Legal

Privacy Policy

This is a general policy template and should be reviewed by qualified legal counsel before it is relied upon.

Last updated: July 6, 2026 (version 2026-07-06)

Introduction and Who We Are

This Privacy Policy explains how Ithura ("Ithura", "we", "us", or "our") collects, uses, stores, and protects personal information when you use our project management platform (the "Service"). The Service helps teams plan work, track issues, collaborate on documents, and manage projects. This policy applies to account holders, workspace members, and visitors who use the Service.

The Service is operated by Anorph Oy (Finnish Business ID 3602595-5), a limited company established in Finland, with its registered office at Kurkikuja 14, 53650 Lappeenranta, Finland. Anorph is the entity responsible for the account data we collect directly (see below). You can reach us at privacy@ithura.com.

Under EU and UK data protection law (GDPR), there are two roles: a "controller" decides why data is used, and a "processor" handles it on the controller's instructions. The way these roles apply depends on how you use Ithura:

  • For the content your team creates in a workspace (projects, issues, documents, and so on), the organisation that runs your Ithura instance is the controller, and Anorph is its processor.
  • For account data we collect directly, Anorph is the controller.

This is a legal characterization that should be confirmed with counsel and, for business customers, set out in a Data Processing Agreement (see "Data Processing Agreement" below). If you use a self-hosted instance operated by your own organisation, that organisation is the controller, so also check its own privacy notice.

EU/UK representative and Data Protection Officer

Anorph Oy is established in Finland, within the European Economic Area, so an Article 27 EU representative is not required. We have not appointed a UK representative. We have not appointed a Data Protection Officer, as one is not required for the processing we carry out. If this changes, we will update this policy.

If you have any questions about this policy or your personal data, contact us at privacy@ithura.com.

Information We Collect

We collect the following categories of information.

Account data

When you register, or when an administrator creates an account for you, we store your username, email address, and password (stored only as a bcrypt hash, never in plaintext or any reversible form). Depending on how your account is set up, we may also store your first name, last name, display name, avatar or profile picture, cover image, and time zone. We keep basic account status flags (for example, whether your account is active and whether your email is verified) and activity timestamps such as your last login and last active time.

If you sign in through a third-party identity provider (for example Google, GitHub, GitLab, Gitea, or Okta), we store the provider name and the identifier that provider assigns to your account so that we can recognise you on future logins. We do not retain the OAuth access or refresh tokens from these sign-in providers. We use those tokens only for a moment during login to read your basic profile, then we discard them.

Account data provisioned through SSO and SCIM

If your organisation enables single sign-on (SAML 2.0 or OIDC) or automated user provisioning (SCIM), some of your account and identity data does not come from you directly. Instead, your organisation's identity provider supplies it, and accounts may be created, updated, or deactivated automatically based on the attributes your employer pushes to us (such as name, email, and group membership). Accounts created this way are given a random placeholder password hash that cannot be used to sign in with a password. Where this data originates from your organisation rather than from you, your organisation is the controller and its own privacy notice governs how it decides to share that data with us.

Profile and preference data

We store per-user preferences such as your theme, language, onboarding progress, notification settings, start-of-week preference, and optional profile details you choose to add, including a short bio, a job role description, and social links. We store any profile picture or cover image you upload as a file, and our database keeps a link to it.

Workspace content

When you use the Service you create content, and we store it so the Service can function. This is the content you and your team create in the app, for example: workspaces and projects; issues and comments; cycles, sprints, and modules; labels and saved views; pages and wiki documents; whiteboards, boards, and stickies. It also includes files you attach or upload, such as issue attachments, page images, project logos, and cover images. For each file, our database records a storage identifier, the file size, the file type (MIME type), and what it is attached to.

Usage and log data

To operate the Service securely, we record technical information tied to your sessions and to certain administrative actions. For each session we keep a session token, an expiry time, and the IP address and browser/device details (user-agent) tied to it. Workspace audit logs record admin actions, such as membership, settings, integration, and billing changes. For each entry we store who acted, what they did, what was affected, the IP address, and the browser/device details. These records support security, troubleshooting, and accountability.

Cookies

The Service uses cookies that are necessary for it to function. See the Cookies section below for details.

Third-Party Integrations

Connecting an external integration is always optional and is initiated by a workspace administrator. You can disconnect an integration at any time. When an integration is disconnected, we mark its stored connection record as deleted (a "soft delete") and add an audit-log entry noting the removal.

Integration connection tokens are stored per workspace. For the integrations listed below, tokens are encrypted at rest using AES-256-GCM (see the Security section).

Google Drive

If you connect Google Drive, we ask for the most limited permission Google offers (`drive.file`). It lets Ithura see only the specific files you pick to attach through the picker, never your whole Drive. The Google access token and refresh token are both stored encrypted at rest.

We do not copy your Google Drive file contents into Ithura. When you attach a file, we store metadata references only, such as the external file identifier, URL, title, MIME type, icon and thumbnail URLs, an embed URL, and file size. Each attachment is just a live link and preview; the actual file stays in your Google Drive.

Dropbox

You attach Dropbox files through the Dropbox Chooser, which runs in your browser. Dropbox returns only the details of the file you pick, such as its name, a shared link, its size, and an icon, and we store those as a metadata reference. We do not use Dropbox account authorization, we do not store Dropbox access tokens, and we do not download or store file contents. As with Google Drive, each attachment is just a live link and preview, and the file itself stays in your Dropbox.

Other integrations

Additional integrations may be available and configured by a workspace administrator, including Notion, Slack, GitHub, GitLab, Bitbucket, Gitea, Sentry, and Atlassian Confluence, as well as an optional AI assistant. Each of these is optional and disconnectable in the same way.

For most of these integrations, connection secrets are stored encrypted at rest. One exception: the Slack bot token for each workspace is not wrapped in the extra layer of app-level encryption we apply to the Google Drive and Notion tokens. (We still verify every incoming Slack request using Slack's signatures.) The GitHub integration uses a GitHub App that generates short-lived access tokens as needed, so we never store long-lived tokens.

How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the Service and your account.
  • Authenticate you and keep your sessions secure.
  • Store and display the workspace content you and your team create.
  • Enable optional integrations you connect, and display linked files and previews.
  • Send you service emails that your own actions trigger, such as an invitation or a password reset (see below).
  • Provide notifications about activity relevant to you, subject to your notification preferences.
  • Maintain security, prevent abuse, troubleshoot problems, and keep audit and accountability records.
  • Comply with legal obligations.

Service (transactional) email

We send you service emails only when a specific action triggers them, such as:

  • Sign-in and security: magic-login codes, email verification codes, password reset and new-password messages, and password-changed and email-changed confirmations.
  • Account: workspace invitations, project-added notifications, welcome messages, and account deactivation notices.
  • Activity: issue and comment activity notifications, subject to your notification preferences.
  • Requests and exports: request confirmations and export-ready notices.

We do not send marketing or bulk email. If the operator has not set up an email provider, we send no email at all.

AI assistant

If a workspace administrator enables the optional AI assistant, the text you submit to that assistant, which may include relevant workspace content passed to the model along with your typed prompt, is sent to the configured third-party language model provider (OpenAI or Anthropic) to generate a response. If no administrator has configured this feature, the AI assistant is disabled and no data is sent to any language model provider.

We use these providers through their standard business or API interfaces, under terms that bind them to process the submitted content only to return a response to us and not to train their own models on it. Provider retention and handling are governed by that provider's terms, which we recommend reviewing (OpenAI and Anthropic publish their own data-usage and retention policies). Please do not submit unnecessary personal or sensitive information to the assistant.

Analytics and tracking

We do not ship third-party web analytics or advertising trackers in the product. Product telemetry is disabled (hardcoded off), not merely turned off by default. The frontend does not include any analytics, session-replay, or advertising libraries. An operator may optionally configure self-hosted infrastructure observability (for example OpenTelemetry) for their own instance, which is used for operational monitoring rather than third-party user tracking.

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract. We process account data, workspace content, and session data because it is necessary to provide the Service you or your organisation have requested.
  • Legitimate interests. We process usage and log data (such as session IP addresses, user-agents, and audit logs) to keep the Service secure, prevent abuse, troubleshoot, and maintain accountability. We balance these interests against your rights and freedoms.
  • Consent. We rely on consent where you choose to connect an optional integration or enable optional features. You can withdraw consent at any time by disconnecting the integration.
  • Legal obligation. We process information where necessary to comply with applicable law.

If your organisation runs the instance, it decides the legal basis for processing its members' workspace content.

Sharing and Sub-Processors

We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes. Where we use the providers below to process personal data on our behalf, they act as our service providers or sub-processors: they are contractually bound to process the data only on Ithura's instructions and only to deliver the relevant function, not for their own purposes.

The Service relies on a small set of standard infrastructure components:

  • a database that holds your main data (PostgreSQL);
  • file storage for uploads, attachments, and avatars (S3-compatible object storage);
  • an in-memory store for sessions, rate limiting, and caching (Valkey, a Redis-compatible store);
  • a helper service that powers live, collaborative editing (document conversion for real-time editing).

For the Anorph-run production service, these run on Anorph-managed servers behind a reverse proxy on our own domains.

We share information only with the providers necessary to run the Service, and only as needed:

  • Optional integration providers. If an administrator connects an integration, relevant data is exchanged with that provider (for example Google, Dropbox, Notion, Slack, GitHub, GitLab, Bitbucket, Gitea, Sentry, or Atlassian Confluence) as needed to make the integration work.
  • Identity providers. If your organisation enables SSO or SCIM, account and identity data is exchanged with your organisation's identity provider (for example Okta or another SAML 2.0 / OIDC provider).
  • Email provider. If configured, service email is delivered through an operator-configured SMTP provider.
  • Language model provider. If the optional AI assistant is enabled, the text you submit to it is sent to the configured provider (OpenAI or Anthropic) to produce a response.

We maintain a list of the sub-processors we use to run the Anorph-operated production service (hosting and infrastructure, object storage, in-memory store, email delivery, and language model provider), available on request at privacy@ithura.com. We will give advance notice of any new sub-processor and provide a reasonable opportunity to object before it begins processing your personal data.

We may also disclose information where required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or Ithura.

Data Processing Agreement

If you are a business customer acting as a controller (for example, an organisation whose members use an Anorph-operated instance), a Data Processing Agreement (DPA), incorporating standard contractual clauses where applicable, is available to govern our role as your processor. Contact privacy@ithura.com to put a DPA in place. A public privacy policy does not itself establish the controller/processor relationship; the DPA is the correct instrument for that.

Data Retention and Deletion

We retain personal data and workspace content for as long as your account or workspace remains active and as needed to provide the Service. Indicative retention by category:

  • Account and profile data: kept for the life of your account and deleted or unlinked when the account is deleted.
  • Workspace content: kept for the life of the workspace and removed or unlinked when the workspace or account is deleted.
  • Session and log data: session records expire at their set expiry time; related security logs are kept for a limited operational period.
  • Audit logs: retained for up to 24 months, after which they are deleted, except where a longer period is required by law or a legal hold.
  • Backups: any backups containing your data are retained on a short rolling cycle of up to 30 days and then overwritten.

Most items use "soft deletion": when you delete something, we mark it as deleted and hide it from the app right away. A soft-deleted item is excluded from the Service, but a copy may remain in the database. We do not run an automatic purge that guarantees eventual permanent erasure of every soft-deleted row; instead, when you delete a user or workspace, we automatically delete or disconnect the related records through database cascade rules, and backups age out on the cycle above. When an integration is disconnected, its connection record is soft-deleted.

We deliberately keep audit logs as an add-only record and do not soft-delete them, so security-relevant actions stay traceable, subject to the audit-log retention ceiling above.

You can request deletion of your personal data as described in the Your Rights section, subject to the audit-log and legal-hold exceptions noted there. Where your organisation operates the instance, deletion requests may be directed to and fulfilled by that organisation as controller.

Security

We take reasonable technical and organisational measures to protect your information.

  • Passwords are stored only as bcrypt hashes, never in plaintext or any reversible form. Accounts provisioned through single sign-on are given a random placeholder hash that cannot be used to sign in.
  • Sensitive stored secrets are encrypted with AES-256-GCM. This covers most integration OAuth tokens, the AI provider API key, the email provider password, and administrative instance secrets. (The Slack bot token is the one exception noted above.)
  • Sessions use HttpOnly session cookies, with the Secure attribute applied automatically when the Service is served over HTTPS, and SameSite protection. We use CSRF protection for state-changing requests.
  • In transit, the Service is built to run over HTTPS, with encryption handled at the reverse proxy.

To be clear about our limits: we do not encrypt every database field or stored file inside the application, and we do not offer end-to-end encryption. Apart from the specific encrypted secrets and hashed passwords listed above, the rest of the stored data is protected by the disk or volume encryption of the hosting environment.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

International Data Transfers

Ithura is a self-hostable platform, and the location where your data is stored depends on where your instance is hosted. For the Anorph-operated production service, data is stored on Anorph-managed infrastructure.

Some optional features involve providers that may operate outside your country. In particular, enabling the AI assistant, an email provider, or certain integrations may transfer personal data to providers based in the United States or elsewhere (for example OpenAI, Anthropic, or an SMTP or integration provider). When we move personal data between countries in a way that GDPR's transfer rules cover, we use the safeguards the law requires, such as an EU adequacy decision or standard contractual clauses (with the UK Addendum where the UK GDPR applies). We will make a copy of the relevant safeguard available on request at privacy@ithura.com. If your organisation self-hosts Ithura, that organisation controls where the data resides.

Automated Decision-Making and Profiling

We do not carry out automated decision-making that produces legal effects or similarly significant effects concerning you. The optional AI assistant generates responses only when a user invokes it; it is a tool that assists people and does not make automated decisions about you.

Data Breach Notification

If a personal data breach occurs, we will act promptly to investigate and contain it. Where required by applicable law, we will notify the relevant supervisory authority and any affected individuals within the timelines the law sets (for example, notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours under the GDPR when the breach is likely to result in a risk to your rights and freedoms). Where your organisation operates the instance as controller, we will support it in meeting its own notification obligations.

Your Rights

Depending on where you live, you may have some or all of the following rights regarding your personal data.

Under the GDPR and similar laws, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data (the right to erasure).
  • Portability, to receive your personal data in a structured, commonly used, machine-readable format.
  • Object to or restrict certain processing, including processing based on legitimate interests.
  • Withdraw consent at any time where we rely on consent, for example by disconnecting an integration.
  • Lodge a complaint with your local data protection authority.

Please note that the right to erasure does not extend to records we must keep for legal, security, or accountability reasons, such as audit logs within their retention period or data under a legal hold. We will explain if such an exception applies to your request.

Under the California Consumer Privacy Act as amended by the CPRA, and similar U.S. state laws, you may have the right to:

  • Know what categories of personal information we collect, the sources, and how we use them.
  • Access the specific pieces of personal information we hold about you.
  • Delete your personal information, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information. We do not sell or share (as CCPA/CPRA define "share" for cross-context behavioural advertising) your personal information, so there is nothing to opt out of.
  • Limit the use of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right.
  • Not be discriminated against for exercising your rights.

California privacy disclosures (CCPA/CPRA)

For California residents, the categories of personal information we collect map to the statutory categories as follows:

  • Identifiers (name, username, email address, account and provider identifiers, IP address).
  • Internet or network activity (session and audit-log information, user-agent/browser and device details).
  • Professional information (job role description and workspace/team membership).
  • User-generated content (the workspace content you and your team create, and files you upload).

Sources. We collect this information directly from you, automatically through your use of the Service, and, where SSO or SCIM is enabled, from your organisation's identity provider.

Business and commercial purposes. We use this information to provide and secure the Service, authenticate you, deliver service emails, enable optional integrations, maintain audit and accountability records, and comply with law, as described in "How We Use Information."

Disclosure to third parties. We disclose personal information only to service providers and sub-processors (hosting and infrastructure, object storage, in-memory store, email provider, language model provider, and integration/identity providers), bound by contract to process it only for the business purposes we specify.

Sensitive personal information. Passwords are stored only as bcrypt hashes and are not used to infer characteristics. We do not collect or use sensitive personal information for the purpose of inferring characteristics about you, and we do not sell or share it.

Retention. We retain each category of personal information for the periods described in "Data Retention and Deletion."

How to exercise your rights

To exercise any of these rights, contact us at privacy@ithura.com. We will verify your identity before acting on your request. For GDPR requests we aim to respond within one month (extendable by two further months for complex or numerous requests, in which case we will tell you). For CCPA/CPRA requests we will confirm receipt within 10 business days and respond within 45 calendar days (extendable by a further 45 days where reasonably necessary, with notice).

California residents may use an authorized agent to submit a request on their behalf; we may ask the agent for proof of authorization and may still verify your identity directly. If we deny your request, and where applicable law (for example in Virginia, Colorado, Connecticut, and certain other states) provides a right to appeal, you may appeal by writing to privacy@ithura.com with the subject line "Privacy request appeal"; we will respond to your appeal within the time the applicable law requires.

Where your data is held within an instance operated by your own organisation, we may forward your request to it or ask you to contact it directly, since it is the controller.

Cookies

The Service uses only cookies that are essential to its operation:

CookiePurposeDuration
Session cookieKeeps you signed in. HttpOnly, marked Secure over HTTPS, and uses SameSite protection.Expires at the session's expiry time (up to 30 days)
CSRF token cookieProtects against cross-site request forgery. The app's own scripts can read it so they can send it back to confirm a request is genuine. Marked Secure over HTTPS and uses SameSite protection.Session (removed when the session ends)

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. Because these cookies are essential to running the Service you asked for, the law does not require us to ask for consent. If you block essential cookies, the Service may not function correctly.

Children

The Service is not directed to children. It is intended for use by organisations and their team members, and it is not intended for anyone under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at privacy@ithura.com and we will take appropriate steps to delete it.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, or legal requirements. Each version carries a "Last updated" date and a version identifier at the top of the policy. When we make material changes that affect existing users, we will give notice before those changes take effect, through an in-product notice or by email to account holders, in addition to updating the date and version identifier. We encourage you to review this policy periodically.

Contact

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:

Email: privacy@ithura.com

Ithura is operated by Anorph Oy (Finnish Business ID 3602595-5), Kurkikuja 14, 53650 Lappeenranta, Finland.