Tarosyn Legal
Trust Center
Last updated May 31, 2026
Your spiritual journey is deeply personal. Tarosyn is built on the conviction that the people who share their readings, birth charts, and private thoughts with us deserve rigorous protection and honest answers about how that data is used. This Trust Center is the single place to find every security, privacy, compliance, and AI governance document we publish.
compliance posture GDPR-Ready
We publish a full Data Processing Agreement covering controller/processor roles, sub-processor list, security measures, breach notification, and Standard Contractual Clauses for cross-border data transfers.
Breach notification ≤ 72 h
Our Incident Response Policy commits to notifying affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware of a personal-data breach.
PCI-DSS (via Stripe)
Payment card data never touches Tarosyn servers. All billing is handled by Stripe, a PCI-DSS Level 1 certified processor. We store only a Stripe customer reference.
SOC 2 — planned
A SOC 2 Type II audit is on our roadmap as part of our enterprise readiness programme. We will link the report here once it is complete.
ISO 27001 — evaluating
We are evaluating ISO 27001 certification as our security programme matures. Controls in our Information Security Policy are aligned with ISO 27001 objectives.
COPPA / Age 13+
Tarosyn is rated 17+ on the App Store and Google Play. We enforce date-of-birth verification at sign-up and delete accounts where the user is confirmed to be under 13.
SECURITY
Security Overview
Encryption in transit and at rest, access controls, infrastructure security, and monitoring.
Information Security Policy
Governance, risk management, access control, and incident-response commitments for enterprise and partner review.
Incident Response Policy
How we detect, contain, and notify users of security incidents — including our 72-hour breach notification commitment.
Vulnerability Disclosure & Bug Bounty
Responsible disclosure programme — how to report a vulnerability and what to expect in return.
PRIVACY
Privacy Policy
What personal data we collect, how we use it, who we share it with, and your rights over it.
Data Processing Agreement (DPA)
Controller/processor roles, sub-processor list, Standard Contractual Clauses, and GDPR-compliant data transfer safeguards.
Cookie Policy
Which cookies and local storage we use, why we use them, and how to manage them.
Account Deletion Policy
What happens to your data, readings, and purchases when you delete your Tarosyn account.
AI GOVERNANCE
AI Transparency
The AI models Tarosyn uses, what data is sent to them, and the limitations of AI readings.
Responsible AI Principles
Our commitments to fairness, safety, transparency, and accountability in every AI-powered feature.
AI Safety Policy
Disallowed uses, harm-prevention measures, content safeguards, and responsible output limits.
AI Training Data Policy
Whether your content is used to train AI models, how providers handle data, and your opt-out options.
AI Usage Policy
AI limitations, hallucination risk, entertainment-only framing, and your responsibility to verify important decisions.
LEGAL & COMPLIANCE DOCS
Terms of Service
The agreement governing your use of Tarosyn — your rights, our rules, and how disputes are handled.
Acceptable Use Policy
Conduct that is and isn't permitted on Tarosyn — protects our community from abuse and misuse.
Subscription Terms
Billing cycles, renewal rules, cancellation policies, and free trial details for every tier.
APP STORE DISCLOSURES
App Privacy Disclosures
Apple App Store privacy nutrition labels and Google Play Data Safety declarations — what data we collect and how it is used.
Age Rating — 17+
Why Tarosyn is rated 17+ and how age is confirmed and enforced at sign-up.
Content Moderation Policy
What content is prohibited, how reports are reviewed within 24 hours, and how to appeal.
enterprise & partner enquiries
If you are evaluating Tarosyn for enterprise use or as a business partner and need additional documentation — such as a completed security questionnaire, a copy of a signed DPA, or details of our sub-processor list — request it below and our team will route it to the right people.
Company name Work email Document requested Select a document Completed security questionnaire Signed Data Processing Agreement (DPA) Sub-processor list Other / not sure Message (optional) Request documentation
Prefer email? You can also reach us directly:
[email protected] [email protected] View all contact options responsible disclosure
Security researchers who identify a vulnerability in any Tarosyn service are encouraged to disclose it responsibly via our Bug Bounty programme. Valid reports are reviewed by the engineering team and, where appropriate, rewarded with Luna credits. For urgent matters, email [email protected].
View the Bug Bounty programme
© 2026 Tarosyn LLC. All rights reserved.
Questions? [email protected]
