Trust Center

Your spiritual journey is deeply personal. Tarosyn is built on the conviction that the people who share their readings, birth charts, and private thoughts with us deserve rigorous protection and honest answers about how that data is used. This Trust Center is the single place to find every security, privacy, compliance, and AI governance document we publish.

compliance posture GDPR-Ready

We publish a full Data Processing Agreement covering controller/processor roles, sub-processor list, security measures, breach notification, and Standard Contractual Clauses for cross-border data transfers.

Breach notification ≤ 72 h

Our Incident Response Policy commits to notifying affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware of a personal-data breach.

PCI-DSS (via Stripe)

Payment card data never touches Tarosyn servers. All billing is handled by Stripe, a PCI-DSS Level 1 certified processor. We store only a Stripe customer reference.

SOC 2 — planned

A SOC 2 Type II audit is on our roadmap as part of our enterprise readiness programme. We will link the report here once it is complete.

ISO 27001 — evaluating

We are evaluating ISO 27001 certification as our security programme matures. Controls in our Information Security Policy are aligned with ISO 27001 objectives.

COPPA / Age 13+

Tarosyn is rated 17+ on the App Store and Google Play. We enforce date-of-birth verification at sign-up and delete accounts where the user is confirmed to be under 13.

SECURITY

Security Overview

Encryption in transit and at rest, access controls, infrastructure security, and monitoring.

Information Security Policy

Governance, risk management, access control, and incident-response commitments for enterprise and partner review.

Incident Response Policy

How we detect, contain, and notify users of security incidents — including our 72-hour breach notification commitment.

Vulnerability Disclosure & Bug Bounty

Responsible disclosure programme — how to report a vulnerability and what to expect in return.

PRIVACY

Privacy Policy

What personal data we collect, how we use it, who we share it with, and your rights over it.

Data Processing Agreement (DPA)

Controller/processor roles, sub-processor list, Standard Contractual Clauses, and GDPR-compliant data transfer safeguards.

Cookie Policy

Which cookies and local storage we use, why we use them, and how to manage them.

Account Deletion Policy

What happens to your data, readings, and purchases when you delete your Tarosyn account.

AI GOVERNANCE

AI Transparency

The AI models Tarosyn uses, what data is sent to them, and the limitations of AI readings.

Responsible AI Principles

Our commitments to fairness, safety, transparency, and accountability in every AI-powered feature.

AI Safety Policy

Disallowed uses, harm-prevention measures, content safeguards, and responsible output limits.

AI Training Data Policy

Whether your content is used to train AI models, how providers handle data, and your opt-out options.

AI Usage Policy

AI limitations, hallucination risk, entertainment-only framing, and your responsibility to verify important decisions.

LEGAL & COMPLIANCE DOCS

Terms of Service

The agreement governing your use of Tarosyn — your rights, our rules, and how disputes are handled.

Acceptable Use Policy

Conduct that is and isn't permitted on Tarosyn — protects our community from abuse and misuse.

Subscription Terms

Billing cycles, renewal rules, cancellation policies, and free trial details for every tier.

APP STORE DISCLOSURES

App Privacy Disclosures

Apple App Store privacy nutrition labels and Google Play Data Safety declarations — what data we collect and how it is used.

Age Rating — 17+

Why Tarosyn is rated 17+ and how age is confirmed and enforced at sign-up.

Content Moderation Policy

What content is prohibited, how reports are reviewed within 24 hours, and how to appeal.

enterprise & partner enquiries

If you are evaluating Tarosyn for enterprise use or as a business partner and need additional documentation — such as a completed security questionnaire, a copy of a signed DPA, or details of our sub-processor list — request it below and our team will route it to the right people.

Company name Work email Document requested Select a document Completed security questionnaire Signed Data Processing Agreement (DPA) Sub-processor list Other / not sure Message (optional) Request documentation

Prefer email? You can also reach us directly:

[email protected] [email protected] View all contact options responsible disclosure

Security researchers who identify a vulnerability in any Tarosyn service are encouraged to disclose it responsibly via our Bug Bounty programme. Valid reports are reviewed by the engineering team and, where appropriate, rewarded with Luna credits. For urgent matters, email [email protected].

View the Bug Bounty programme

© 2026 Tarosyn LLC. All rights reserved.

Questions? [email protected]