Privacy

Version 2026-09-10 · effective 2026-09-10

This notice describes the personal data Titan Community processes and what you can do about it. It reflects what the software actually does.

Who is responsible

Titan Software z.s. (zapsaný spolek), Ametystová 702/46, 153 00 Praha 16, Czech Republic, IČO 29738725, is the controller for your Titan Community account data. Contact: [email protected]. Full details are on our imprint page.

Two kinds of data

Platform account data is what we hold about you as a Titan Community user: your Discord account id, username, display name, avatar, and — if your Discord email is verified — your email address. We are the controller for this.

Community content is what a community collects using the product: tickets, ticket messages, transcripts, form submissions and reviewer notes. The community that operates the Discord server decides what to collect and why. We process it on their behalf as a processor, under our Data Processing Agreement. If you want that content changed or removed, contact that community’s staff first.

What we store, why, and on what basis

DataWhyLegal basis
Discord id, username, display name, avatarIdentify your account and show who did whatPerformance of our contract with you
Verified email addressBilling records and service noticesContract; legal obligation for invoicing
Discord authorisation tokens (encrypted)List the servers you can connectContract
Session records, including a hashed IPKeep you signed in; let you revoke accessContract; our legitimate interest in security
Sign-in history and failed sign-insDetect and investigate account compromiseOur legitimate interest in security
Messages in ticket channels our bot createsProvide support and build transcriptsOn the community’s instruction, as processor
Form submissions and answersLet the community review your applicationOn the community’s instruction, as processor
Hashed IP on public form submissionsRate limiting and spam prevention onlyOur legitimate interest in preventing abuse
Administrative audit logAccountability; resolve disputes about changesLegitimate interest; accountability under GDPR
Product analytics eventsSee which features are used, to improve themOur legitimate interest in improving the service
Subscription and payment statusBilling and entitlementsContract; legal obligation for accounting

Where we rely on legitimate interests, you can object — see “Your rights” below.

About the hashed IP address

We do not store raw IP addresses. We store a shortened, salted one-way hash. Be aware that this is pseudonymised, not anonymous: the same address always produces the same value, so it remains personal data under the GDPR. We treat it as such — it is covered by the retention periods below and included in a data request.

What we do not do

  • We do not read messages outside the ticket channels our bot creates.
  • We do not sell data or share it with advertisers.
  • We do not put message content or form answers into analytics.
  • We do not log tokens, authorisation codes or payment credentials.
  • We do not use any third-party analytics, advertising or tracking technology.

Cookies and local storage

We use four small pieces of browser storage and no third-party trackers.

NamePurposeDurationType
tc_sessionKeeps you signed in30 daysStrictly necessary
tc_oauthProtects the Discord sign-in against forgery10 minutesStrictly necessary
tc_orgRemembers the organization you last opened90 daysFunctional
tc-themeRemembers light or dark mode. Only written when you change it.Until clearedFunctional (local storage)

None of these are used for analytics, profiling or advertising, so we do not ask for consent to set them. You can clear them at any time in your browser; clearing tc_session signs you out.

How long we keep things

  • Ticket messages: deleted once a closed ticket falls outside the community’s plan history window — 14 days on Free, 180 days on Community, 730 days on Pro. Open tickets keep their full conversation while they are open.
  • Transcripts: kept up to one year, and never longer than the plan history window above.
  • Form submissions and answers: 730 days. A submission a reviewer deletes is removed permanently after 30 days.
  • Sessions: 30 days, or immediately when you sign out.
  • Sign-in and security history: 180 days.
  • Administrative audit log: 730 days.
  • Product analytics: 425 days, and deleted with the organization.
  • Webhook delivery records: 30 days.
  • Deleting an organization removes its content permanently after a 30-day recovery window.
  • Invoices and accounting records are kept for the period Czech accounting and tax law requires, which is longer than the periods above.

Backups follow their own rotation, so data can persist in a backup for a short period after deletion from the live system.

Who else receives data

Discord, Stripe and our hosting provider. Each is listed with the data it receives, its location and its transfer basis on our sub-processors page. Notably, we send Stripe your organization name, the owner’s email address and the owner’s Discord user id so that a billing account can exist. Card details are collected by Stripe and never reach our servers.

Automated decisions

We do not make automated decisions with legal or similarly significant effects about you, and we do not profile you. Ticket routing follows the category a member picks. Applications are reviewed by people. A community can block a specific Discord account from opening tickets, but that is a manual entry made by its staff, not an automated decision by us.

Your rights

You have the right to access your data, correct it, have it erased, restrict or object to processing, and receive it in a portable format. You can also withdraw consent where we rely on it, though for most processing we rely on contract or legitimate interests rather than consent.

Two of these are self-service. In your account settings you can download all your data as a JSON file, and delete your account. Deleting your account removes your identity from Titan Community: your name, avatar, email and Discord link are erased, your Discord authorisation is revoked, and every session ends. Support records and applications held by the communities you contacted are kept but are no longer linked to you, because those communities are the controllers of their own records.

For anything else, email [email protected]. We respond within one month.

Complaints

If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to the Czech supervisory authority, Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic https://uoou.gov.cz. If you live in another EU country, you may complain to your local authority instead.

Children

You must be at least 15 years old to have a Titan Community account, matching the Czech age for information society services. Communities may ask applicants their age in their own forms; that data belongs to the community, and it is responsible for handling it lawfully.

Changes

This notice is versioned. The version you accepted is recorded on your account and shown in your account settings. If we make a material change we will ask you to review it at your next sign-in.