Last updated: 15 September 2026
This Privacy Policy explains how personal data is processed when you use Children of Titan, the website childrenoftitan.com and the associated browser-based game (together, the "Service"). It fulfils the information obligations under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Austrian Data Protection Act (DSG).
The controller responsible for processing your personal data is:
Gorden Kirisits
Sole proprietor trading as PI IT Solutions
Waldesruhgasse 3B, 5111 Bürmoos, Austria
Email: [email protected]
Further details are set out in our Imprint.
We have not appointed a Data Protection Officer because we are not required to do so under Article 37 GDPR. All data protection questions and requests can be sent to the email address above.
To create and use a game account you must provide an email address, a username and a password. Without this data we cannot conclude or perform the contract for the Service. To make purchases, payment data must be provided to our payment provider. All other data is optional: connecting a wallet, linking Discord, enabling push notifications, uploading an avatar and writing chat messages are your choice, and not doing so only means that the respective feature is not available to you. You are not required by law to provide personal data to us.
When you register we process your email address, username and a hashed password (the password itself is never stored in plain text). We send you an email to verify your address, and we send one-time codes by email for two-factor authentication and links for password resets. When you register we store the time at which you accepted the Terms of Service and the version of the Terms you accepted, so that we can prove the conclusion of the contract. If you were invited by another player, we store the referral link between the two accounts. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for the acceptance record also our legitimate interest in being able to prove the contract (Art. 6(1)(f) GDPR).
We process the data generated while you play, for example bases, colonies, resources, troops, ships, alliances, research, cards, gems and other in-game balances, missions, battle reports, league and tournament results, achievements and in-game transaction histories. Your username, avatar, game statistics, alliance membership and rankings are visible to other players, for example on leaderboards and public profile pages. If you use the paid simulation bot API, the bot name and author link you choose are shown on the public leaderboard; we store only a hash of your API key. Legal basis: performance of the contract (Art. 6(1)(b) GDPR), because a multiplayer game with rankings cannot be provided without showing this information to other players.
The Service has a moon chat (readable by players who open that moon) and an alliance chat (readable by members of the alliance). We store the message content, the sender account and the time. Avatars and alliance or tournament images that you upload are stored with our file storage provider (see Section 6) and are publicly accessible via their link. If your alliance has a managed Discord channel and the optional chat bridge is active, alliance chat messages are also posted to that Discord channel together with your in-game username, and messages written in that Discord channel appear in the alliance chat.
Messages can be reported with the report button. A report is sent to our support team by email and contains the reported message, its sender and the reporting account. We use this information to review the report, take a decision and inform the affected user and the reporting user about it, as required by Articles 16 and 17 of the Digital Services Act (DSA). Legal basis: performance of the contract (Art. 6(1)(b) GDPR) for providing the chat; compliance with legal obligations under the DSA (Art. 6(1)(c) GDPR) and our legitimate interest in a safe community (Art. 6(1)(f) GDPR) for handling reports and moderation.
Gem packages, the Commander Pass subscription and the simulation bot API subscription are paid through Stripe. When you start a checkout we send Stripe your account email address and internal identifiers of your account and the product. Stripe collects your payment details (for example card data, name and billing address) directly; we do not receive your full card number. From Stripe we receive the payment and subscription status, a customer identifier and the amounts, which we need to credit your purchase and manage your subscription. Before checkout you confirm that you are at least 18 years old or have the consent of a legal guardian and that you request immediate supply and acknowledge that you lose your right of withdrawal once supply begins; the time of this confirmation is stored with the Stripe checkout session. You can manage or cancel subscriptions in the Stripe customer portal or through our contract cancellation and withdrawal page.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR); retention of accounting records under tax law (Art. 6(1)(c) GDPR in conjunction with §132 Austrian Federal Fiscal Code, BAO); the consent and waiver record to meet and prove our obligations under consumer law (Art. 6(1)(c) and (f) GDPR).
We send transactional emails that are necessary for your account, such as email verification, password resets, two-factor authentication codes and messages about purchases, cancellations, withdrawals and moderation decisions. These emails are sent through the email servers of our hosting provider IONOS. We do not send marketing or newsletter emails without your consent. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and legal obligations (Art. 6(1)(c) GDPR).
If you turn on push notifications and allow them in your browser, we store the push subscription your browser creates (an endpoint address at your browser vendor's push service and encryption keys), a shortened browser description for your device list, and your notification settings. Notifications are encrypted and delivered through the push service of your browser vendor (see Section 6). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by turning notifications off in the game or in your browser settings.
You can link your Discord account. For this we use Discord's login authorisation with the "identify" permission only and store your Discord user ID, Discord username, Discord avatar and the time of linking. With a linked account our Discord bot assigns you roles on our Discord server that reflect your game progress and alliance, gives access to your alliance's private channel and can post game event announcements. If you use the bot commands to link the simulation game, we store your simulation API key in encrypted form. You can unlink Discord at any time in your profile settings. Legal basis: performance of the contract at your request (Art. 6(1)(b) GDPR). Discord processes data on its platform under its own privacy policy.
If you connect a cryptocurrency wallet, we store your public wallet address and, when you link the wallet to your account, a signed message that proves you control it. We never have access to your private keys or seed phrase. Wallet connections run through Reown (WalletConnect) and reading blockchain data runs through blockchain node providers (see Section 6). The wallet connection components are only loaded after you choose to connect a wallet; pages with NFT and portal features may read public blockchain data through a node provider directly from your browser. When you mint cards as NFTs or perform other on-chain transactions, the transaction and your wallet address are recorded on a public blockchain (Base or Ethereum). Such data is public, can be viewed by anyone and cannot be changed or deleted by us or by you. Legal basis: performance of the contract at your request (Art. 6(1)(b) GDPR).
When you access the Service, your IP address, the time, the requested page and technical browser information are processed by our hosting provider and by Cloudflare, which protects the Service against attacks and delivers content. Requests are rate-limited based on the IP address. In the simulation game we store the last IP address used with your game state to detect multiple accounts and abuse; this IP address is deleted after 90 days. Suspicious cases are reviewed by a person. Legal basis: our legitimate interest in the security of the Service and fair play (Art. 6(1)(f) GDPR).
We process data where this is required to comply with legal obligations, for example tax and accounting rules or requests from authorities (Art. 6(1)(c) GDPR), and where necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR).
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account, login, two-factor authentication | Email, username, hashed password, one-time codes, terms acceptance record | Contract (Art. 6(1)(b)); proof of contract (Art. 6(1)(f)) |
| Gameplay, public profile, leaderboards | Gameplay data, username, avatar, statistics, alliance | Contract (Art. 6(1)(b)) |
| Moon chat and alliance chat | Message content, sender, time | Contract (Art. 6(1)(b)) |
| Reports and moderation decisions | Reported content, sender, reporter, decision | Legal obligation under the DSA (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)) |
| Purchases and subscriptions | Email, customer and subscription identifiers, amounts, consent record | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Transactional emails | Email address, message content | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Push notifications | Push subscription, browser description, settings | Consent (Art. 6(1)(a)) |
| Discord linking, roles, alliance channels, chat bridge | Discord ID, username, avatar, alliance chat messages | Contract at your request (Art. 6(1)(b)) |
| Wallet connection and blockchain features | Public wallet address, signatures, transactions | Contract at your request (Art. 6(1)(b)) |
| Security, CDN, abuse prevention | IP address, request data, last IP in the simulation game | Legitimate interest (Art. 6(1)(f)) |
| Accounting and legal compliance | Payment and invoice records, as required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, our interests are the security and integrity of the Service, fair play, a safe community and the ability to prove and defend our legal position. You may object to this processing at any time for reasons arising from your particular situation (see Section 10).
We do not sell or rent your personal data. We use the following service providers. Processors act only on our instructions under a data processing agreement (Art. 28 GDPR). Where a provider acts as an independent controller, its own privacy policy also applies.
IONOS SE (Germany)
Purpose: Hosting of the website, game servers and database; sending transactional emails via IONOS email servers (SMTP).
Data: All data processed in the Service, including account data, gameplay data, chat messages, IP addresses and email content.
Legal basis: Art. 6(1)(b), (c) and (f) GDPR, depending on the purpose served.
Role: Processor
Location: Servers located in the European Union
Transfer safeguard: No transfer outside the EU/EEA by us.
Cloudflare, Inc. (USA)
Purpose: Content delivery network and protection against attacks and abuse.
Data: IP address, request data (URL, time, browser information).
Legal basis: Art. 6(1)(f) GDPR (secure and fast delivery of the Service).
Role: Processor
Location: Global network, including the USA
Transfer safeguard: EU-U.S. Data Privacy Framework (Cloudflare is certified) and Standard Contractual Clauses.
Stripe Payments Europe, Limited (Ireland) and Stripe, Inc. (USA)
Purpose: Payment processing for gem purchases and subscriptions, Stripe Checkout, subscription management in the Stripe customer portal, tax calculation, fraud prevention.
Data: Email address, name, billing address, payment method details, transaction and subscription data, account and product identifiers, purchase consent record.
Legal basis: Art. 6(1)(b) and (c) GDPR.
Role: Stripe processes payment data as an independent controller where it acts for its own purposes (for example payment processing, fraud prevention and its legal obligations); otherwise as a processor.
Location: EU and USA
Transfer safeguard: EU-U.S. Data Privacy Framework (Stripe, Inc. is certified) and Standard Contractual Clauses.
Vercel Inc. (USA), Vercel Blob storage
Purpose: Storing uploaded avatars, alliance and tournament images, and generated base images.
Data: Uploaded image files and their public links; the file name contains an internal identifier.
Legal basis: Art. 6(1)(b) GDPR.
Role: Processor
Location: USA
Transfer safeguard: EU-U.S. Data Privacy Framework (Vercel is certified) and Standard Contractual Clauses.
Discord Inc. (USA)
Purpose: Linking your Discord account, role assignment and alliance channels on our Discord server via our bot, bot commands, and the optional alliance chat bridge.
Data: Discord user ID, Discord username and avatar, role assignments, in-game username and alliance chat messages relayed to the alliance's Discord channel.
Legal basis: Art. 6(1)(b) GDPR (only if you link Discord or use our Discord server).
Role: Independent controller for the Discord platform
Location: USA
Transfer safeguard: EU-U.S. Data Privacy Framework where Discord is certified; otherwise the transfer is necessary for the performance of the service you request (Art. 49(1)(b) GDPR).
Browser push services: Google LLC (Firebase Cloud Messaging), Mozilla Corporation, Apple Inc., Microsoft Corporation (all USA)
Purpose: Delivering push notifications. Which service is used depends on your browser (for example Chrome and most Chromium browsers use Google, Firefox uses Mozilla, Safari uses Apple).
Data: Push endpoint address and the end-to-end encrypted notification; the push service also sees the IP address of our server and your device's connection data.
Legal basis: Art. 6(1)(a) GDPR (only if you enable push notifications).
Role: Provider of the push infrastructure selected by your browser vendor
Location: USA and other countries
Transfer safeguard: EU-U.S. Data Privacy Framework where the provider is certified; otherwise Art. 49(1)(a) GDPR based on your consent after this information.
Reown (WalletConnect network)
Purpose: Connecting your crypto wallet through the wallet connection dialog and relaying signing requests to your wallet app. The Reown usage analytics feature is switched off.
Data: Public wallet address, connection and session data, IP address, signing requests.
Legal basis: Art. 6(1)(b) GDPR (only if you choose to connect a wallet).
Role: Provider of the wallet connection infrastructure
Location: May be outside the EU/EEA, including the USA
Transfer safeguard: Where no adequacy decision applies, the transfer is necessary to provide the wallet connection you request (Art. 49(1)(b) GDPR).
Blockchain node providers: LlamaNodes (llamarpc.com) and Chainstack (chainstack.com)
Purpose: Reading blockchain data and sending transactions for wallet and NFT features.
Data: Wallet addresses, transaction data and hashes; for requests sent from your browser also your IP address.
Legal basis: Art. 6(1)(b) GDPR (only if you use wallet or blockchain features).
Role: Provider of blockchain access
Location: May be outside the EU/EEA
Transfer safeguard: Where no adequacy decision applies, the transfer is necessary to provide the blockchain features you request (Art. 49(1)(b) GDPR).
Public blockchains (Base, Ethereum)
Purpose: Recording on-chain transactions you initiate, such as minting cards as NFTs.
Data: Wallet address, transaction details, token ownership.
Legal basis: Art. 6(1)(b) GDPR (only if you initiate an on-chain transaction).
Role: Public, decentralised networks without a controller we can instruct
Location: Worldwide
Transfer safeguard: Data on a public blockchain is publicly visible worldwide and cannot be changed or deleted.
In addition, other players see the information described in Sections 4.2 and 4.3, and we disclose data to authorities or courts where we are legally required to do so. Our website contains links to external sites such as social networks; no data is sent to them unless you click the link, and their own privacy policies apply from then on.
Without your consent we only store information on your device that is strictly necessary to provide the Service you request (§165(3) Austrian Telecommunications Act, TKG 2021). The cookie banner lets you allow or refuse the optional categories "Functional" and "Analytics". At present no optional service is loaded in either category; should we introduce one, it will only run if you have allowed that category. We use no marketing or advertising cookies:
| Item | Purpose | Duration | Consent |
|---|---|---|---|
| Session and security cookies (authjs.*) | Keeping you logged in, protecting forms against cross-site request forgery | Until you log out, at the latest 30 days | Not required (strictly necessary) |
| Cookie settings (local storage) | Remembering your cookie choices | Until you change or clear them | Not required (strictly necessary) |
| Preferences you set (local storage) | Sound settings, collapsed sidebar, map position, dismissed hints and reminders, pending transaction display | Until you change or clear them | Not required (requested by you) |
| Wallet connection state (cookie and local storage) | Keeping your wallet connected after you choose to connect it | Until you disconnect or clear them | Not required (requested by you) |
You can change or withdraw your choice at any time via "Cookie settings" in the footer or, inside the game, in the sidebar. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Our servers are located in the EU. Some of the providers listed in Section 6 are based in the USA or other third countries. For the USA, the European Commission has adopted an adequacy decision for companies certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Where a provider is not certified, we rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR) where we have concluded them, or, for services you actively request such as wallet connections, on the exception in Art. 49(1)(b) GDPR. Please note that in countries without an adequate level of protection, authorities may have access to data and your rights may be harder to enforce. You can request a copy of the safeguards by contacting us.
Under the GDPR you have the right to:
To delete your account or exercise any other right, write to [email protected]. We may ask for information to confirm your identity. We respond within one month; this period can be extended by two further months for complex requests, in which case we will inform you. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal.
If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority responsible for us is:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42, 1030 Wien, Austria
Web: dsb.gv.at
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). Rankings and game outcomes are calculated automatically according to the game rules. Names you choose for certain in-game objects are checked automatically against a list of prohibited words and rejected if they match. Decisions to restrict or suspend accounts are taken by a person.
The Service is not directed at children under 13, and the Terms of Service require a minimum age of 13 for an account. If we learn that an account belongs to a child under 13, we will delete it. Processing for the game account is based on the contract (Art. 6(1)(b) GDPR).
Consent-based processing (push notifications) requires the consent of a parent or legal guardian for users below the age of digital consent in their country (for example 14 in Austria and 16 in Germany). Users below that age should not opt in without such consent. Purchases and subscriptions are only permitted from the age of 18 or with the consent of a legal guardian. Parents or guardians can contact us at [email protected].
We take appropriate technical and organisational measures (Art. 32 GDPR), including:
If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the supervisory authority within 72 hours where required (Art. 33 GDPR) and inform you without undue delay where the risk is high (Art. 34 GDPR).
We update this Privacy Policy when our processing or the law changes. The current version is always available on this page with its "Last updated" date. We inform you about material changes in the game or by email. Where a change requires your consent, we will ask for it.
Gorden Kirisits, PI IT Solutions (Children of Titan)
Waldesruhgasse 3B, 5111 Bürmoos, Austria
Email: [email protected]