Privacy
What information Titan holds about you, why we use it, who can see it, how long we keep it, and what choices and rights you have.
Last updated
The short version
Titan holds the information needed to operate your account and the community. That includes your email address, username, anything you publish or submit to Titan, information associated with a linked Minecraft account, and records needed for moderation, safety, security, appeals, and fraud or ban-evasion prevention.
The Minecraft server and forums may also generate ordinary operational records such as login information, gameplay or server logs, transaction records, anti-cheat information, and security logs.
When you sign in to the website, Titan stores a one-way keyed fingerprint derived from your IP address for up to 30 days. The website does not store the IP address itself in that field. The fingerprint may help staff identify possible alternate-account or ban-evasion activity, but a shared fingerprint or network is not treated as conclusive proof that two accounts belong to the same person.
Titan does not use advertising networks, marketing trackers, tracking pixels, or analytics packages, and does not sell or rent personal information for marketing.
Deleting an account does not necessarily erase every moderation or security record. Where Titan needs limited information to keep a punishment enforceable, prevent abuse, resolve an appeal, meet a legal obligation, or preserve the integrity of its audit records, that information may be retained in a reduced or pseudonymised form.
Who this policy is from
Titan is a Minecraft community consisting of a game server, forums, and associated official services.
This policy applies to visitors, account holders, players, and people who interact with Titan through its official systems.
What we hold about you
The information Titan holds depends on how you use the service.
Your account
Titan may hold:
- your email address, used for authentication, account verification, password recovery, security notices, and necessary account communications;
- your password hash, handled by Titan’s authentication provider rather than stored as a readable password;
- whether your email address has been confirmed;
- authentication and session records;
- timestamps or security values used to invalidate old sessions;
- two-factor authentication information where you enable it or where it is required for staff accounts.
Titan staff cannot retrieve your password from its stored hash.
Titan staff will never ask you to provide your password, password-reset code, or two-factor authentication code.
Your profile
Titan may hold:
- your public username;
- previous usernames;
- your join date;
- post count and reaction score;
- a title or role displayed on your profile;
- your Minecraft account UUID and in-game name where you link a Minecraft account;
- previous or relevant Minecraft names where needed for account integrity or moderation records;
- an attested year of birth where Titan operates an age-attestation system.
Your username, profile information intended to be public, join date, post count, and reaction score may be visible publicly.
Your email address and age information are not public.
Linking a Minecraft account is optional unless a particular Titan service expressly requires it.
Things you publish or submit
Titan may hold content you provide through its services, including:
- forum threads and posts;
- edits and previous versions of edited posts;
- reactions;
- reports;
- evidence submitted with a report;
- appeals and supporting evidence;
- replies or information provided during an investigation;
- support requests or other communications sent through official Titan systems where those features are available.
Public forum posts may be visible to anyone on the internet and may be indexed, copied, quoted, archived, or cached by third parties outside Titan’s control.
You should therefore treat content deliberately posted in a public area as public information.
When you report content, Titan may preserve a snapshot of the relevant content as it existed when the report was made. This allows a report to remain reviewable even if the original content is later edited or deleted.
Minecraft and operational records
Operating a Minecraft server generates records beyond the information shown on your forum profile.
Depending on the Titan server mode and systems in use, Titan may hold information such as:
- Minecraft account identifiers and usernames;
- connection and login records;
- server and gameplay logs;
- chat records;
- command or action logs;
- transaction or economy records;
- anti-cheat information;
- records relating to trades, inventories, land, builds, or other gameplay systems where necessary to operate or investigate those systems;
- security and abuse-prevention information.
These records may be used to operate the server, investigate reports, diagnose technical problems, detect cheating or exploitation, restore damage where reasonably possible, prevent fraud, and enforce the Rules.
Moderation records
Titan keeps moderation records so decisions can be understood, reviewed, appealed, and enforced consistently.
These records may include:
- warnings;
- the rule or conduct involved;
- warning points or other internal severity information;
- the date of an incident or moderation action;
- restrictions or sanctions imposed;
- sanction duration or expiry;
- whether points remain active;
- the staff member responsible for an action;
- information explaining the decision;
- the in-game name or account identifier relevant at the time;
- reports made about an account;
- appeals and their outcomes;
- information submitted during an investigation;
- relevant server, forum, transaction, security, or anti-cheat records;
- staff observations;
- staff-only notes where reasonably necessary for moderation, security, safeguarding, fraud prevention, or administration.
Staff-only notes are not public and should be factual, relevant, and proportionate.
Particular care should be taken with unnecessary information about accounts known to belong to minors.
Titan also keeps an audit log of staff actions so important staff activity can be reviewed and staff members can be held accountable.
Evidence relating to moderation
The Rules allow moderation decisions to take account of different kinds of reasonably reliable evidence.
That means Titan may process evidence such as:
- server or forum logs;
- chat history;
- transaction records;
- anti-cheat information;
- screenshots;
- recordings;
- reports;
- account records;
- staff observations;
- information voluntarily supplied during an investigation;
- relevant off-platform material supplied to Titan.
Off-platform material is considered only where there is a meaningful connection to Titan, such as evidence of harassment connected to Titan, punishment evasion, scams targeting Titan members, attacks on Titan, or another matter within the scope of the Rules.
Titan does not claim authority over unrelated private activity merely because the people involved use Titan.
Evidence is assessed in context. A single category of evidence is not necessarily conclusive.
In particular, accounts using the same network or producing the same IP-derived fingerprint are not automatically treated as belonging to the same person. Shared households, schools, workplaces, VPNs, mobile networks, and other legitimate circumstances may cause people to appear technically related.
Technical and security information
Titan also holds limited technical information used for security and abuse prevention.
IP-derived fingerprints
When you sign in to the website, Titan may derive a keyed one-way fingerprint from your IP address.
Only the derived value is stored in Titan’s application database for this purpose.
The fingerprint is used to identify possible relationships between accounts for security, abuse prevention, and punishment-evasion investigations.
It is designed to answer questions such as whether accounts appear to have recently used the same network identifier. It is not intended to reveal an address to ordinary staff or members.
The fingerprint is deleted after 30 days.
A matching fingerprint is an investigative signal, not proof by itself that accounts belong to the same person.
Rate limiting
Titan may derive short-lived identifiers from connection information in order to prevent abuse of:
- registration;
- sign-in;
- password reset;
- posting;
- reporting;
- other endpoints vulnerable to flooding or automated abuse.
These records normally contain counters or temporary identifiers and expire automatically within the applicable rate-limit window.
Provider and infrastructure logs
Hosting, network, authentication, or infrastructure providers may create ordinary server or request logs containing information such as:
- IP address;
- request time;
- browser or protocol information;
- requested resource;
- error or security information.
Retention of these logs depends partly on the provider and configuration Titan uses.
Access to raw infrastructure logs should be limited to people who need them for security, abuse investigation, technical administration, or legal purposes.
What we do not do
Titan does not currently use:
- behavioural advertising;
- advertising networks;
- marketing tracking pixels;
- social-media tracking embeds;
- third-party analytics packages;
- personal data sales;
- personal data rental;
- profiling for advertising.
Titan does not share personal information with advertisers for marketing.
Technical systems may perform functions such as spam prevention, rate limiting, cheat detection, or the production of security signals. Titan does not use personal information for solely automated decision-making that produces legal or similarly significant effects on you.
If Titan later introduces materially different tracking, advertising, profiling, or data-sharing practices, this policy must be updated before or when those practices begin, as applicable, and significant changes will be announced.
Why we use your information
Where UK or EU data-protection law applies, Titan must have a lawful basis for processing personal information.
The basis depends on what the information is being used for.
Providing the service
Titan uses information necessary to provide the services you request, including:
- creating and maintaining your account;
- authenticating you;
- linking your Minecraft account where requested;
- publishing content you choose to post;
- maintaining account and security settings;
- sending necessary account communications;
- providing reports and appeals systems.
Where applicable, this processing is necessary to perform Titan’s agreement with you or to take steps at your request in connection with that agreement.
Legitimate interests
Titan relies on legitimate interests where reasonably necessary to operate and protect the community, including:
- enforcing the Rules;
- investigating reports;
- preventing cheating and exploitation;
- detecting punishment evasion;
- preventing fraud and scams;
- protecting accounts;
- preventing spam and automated abuse;
- maintaining service security;
- safeguarding members;
- handling appeals;
- keeping consistent moderation history;
- keeping staff accountable through audit records;
- protecting the integrity and availability of Titan’s services.
Titan aims to limit this processing to what is reasonably necessary.
Examples include keeping an IP-derived fingerprint for 30 days rather than indefinitely, treating network matches as investigative information rather than conclusive identity evidence, limiting sensitive information to staff who need it, and retaining only the parts of deleted-account moderation records that remain necessary.
Legal obligations
Titan may process, preserve, or disclose information where necessary to comply with a legal obligation.
This can include responding to a valid legal demand or preserving information that Titan is legally required to retain.
Vital interests and serious safety situations
In exceptional circumstances involving a serious risk to somebody’s life or safety, Titan may use or disclose relevant information where data-protection law permits this.
This may be relevant, for example, where Titan receives credible evidence of serious threats or child-safety concerns.
Consent
Titan does not currently rely on consent for advertising or marketing.
If Titan introduces an optional feature for which consent is the appropriate basis, consent will be requested separately and should be capable of being refused or withdrawn where required by law.
Service providers
Titan uses third parties to operate parts of the service.
Those providers may process personal information on Titan’s behalf or as otherwise described in their applicable terms.
Supabase
Titan uses Supabase for database and authentication functionality.
Information held there may include account information, forum information, moderation records, authentication data, and other application data described in this policy.
Supabase may also provide authentication-related account emails such as email confirmation and password-reset messages.
Cloudflare Turnstile
Titan uses Cloudflare Turnstile as an anti-bot measure on certain sensitive forms, such as registration, sign-in, or password reset.
Cloudflare may receive technical information including your IP address and information necessary to determine whether a request appears to come from a human user.
Titan does not use Turnstile as an advertising system.
Upstash
Where configured, Titan uses Upstash for short-lived rate-limiting information.
Rate-limit values are based on derived identifiers and expire within the applicable rate-limit period.
Crafatar
Titan may use Crafatar to render Minecraft player-head images.
Where Titan fetches these images server-side, your browser does not need to send your IP address directly to Crafatar for the image request.
The Minecraft UUID needed to obtain the relevant player image may be sent.
Hosting and infrastructure provider
Other disclosures
Titan does not sell personal information or disclose it for third-party advertising.
Titan may disclose relevant information where reasonably necessary and legally permitted:
- to service providers operating Titan systems;
- in response to a valid legal requirement;
- to investigate or respond to serious fraud or security threats;
- where somebody appears to be at serious risk of harm;
- in connection with serious child-safety concerns;
- to protect Titan, its members, or others from serious unlawful conduct.
Where serious child-safety concerns arise, Titan may preserve relevant evidence and report the matter to an appropriate platform, service provider, safeguarding body, or authority where permitted or required.
Where law permits, Titan will seek to avoid disclosing more information than reasonably necessary.
How long we keep information
Titan does not keep every category of information for the same period.
IP-derived fingerprints
Up to 30 days, after which they are deleted.
Rate-limiting information
Normally minutes to an hour, depending on the applicable rate-limit window.
These records expire automatically.
Previous usernames
A released username may be reserved for 90 days after a change to reduce impersonation risk.
Names that have been associated with staff roles may be retained longer where reasonably necessary to prevent staff impersonation or preserve historical accountability.
Posts and threads
Public forum contributions may remain for as long as the forum operates.
Account deletion does not automatically remove every post because removing all contributions from a discussion may materially disrupt content created by other participants.
You may separately request removal of particular personal information or content. Titan will consider that request in light of applicable law and the rights and interests of other people.
Content removed by moderators may enter a recycle or recovery system before being permanently purged according to Titan’s operational retention process.
Minecraft and operational logs
Retention depends on the type of record and its purpose.
Routine operational logs should not be retained longer than reasonably necessary for operation, security, troubleshooting, moderation, fraud prevention, or legal obligations.
Records attached to an active moderation case, appeal, security investigation, safeguarding matter, or legal hold may be retained longer where necessary for that purpose.
Your account
Account information is normally retained while your account remains open.
Additional information may remain after closure where described below.
Moderation records
A moderation finding does not necessarily disappear merely because its active warning points expire.
Historical moderation information may be retained so Titan can:
- distinguish previous conduct from a clean record;
- investigate repeated or serious misconduct;
- prevent punishment evasion;
- review appeals;
- maintain consistent enforcement;
- prevent fraud;
- safeguard the community;
- maintain staff accountability.
Expired historical information is not necessarily treated as an active punishment.
After account deletion, Titan should reduce retained moderation information to what remains reasonably necessary for these purposes.
Staff audit logs
Audit records may be retained for an extended period where necessary to preserve accountability, investigate staff conduct, demonstrate how a moderation or administrative action occurred, or protect the integrity of Titan’s systems.
Legal and investigation holds
Information that would otherwise be deleted may temporarily be retained where it is:
- relevant to an active investigation;
- relevant to an unresolved appeal;
- necessary for a safeguarding matter;
- subject to a legal preservation requirement;
- reasonably necessary to investigate serious fraud or security abuse.
The information should return to its ordinary retention rules once the reason for the hold ends.
Backups
Titan may maintain encrypted rolling backups.
Deleting information from the live system may not immediately remove every historical copy from an existing backup.
Backups should expire according to their normal retention schedule.
Where a deleted account or record is restored from a backup, applicable deletion or suppression measures should be re-applied.
Your rights
Depending on where you live and the law that applies, you may have rights concerning your personal information.
For people covered by UK or EU data-protection law, these can include the right to:
- ask for access to personal information;
- correct inaccurate information;
- request deletion;
- restrict certain processing;
- object to certain processing;
- receive certain information in a portable format;
- complain to a data-protection authority.
These rights are not absolute in every situation.
For example, Titan may be entitled or required to retain certain information where it remains necessary for legal obligations, the establishment or defence of legal claims, security, fraud prevention, or other legitimate purposes recognised by law.
Titan will not charge for an ordinary rights request unless applicable law permits it in exceptional circumstances.
Titan may need to verify your identity before giving somebody access to account information or carrying out a sensitive request.
Information you can access yourself
Where available:
- your account page shows account information;
- your warnings page shows the user-facing portion of your moderation record and available appeals;
- security settings allow you to manage password and session security.
Data requests
There is currently no self-service export tool.
Requests for access, correction, portability, objection, or deletion are handled through Titan’s privacy contact process.
Where UK or EU law applies, Titan will normally respond to a valid request within the period required by law, subject to any lawful extension.
Deleting your account
Deleting your Titan account closes the account and removes or de-identifies information that Titan no longer needs.
It does not automatically erase every piece of content or every record connected to the account.
Public contributions
Posts and threads may remain after account deletion where retaining the contribution is reasonably necessary to preserve discussions involving other members.
Titan may remove, anonymise, or otherwise alter identifying profile information associated with a deleted account where appropriate.
You may separately ask for specific content containing personal information to be removed.
Moderation, safety, and security records
Some moderation, security, fraud-prevention, safeguarding, and audit information may need to remain after account deletion.
This is particularly relevant where deleting the record would allow somebody to avoid an existing punishment simply by deleting an account and creating another.
Where continued identification is necessary, Titan should retain only the identifiers reasonably needed to keep the record meaningful or enforceable.
This retained information should therefore be described as minimised or pseudonymised, rather than anonymous, wherever Titan can still connect the information to a person or account for enforcement purposes.
Information that no longer needs to identify you should be de-identified where reasonably possible.
The retained record may include information such as:
- the fact that a moderation action occurred;
- the rule or conduct involved;
- its date;
- the sanction;
- whether the sanction remains active;
- the minimum account or game identifiers needed to prevent evasion;
- information necessary to understand or review the decision;
- associated audit information.
Retaining a historical moderation record does not automatically mean expired warning points continue to count.
Objections
Where Titan relies on legitimate interests to retain information, you may object to that processing where the law gives you that right.
Titan will consider your circumstances against the reasons for retaining the information and tell you the outcome.
Active investigations and legal holds
Where information is part of an active investigation, unresolved appeal, safeguarding matter, fraud or security investigation, or legal hold, deletion may be deferred for the relevant information until that reason no longer applies.
Titan should tell you where it is legally able to do so.
Children and young people
Titan is a mixed-age Minecraft community.
Protecting younger users is therefore part of the way the service and moderation system should be designed.
Titan does not use anyone’s information for advertising, including information relating to minors.
Titan also seeks to minimise unnecessary sensitive information about younger members.
Examples include:
- short retention of IP-derived fingerprints;
- restrictions on who can access private account information;
- expectations that staff notes remain factual and proportionate;
- particular restraint when recording unnecessary information about a known minor;
- safeguarding procedures for serious child-safety concerns.
Minimum age
You must meet the minimum age stated in Titan’s Terms of Service to hold an account.
If Titan determines that an account belongs to somebody who does not meet the applicable minimum age, the account may be closed and associated personal information deleted or otherwise handled in accordance with applicable law.
Titan may retain the minimum information lawfully necessary to prevent immediate recreation of an account or to deal with a serious safety, safeguarding, security, fraud, or legal matter.
Parents and guardians
A parent or guardian may contact Titan about personal information held concerning their child.
Titan may need to verify:
- the identity of the requester;
- the identity of the account holder;
- the requester’s authority or relationship to the child;
before disclosing or altering personal information.
How we protect information
Titan uses technical and organisational measures intended to limit unauthorised access, alteration, disclosure, and misuse.
Current measures include the following.
Database permissions
Access controls are enforced at the data layer so users and staff should receive only information their role permits them to access.
Controlled writes
Application changes to protected data are intended to go through controlled database operations that verify permissions rather than giving ordinary user accounts unrestricted write access.
Staff authentication
Staff are required to use two-factor authentication before exercising staff powers.
Particularly sensitive actions may require additional authentication.
Restricted sensitive access
Sensitive account, security, and moderation information is restricted according to staff role and need.
IP-data minimisation
Titan’s application database stores a keyed one-way fingerprint for the 30-day account-correlation function rather than storing the raw IP address in that field.
The secret used to create the fingerprint is kept separately from the database.
Audit logging
Important staff actions are recorded in audit logs designed to make unauthorised or inappropriate administrative activity detectable.
Encryption
Traffic between your browser and Titan is encrypted in transit using HTTPS where applicable.
Hosting and database providers may also provide encryption and security controls for stored data.
No technical system can be guaranteed to be perfectly secure.
If you discover a genuine security vulnerability, please report it privately rather than exploiting it or publishing instructions that could place Titan or its members at risk.
Good-faith security reports will not be treated as misconduct merely because the reporter discovered a vulnerability.
Contact and complaints
To:
- request access to your information;
- correct information;
- request deletion;
- object to processing;
- make another privacy request;
- report a privacy concern;
contact Titan through its designated privacy contact.
If you are dissatisfied with Titan’s handling of your information, you may also have the right to complain to the data-protection authority responsible for your area.
In the United Kingdom, this is the Information Commissioner’s Office.
In the European Union, it will generally be the competent supervisory authority for the relevant member state.
You do not have to complain to Titan before exercising any right to contact a regulator.
Changes to this policy
Titan may update this Privacy Policy as its services, legal obligations, or data practices change.
The “last updated” date at the top should always show when the published policy was most recently changed.
Significant changes affecting what information Titan collects, why it is used, how long it is retained, or who receives it should be announced through an appropriate official Titan channel.
Titan will not quietly introduce advertising, marketing data-sharing, materially broader tracking, or similarly significant new uses of personal information without updating this policy as required.
Where appropriate, changes will be announced before they take effect.