TERRANES

Security and data residency

This page names the region, the sub-processors and the transfer mechanisms, because a buyer’s security reviewer will ask for all three and a page that argues instead of answering wastes their time.

Under this page

Where it lives

An EU region, by invariant

The production database is in an EU region and application functions are pinned to Frankfurt. Both are recorded as invariants: changing either is a decision, not a setting.

Who we are

A Swiss company under EU adequacy

Switzerland holds an EU adequacy decision, so a transfer from the EEA to us needs no further mechanism. We are the seller of record and hold the DPA directly with you.

Getting out

Exportable in every billing state

Including read-only. An organisation that stops paying loses write access, not access. Every screen loads, every export works, nothing is deleted.

Every sub-processor that touches customer data

Named here because a Data Processing Agreement has to name them, and because the first business customer of any size asks before signing. Changes to this list are announced to every organisation owner thirty days before they take effect, and the DPA gives you the right to object.

A row marked Planned is one we intend to add and have not yet. It is listed early on purpose: that is the thirty days’ notice running before the change rather than after it, and it means nothing appears on this page for the first time on the day it starts processing anything. A planned row receives no data until it is marked Active.

Sub-processor Status What it processes Where Transfer mechanism
Supabase Active All application data: accounts, projects, tasks, comments, uploaded files, search embeddings EU region EU region — no transfer
Vercel Active Request data in transit. No durable storage of customer content Functions pinned to Frankfurt Standard Contractual Clauses for the US parent
Stripe Active Billing contact details, VAT numbers, payment methods, invoices. No card data ever reaches our servers EU / US, under its own DPA Stripe DPA and SCCs
Resend Active Email addresses and rendered message content only. Sends from mail.terranes.app, a subdomain kept separate from the mailbox we reply from EU — Ireland (eu-west-1) DPA and SCCs. The region pins where mail is processed; the provider is a US company, so the clauses still apply
Anthropic Active One report’s structured figures at the moment a person asks for AI wording — counts, dates, milestone names, the titles of overdue and blocked tasks. Never comment bodies, file contents, stakeholder notes or budget lines US Commercial terms and SCCs. Inputs are not used to train models
Sentry Planned Error reports: the failing request’s route, stack trace and browser. Personal data is switched off and user context is scrubbed, so a report says which route broke and not who was using it EU region EU region — no transfer

Anthropic is on this list and it surprises people. It is disclosed plainly here rather than left to be discovered — and it is reached only when somebody asks for a report to be narrated. How AI is used.


This website itself

The table above is about data we process for a customer, where the customer decides and we carry it out. This site is the other relationship: you are reading a public page, nobody has signed anything, and the decisions are ours. Different relationship, different rules, so it is answered separately rather than folded into the list above.

Page views

Counted, not tracked

Vercel Web Analytics records that a page was viewed, from which country, on what kind of device, and which page sent you. No cookie is set and no identifier is stored on your device, which is why there is no consent banner here — there is nothing to consent to. Visits are not joined across days into a profile of one person.

Fonts and assets

Nothing is fetched elsewhere

Both typefaces are served from this domain. No content delivery network, no font service, no tag manager, no embedded video, no advertising pixel. Loading this page contacts terranes.app and nothing else, which you are welcome to check in your browser’s network panel.

The form

One mailbox, no list

What you write on the early-access form is carried by Resend to one mailbox on Google Workspace, and used to reply to you. It is not added to a mailing list, not enriched from anywhere, and not passed on. Ask at privacy@terranes.app and it is deleted the same day.

If any of that changes — an analytics product that does set a cookie, an embedded video, a chat widget — this section changes in the same commit. A privacy policy covering all of it is published before launch; until then this section is the whole of it, which is the honest position rather than a link to a page that does not exist.


What leaves the EU is minimised at source, not by promise.

Stripe and Resend receive contact details and rendered content only. The narration provider receives one report’s structured figures and task titles, and only when a person has asked for that report to be narrated.

A test asserts the shape of that payload rather than trusting the sentence: it fails the build if comment bodies, file text, stakeholder notes or budget lines can reach it.

No sub-processor receives a complete copy of your project data, and no sub-processor other than the file store ever receives an uploaded document at all.

The residual risk is US government access to billing contact details and email addresses. The mitigation is that neither of those carries project content. We state it rather than paper over it.

Access, deletion and recovery

Who inside a customer can see a file?
Access is enforced in the database itself with row-level security, files sit in a private bucket and are served by signed URL — not by an application check that can be forgotten on one route. A project admin can additionally mark a single file restricted and name who may see it; a restricted file is hidden rather than shown as a placeholder row, because a placeholder announces that a document exists, which is often the sensitive fact itself.
What happens when we ask for deletion?
Account deletion and organisation deletion each state plainly what is destroyed, what is anonymised and what is retained, and each has a thirty-day cancellable window with a persistent banner carrying a one-click cancel. When an organisation erasure is requested, every owner receives the confirmation — not only the person who asked.
What is the recovery point?
Until the first paying customer, the recovery point is the most recent daily backup — up to twenty-four hours of loss rather than seconds. Point-in-time recovery is enabled from the first paying customer. We state the current position rather than the intended one. Backups age out on a documented thirty-day rotation, and an executed erasure is recoverable by the operator alone, from those backups, within that window and not beyond.
Can we self-host?
No, and that is an accepted gap rather than an oversight. If a specific requirement makes customer-controlled file storage concrete, the storage adapter is the next architectural step — we will not build it speculatively and we will not pretend it exists.

Your reviewer can have the paperwork.

The DPA, the sub-processor list and the transfer-impact note are the actual artefacts. Ask and they are sent — before a trial, not after.