Security & Trust

Read-only by design. Ephemeral by default.

Last updated: August 23, 2026 · Applies to anku.app and all subprocessors.
Questions: hello@anku.app

Read-only access, scoped tight

Anku requests read-only access to Events, Persons, and Insights in your PostHog project. It never asks for write permissions and never installs tracking scripts in your app.

Your key, encrypted

If you opt into scheduled scans, your Personal API Key is encrypted at rest with AES-256-GCM. If you don't opt in, the key is held only for the duration of your session and never written to disk.

Ephemeral processing

Event and session queries are processed in memory during a diagnosis run. Raw telemetry is not persisted after the run completes.

PII scrubbing before synthesis

Automated scrubbing strips passwords, tokens, full names, and sensitive parameters from event payloads before anything reaches our synthesis models.

What we store

Only the deliverables Anku produces for you: computed metrics, classifications, prescribed changes, and outreach drafts keyed to hashed, non-reversible identifiers. Zero end-user PII is persisted.

Your controls

Disconnect in Dashboard → Settings and your encrypted key, briefs, outreach drafts, email logs, and deploy markers are deleted immediately. For full account deletion or an export of the deliverables we hold about you, email hello@anku.app from your registered address.

Security & Trust | Anku