Security
What we do with your church's data.
Plain answers for the people who have to sign off on a new system: what is stored, who can see it, and what happens when something goes wrong.
Access is scoped per church
Every table enforces row-level access control in the database itself, not only in the app. A signed-in user reaches the rows belonging to their own church and nothing else. Roles are stored separately from profiles, so a user cannot raise their own privileges by editing their profile.
Workers see their own duties. Department heads see their department. Administrators see their church, and only leadership sees a consolidated view across branches.
Transport and hosting
All traffic is served over HTTPS with strict transport security, a restrictive content security policy, and a locked-down permissions policy. Data is held in a managed Postgres database with automated backups.
Invitations, reminders and roster notices are sent from a dedicated sending domain with your church's verified reply-to address, so replies reach you rather than us. Every message is written to a delivery log with its status, visible to your administrators.
Deletion and recovery
Deleting a record moves it to a recovery area for 30 days, so a mistaken deletion is reversible from Settings. After that window it is removed.
Any user can delete their own account from the app. If you are the only administrator of a church, ownership must be transferred first so the church is never left unreachable.
Monitoring
Application errors and delivery failures are recorded and surfaced in the in-app health panel, and an independent external check probes the service on a schedule so an outage is detected even when the app itself is down.
What we do not claim
Oruchi holds no third-party security certification at this time, and we will not imply one. If your church requires a formal review, contact us and we will answer specific questions directly.