neon | The Postgres database. Your workspace is stored here. | United States |
| OpenAI | The AI features only, and only the content described below. Never the whole workspace. | United States |
| Sign-in. Google confirms an email address; we receive no other profile data. | United States | |
| Resend | Transactional email: magic-link sign-in and the weekly digest. | United States |
| Lemon Squeezy | Payment and subscription billing. Card details go to them, never to us. | United States |
We do not sell data, and we do not share it with anyone not on this list.
AI, and what is sent
AI features run on OpenAI's API. Each feature sends only what that feature needs, and each one is triggered by a person clicking something - nothing is sent in the background.
- Classifying a risk sends that risk's text.
- Drafting a mitigation sends the risk's text.
- A milestone pre-mortem sends that milestone's fields, its dependency chain, and the risks already linked to it.
- An executive summary sends a digest of the projects in scope: names, statuses, milestone counts and dates, and risk text.
- Cause attribution and timeline summaries send the milestone history and risk text for the period concerned.
Uploaded files are parsed by us, not by the AI provider. Billing records, email addresses and sign-in data are never sent to it.
Turning it off
Every account has a data mode. An account set to test sends nothing to the AI provider at all - every AI feature is disabled - unless someone with owner rights explicitly opts that account in. An account set to production has AI available on the plans that include it. The setting is on the account page and takes effect immediately.
OpenAI states that data submitted through its API is not used to train its models. We do not fine-tune, and we do not send your data to any other model provider.
Access and sharing
A workspace is reachable only by its members. Roles are owner, admin, editor and viewer, and they are enforced on the server for every request, not in the browser.
Reports and program reviews can be shared by link with people who have no account. Those links are frozen snapshots, not live windows: someone opening one next month sees what was sent, not today's plan. Every share link can be given an expiry and can be revoked.
Getting your data back
Plans export as CSV, and reports as branded PDF, from inside the product on the plans that include exports.
Not available yet: there is no customer-facing API for programmatic export. If you need a full machine-readable extract of an account, ask us and we will produce one. Outbound webhooks exist for notifications, but they push events - they are not a way to read your data back.
Deletion and retention
Deleting a workspace marks it immediately: it disappears from the product and nobody can reach it. The data itself is destroyed 30 days later by a scheduled purge. That gap exists so an accidental deletion can be undone, and it is the only path by which workspace data is permanently removed.
Ask us at any point in those 30 days and we will restore it, or destroy it immediately instead of waiting.
Security
- All traffic is served over HTTPS.
- No passwords are stored - sign-in is Google or a single-use magic link.
- Session cookies are signed, expire, and carry no data beyond an email address and that expiry.
- Any third-party credential we hold on your behalf is encrypted at rest with AES-256-GCM, and its plaintext is never sent to a browser.
- Payment webhooks are signature-verified before anything is granted.
What we do not have yet
Stated plainly, because a security review will find it anyway: no SOC 2 report, no ISO 27001, no SAML single sign-on, and no SCIM provisioning. Sign-in is Google or a magic link, and members are added and removed by hand. If any of those is a condition of purchase for you, tell us - it changes what we build next, and we would rather hear it than guess.
Contact
Security questions, data requests, deletion requests, or a DPA: sales@theruka.com. We answer security reviews directly - there is no portal to fill in.
Back to the site