Safety and security
We describe what our products do and don’t do, collect only what they need, and run azet.io on established infrastructure. Here’s how, and how to tell us when something looks wrong.
Our principles
Say what it does, and what it doesn’t
Each product page states what you get and its limits. Seowoon’s readings are for entertainment and self-reflection, not predictions or advice. azet doesn’t give investment, tax or legal advice.
Photos are for the feature, not your identity
Tonemoa analyzes a photo of your face inside your browser to measure colors and to estimate gender and age for example outfits. The photo isn’t uploaded to our servers, isn’t used to identify who you are, and no face-recognition data is kept.
Collect only what we need
We ask for the information a product needs to work and explain it in our Privacy policy. The azet waitlist asks only for an email address.
No surprises when you pay
Prices are shown before checkout, where a price isn’t set we say so, and our Refund policy explains refunds and cancellations.
How we protect azet.io
- HTTPS only. Every request is redirected to https://azet.io, and browsers are told to use HTTPS for every visit (HSTS).
- Strict browser rules. A Content Security Policy allows scripts only from our own site and the analytics providers named in our Cookie policy. Other headers stop other sites from framing our pages and stop browsers from guessing file types.
- Data kept apart from the public site. What you submit, such as a waitlist sign-up, is stored in a separate backend that isn’t reachable from the internet directly. The public site can reach it only with an internal key.
- Payments through payment providers. Card payments are handled by the payment provider or app store named at checkout. AZET doesn’t receive or store full card numbers.
- Limited access. Access to personal information is limited to the few people who need it, as described in section 10 of our Privacy policy.
AZET is a young company. We don’t yet hold third-party security certifications such as SOC 2 or ISO 27001, and we won’t claim them until we do.
Report a security issue
If you think you’ve found a security vulnerability in azet.io or any AZET product, email hello@azet.io with the subject “Security report.” Include the steps to reproduce it and what you think the impact is. We aim to reply within two business days.
Please don’t access or change other people’s data, don’t disrupt our services, and give us reasonable time to fix the issue before you share it publicly.
Report misuse
To report abuse or content that breaks our rules, see our Usage policy. For privacy requests, see our Privacy policy or write to hello@azet.io.