Security

Trust foundations for a family app.

Tai Stars is designed with privacy-conscious family access in mind. This page explains the public trust posture without exposing internal implementation details.

Designed for household access

Tai Stars is built around parents, guardians, children, and households. Family information should only be available to the right signed-in household members.

Parent and guardian roles are part of the product experience, especially for approvals and family management.

Infrastructure & API Security

We implement strict rate limiting (Layer 7) on all API endpoints to protect against brute-force and denial-of-service attempts.

Administrative actions are tracked in a secure audit log to ensure transparency and accountability.

All data is encrypted at rest and in transit (HTTPS/TLS).

Sensitive family data

Child profile information, routines, rewards, progress, and optional photos or avatars are treated as sensitive family data.

We use PII (Personally Identifiable Information) masking in our analytics layer to ensure that internal performance tracking does not expose real names or child ages to unnecessary parts of the system.

Authentication and subscriptions

The mobile app uses secure email-based sign-in and platform sign-in options such as Apple or Google.

Subscriptions are handled by RevenueCat and the respective app-store billing systems (Apple/Google), ensuring your payment data never touches our servers.

Responsible disclosure

Please report suspected vulnerabilities to [email protected]. Include a clear description, affected area, reproduction steps where safe, and your contact details.

Do not access, alter, or disclose other families' data while investigating a concern.

No security audit, certification, or absolute security guarantee is claimed by this page.