Security note

Last updated: 8 August 2026

This page states what is factually true today. We hold no security certifications and make no claim to any.

What we store

Where it is stored

In a managed Postgres database hosted on Amazon Web Services in the ap-south-1 (Mumbai, India) region. We intend to move to an Australian region, and we will tell existing users before we do. Until then we do not describe Tskly as Australian-hosted.

Who processes it

Anthropic PBC processes document text on our behalf to extract and reconcile actions. Anthropic does not train its models on inputs submitted through its API. Our hosting provider stores the data at rest. Our email provider handles sign-in and service emails. No one else receives your content.

Encryption

All traffic to and from Tskly uses TLS. Data at rest is encrypted by our hosting provider using its standard disk-level encryption.

Tenant isolation

Every row of your data carries your user ID and is protected by row-level security policies enforced by the database itself, not by filtering in the application. A query that is not yours returns nothing.

Retention and deletion

Source documents are deleted automatically 90 days after they are submitted, by a scheduled job in the database. Your actions stay until you delete them. Deleting your account and data from the account menu removes your actions, sources and workstreams immediately.

Export

You can export your whole ledger to CSV at any time from inside the app, with no request to us and no waiting period.

Nothing is sent for you

Tskly drafts follow-ups. It never sends them. No bot joins your meetings, and no message leaves on your behalf.

Responsible disclosure

If you find a security issue, email [PRIVACY CONTACT EMAIL] with enough detail to reproduce it. We will acknowledge within two business days and will not pursue anyone who reports in good faith and does not access other people's data.