Beta

Privacy Policy

How Titan Account handles your data

Version 2026-09-12 · Last updated 12 September 2026

This policy explains what Titan Software z.s. collects and processes when you use Titan Account, the identity service at auth.titansoftware.eu.

1. Controller and contact

The controller is Titan Software z.s., zapsaný spolek (registered association), Czech Republic. Registered seat: Ametystová 702/46, 153 00 Praha, Česká republika. IČO: 29738725. For privacy questions and to exercise your rights, contact [email protected]. We have not appointed a Data Protection Officer [OWNER INPUT REQUIRED — confirm].

2. What we process, and why

DataPurposeLegal basis
Name, email address, username, profile image, locale, timezoneCreating and running your account; identifying you to applications you authorizePerformance of a contract (Art. 6(1)(b))
Password hash (Argon2id), passkey credentials, TOTP secret and backup codes (encrypted)Authenticating you and protecting the accountContract; legitimate interest in account security (Art. 6(1)(f))
Sessions: IP address, summarised browser/OS, timestampsKeeping you signed in; showing your active devices; detecting sign-ins from new devicesContract; legitimate interest in security
Security events: sign-in, password and two-factor changes, passkey changes, data export, deletion requests — with IP address and summarised browser/OSLetting you review account activity; investigating abuse and compromiseLegitimate interest in platform security
Acceptance of these documents: timestamp and versionEvidencing which terms your account was created underLegal obligation / legitimate interest in accountability
Onboarding interests — which kinds of work you told us you do (for example “I run a FiveM server”)Deciding which Titan products to suggest to you, instead of showing all of themLegitimate interest in a usable product; clear them at any time
Conversion source — which Titan product you came from when starting a subscriptionUnderstanding which products lead people to subscribe. A coarse product name, not a tracking identifierLegitimate interest in measuring our own funnel
Organization membership, roles and invitationsManaging team access to Titan applicationsContract
OAuth consents and tokens issued to applications you authorizeSingle sign-on to Titan applicationsContract
Discord account identifier and provider tokens, if you link Discord (stored encrypted)Signing in with DiscordContract (you chose this sign-in method)
Billing: Stripe customer and subscription identifiers, plan, status, period dates, invoice amounts and payment outcomes for organizations you administerTaking payment, granting paid features, keeping accounting recordsContract; legal obligation for accounting records
Record of transactional email we sent you (recipient, subject, delivery status)Delivering verification, password-reset and security messages, and retrying failuresContract; legitimate interest in reliable delivery
Administrative audit entries when Titan staff act on an accountAccountability for administrative actionLegitimate interest in accountability

We do not use advertising, profiling for marketing, or analytics or tracking cookies on this service. We do not sell personal data. We do not knowingly collect data from children under 16.

The interests you pick during onboarding are used for one thing: choosing which products to recommend. Nothing is inferred from your behaviour, no score is built, and the selection is never shared with the individual products. Skipping onboarding, or unticking everything, removes it.

3. Automated decisions

Rate limiting and abuse controls may temporarily block a sign-in attempt or a request from an IP address. Two-factor lockout may temporarily block verification after repeated failures. These are automated but time-limited and do not by themselves terminate an account; account suspension is decided by a person. We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR on this service.

4. Cookies and local storage

Titan Account sets only what is strictly necessary to sign you in and keep the service secure: a session cookie, cookies used during OAuth sign-in, and a preference for light or dark theme stored in your browser. These are exempt from consent under the ePrivacy rules, so there is no cookie banner. We set no analytics, advertising or tracking technologies.

5. Who receives your data

  • Titan applications you authorize — the identity claims covered by the scopes shown on the consent screen, plus your organization membership where requested.
  • Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.) — payment processing and subscription billing for paid plans.
  • Resend — delivery of transactional email (verification, password reset, security alerts).
  • Discord — only if you choose to sign in with Discord.
  • Hosting and infrastructure — the provider running our application servers, PostgreSQL database and optional Redis cache. [TITAN LEGAL DETAILS REQUIRED — name the hosting provider]

These providers act as our processors under a data processing agreement, except Discord, which is an independent controller for your Discord account.

6. International transfers

Some of these providers are established outside the European Economic Area or may process data there. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with additional safeguards where required. The specific mechanism for each provider is confirmed in our processor agreements. [OWNER INPUT REQUIRED — confirm the transfer mechanism relied on for each provider]

7. How long we keep it

Your account data is kept while your account exists. Other categories are deleted automatically once they reach the periods below:

CategoryRetention
Security events (sign-ins, password and MFA changes)180 days
Administrative audit entries730 days
Billing and subscription events730 days
Record of transactional email sent to you30 days
Completed change-of-address requests180 days
Expired sessions7 days
Unaccepted organization invitations30 days

Expired sessions, verification links and OAuth tokens are cleared shortly after they expire. Invoices and accounting records are kept for the period Czech accounting and tax law requires. Backups are retained on a rolling schedule and overwritten in turn; data deleted from the live system disappears from backups as they roll over.

8. Deleting your account

You can delete your account from Settings → Security. We email a confirmation link; once you open it we erase your profile, credentials, passkeys, two-factor secrets, sessions, linked accounts, organization memberships and invitations, application consents and issued tokens, your security event history and organizations of which you were the only member.

Two things survive, and we think you should know which: records we are legally required to keep, such as invoices and accounting data for paid subscriptions; and administrative audit entries recording actions taken on other accounts, from which your identity is removed. Deletion of your Titan Account does not automatically delete data held by connected Titan applications you used — contact that service, or us, to have it removed.

9. Your rights

Under the GDPR you have the right to:

  • access your data — download it yourself from Settings → Security;
  • rectify inaccurate data — edit your profile, or contact us;
  • erase your data — delete your account, as described above;
  • restrict or object to processing based on legitimate interests;
  • portability — the export is machine-readable JSON;
  • withdraw consent where processing is based on consent, without affecting prior processing.

We answer within one month. You may also lodge a complaint with the Czech data protection authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), whose address is Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, or with the authority where you live.

10. Security

Passwords are hashed with Argon2id. Two-factor secrets, backup codes and provider access tokens are encrypted at rest. OAuth client secrets and issued tokens are stored hashed. Traffic is encrypted with TLS. We apply rate limiting, log security-relevant events, and restrict administrative access. No system is perfectly secure; if a breach affects your personal data and is likely to result in a high risk to you, we will notify you.

11. Beta service

Titan Account is provided as a beta version. That does not change any of the obligations described here or reduce your rights.

12. Changes

We may update this policy. The version and date at the top change when we do, and we record which version your account accepted. We will notify you of material changes.

Terms of Service

© 2026 Titan Software z.s.