Teezer

Policy · Security

Security Policy

Last updated: July 4, 2026 · Effective: July 4, 2026

This policy is a detailed reference for Section 8 (How We Protect Your Information) of our Privacy Policy. It describes the concrete measures that protect your account and data on Teezer, and how to reach us if you find a weakness.

1.Overview

Security is layered: we protect data in transit, store credentials so that even we cannot read your password, serve media through short-lived signed links, and give you first-party tools to lock down your own account. No system is perfectly secure, but each of these layers narrows what an attacker could do.

2.Encryption in Transit

All traffic between your device and Teezer - the website, the apps, and our API - is encrypted in transit using TLS (HTTPS). Direct messages are encrypted in transit as well; note that messages are not end-to-end encrypted, as described in Section 2 of our Privacy Policy. Voice and video calls are transmitted peer-to-peer and are never recorded or stored by us.

3.Passwords and Credentials

  • Passwords are stored only as strong, salted one-way hashes - we never store or have access to your plain-text password.
  • We never receive or store your full payment card number or bank credentials; those go directly to our payment processors.
  • Where full IP addresses are not required, we store a one-way hash instead of the raw address.

4.Media Protection

Uploaded videos and images are served from our storage through signed, expiring URLs: each link is cryptographically signed and valid only for a limited window, so files cannot be enumerated, guessed, or hot-linked from outside the Platform. Media infrastructure additionally sits behind an edge security layer that validates every request before it reaches storage.

5.Account Protection Tools

ToolWhat it doesWhere
Two-factor authenticationRequires a second factor at login, so a stolen password alone isn't enoughSettings → Security
New-login alertsNotifies you when your account is accessed from a new deviceSettings → Security
Session managementReview every active session and revoke any you don't recognizeSettings → Security
Revoke all other sessionsSign out every device except the one you're using, in one actionSettings → Security

6.Abuse and Bot Prevention

  • Login is protected by bot-management that confirms you're human without a puzzle CAPTCHA in most cases.
  • Platform-wide rate limiting throttles abusive request patterns before they can affect the service.
  • Device and behavioural signals feed automated fraud detection, as described in our Integrity & Authenticity Policy.

7.Internal Access Controls

Administrative access to user data is restricted to authorized personnel on a need-to-know basis and is logged. Staff access to sensitive data (such as message content during a report investigation) is scoped to the task and auditable.

8.Reporting a Vulnerability

If you believe you've found a security vulnerability, please report it responsibly to [email protected] with the subject line "Security Vulnerability" and enough detail to reproduce it. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and do not access, modify or delete data that isn't yours while testing. If you believe your own account has been compromised, change your password, revoke other sessions, and contact us immediately.