← Back to Home

Privacy Policy

Last updated: 15 September 2026

1. Introduction

This Privacy Policy explains how personal data is processed when you use Children of Titan, the website childrenoftitan.com and the associated browser-based game (together, the "Service"). It fulfils the information obligations under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Austrian Data Protection Act (DSG).

2. Controller

The controller responsible for processing your personal data is:

Gorden Kirisits

Sole proprietor trading as PI IT Solutions

Waldesruhgasse 3B, 5111 Bürmoos, Austria

Email: [email protected]

Further details are set out in our Imprint.

We have not appointed a Data Protection Officer because we are not required to do so under Article 37 GDPR. All data protection questions and requests can be sent to the email address above.

3. Do You Have to Provide Your Data?

To create and use a game account you must provide an email address, a username and a password. Without this data we cannot conclude or perform the contract for the Service. To make purchases, payment data must be provided to our payment provider. All other data is optional: connecting a wallet, linking Discord, enabling push notifications, uploading an avatar and writing chat messages are your choice, and not doing so only means that the respective feature is not available to you. You are not required by law to provide personal data to us.

4. What We Process and Why

4.1 Registration, Login and Account Security

When you register we process your email address, username and a hashed password (the password itself is never stored in plain text). We send you an email to verify your address, and we send one-time codes by email for two-factor authentication and links for password resets. When you register we store the time at which you accepted the Terms of Service and the version of the Terms you accepted, so that we can prove the conclusion of the contract. If you were invited by another player, we store the referral link between the two accounts. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for the acceptance record also our legitimate interest in being able to prove the contract (Art. 6(1)(f) GDPR).

4.2 Gameplay, Public Profile and Leaderboards

We process the data generated while you play, for example bases, colonies, resources, troops, ships, alliances, research, cards, gems and other in-game balances, missions, battle reports, league and tournament results, achievements and in-game transaction histories. Your username, avatar, game statistics, alliance membership and rankings are visible to other players, for example on leaderboards and public profile pages. If you use the paid simulation bot API, the bot name and author link you choose are shown on the public leaderboard; we store only a hash of your API key. Legal basis: performance of the contract (Art. 6(1)(b) GDPR), because a multiplayer game with rankings cannot be provided without showing this information to other players.

4.3 Chat, User Content and Reports

The Service has a moon chat (readable by players who open that moon) and an alliance chat (readable by members of the alliance). We store the message content, the sender account and the time. Avatars and alliance or tournament images that you upload are stored with our file storage provider (see Section 6) and are publicly accessible via their link. If your alliance has a managed Discord channel and the optional chat bridge is active, alliance chat messages are also posted to that Discord channel together with your in-game username, and messages written in that Discord channel appear in the alliance chat.

Messages can be reported with the report button. A report is sent to our support team by email and contains the reported message, its sender and the reporting account. We use this information to review the report, take a decision and inform the affected user and the reporting user about it, as required by Articles 16 and 17 of the Digital Services Act (DSA). Legal basis: performance of the contract (Art. 6(1)(b) GDPR) for providing the chat; compliance with legal obligations under the DSA (Art. 6(1)(c) GDPR) and our legitimate interest in a safe community (Art. 6(1)(f) GDPR) for handling reports and moderation.

4.4 Purchases and Subscriptions

Gem packages, the Commander Pass subscription and the simulation bot API subscription are paid through Stripe. When you start a checkout we send Stripe your account email address and internal identifiers of your account and the product. Stripe collects your payment details (for example card data, name and billing address) directly; we do not receive your full card number. From Stripe we receive the payment and subscription status, a customer identifier and the amounts, which we need to credit your purchase and manage your subscription. Before checkout you confirm that you are at least 18 years old or have the consent of a legal guardian and that you request immediate supply and acknowledge that you lose your right of withdrawal once supply begins; the time of this confirmation is stored with the Stripe checkout session. You can manage or cancel subscriptions in the Stripe customer portal or through our contract cancellation and withdrawal page.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR); retention of accounting records under tax law (Art. 6(1)(c) GDPR in conjunction with §132 Austrian Federal Fiscal Code, BAO); the consent and waiver record to meet and prove our obligations under consumer law (Art. 6(1)(c) and (f) GDPR).

4.5 Emails

We send transactional emails that are necessary for your account, such as email verification, password resets, two-factor authentication codes and messages about purchases, cancellations, withdrawals and moderation decisions. These emails are sent through the email servers of our hosting provider IONOS. We do not send marketing or newsletter emails without your consent. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and legal obligations (Art. 6(1)(c) GDPR).

4.6 Push Notifications

If you turn on push notifications and allow them in your browser, we store the push subscription your browser creates (an endpoint address at your browser vendor's push service and encryption keys), a shortened browser description for your device list, and your notification settings. Notifications are encrypted and delivered through the push service of your browser vendor (see Section 6). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by turning notifications off in the game or in your browser settings.

4.7 Discord Linking and Discord Server

You can link your Discord account. For this we use Discord's login authorisation with the "identify" permission only and store your Discord user ID, Discord username, Discord avatar and the time of linking. With a linked account our Discord bot assigns you roles on our Discord server that reflect your game progress and alliance, gives access to your alliance's private channel and can post game event announcements. If you use the bot commands to link the simulation game, we store your simulation API key in encrypted form. You can unlink Discord at any time in your profile settings. Legal basis: performance of the contract at your request (Art. 6(1)(b) GDPR). Discord processes data on its platform under its own privacy policy.

4.8 Wallets and Blockchain Features

If you connect a cryptocurrency wallet, we store your public wallet address and, when you link the wallet to your account, a signed message that proves you control it. We never have access to your private keys or seed phrase. Wallet connections run through Reown (WalletConnect) and reading blockchain data runs through blockchain node providers (see Section 6). The wallet connection components are only loaded after you choose to connect a wallet; pages with NFT and portal features may read public blockchain data through a node provider directly from your browser. When you mint cards as NFTs or perform other on-chain transactions, the transaction and your wallet address are recorded on a public blockchain (Base or Ethereum). Such data is public, can be viewed by anyone and cannot be changed or deleted by us or by you. Legal basis: performance of the contract at your request (Art. 6(1)(b) GDPR).

4.9 Security, Abuse Prevention and IP Addresses

When you access the Service, your IP address, the time, the requested page and technical browser information are processed by our hosting provider and by Cloudflare, which protects the Service against attacks and delivers content. Requests are rate-limited based on the IP address. In the simulation game we store the last IP address used with your game state to detect multiple accounts and abuse; this IP address is deleted after 90 days. Suspicious cases are reviewed by a person. Legal basis: our legitimate interest in the security of the Service and fair play (Art. 6(1)(f) GDPR).

4.10 Legal Obligations and Legal Claims

We process data where this is required to comply with legal obligations, for example tax and accounting rules or requests from authorities (Art. 6(1)(c) GDPR), and where necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR).

5. Overview of Legal Bases

PurposeData UsedLegal Basis
Account, login, two-factor authenticationEmail, username, hashed password, one-time codes, terms acceptance recordContract (Art. 6(1)(b)); proof of contract (Art. 6(1)(f))
Gameplay, public profile, leaderboardsGameplay data, username, avatar, statistics, allianceContract (Art. 6(1)(b))
Moon chat and alliance chatMessage content, sender, timeContract (Art. 6(1)(b))
Reports and moderation decisionsReported content, sender, reporter, decisionLegal obligation under the DSA (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))
Purchases and subscriptionsEmail, customer and subscription identifiers, amounts, consent recordContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Transactional emailsEmail address, message contentContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Push notificationsPush subscription, browser description, settingsConsent (Art. 6(1)(a))
Discord linking, roles, alliance channels, chat bridgeDiscord ID, username, avatar, alliance chat messagesContract at your request (Art. 6(1)(b))
Wallet connection and blockchain featuresPublic wallet address, signatures, transactionsContract at your request (Art. 6(1)(b))
Security, CDN, abuse preventionIP address, request data, last IP in the simulation gameLegitimate interest (Art. 6(1)(f))
Accounting and legal compliancePayment and invoice records, as requiredLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, our interests are the security and integrity of the Service, fair play, a safe community and the ability to prove and defend our legal position. You may object to this processing at any time for reasons arising from your particular situation (see Section 10).

6. Recipients and Service Providers

We do not sell or rent your personal data. We use the following service providers. Processors act only on our instructions under a data processing agreement (Art. 28 GDPR). Where a provider acts as an independent controller, its own privacy policy also applies.

IONOS SE (Germany)

Purpose: Hosting of the website, game servers and database; sending transactional emails via IONOS email servers (SMTP).

Data: All data processed in the Service, including account data, gameplay data, chat messages, IP addresses and email content.

Legal basis: Art. 6(1)(b), (c) and (f) GDPR, depending on the purpose served.

Role: Processor

Location: Servers located in the European Union

Transfer safeguard: No transfer outside the EU/EEA by us.

Cloudflare, Inc. (USA)

Purpose: Content delivery network and protection against attacks and abuse.

Data: IP address, request data (URL, time, browser information).

Legal basis: Art. 6(1)(f) GDPR (secure and fast delivery of the Service).

Role: Processor

Location: Global network, including the USA

Transfer safeguard: EU-U.S. Data Privacy Framework (Cloudflare is certified) and Standard Contractual Clauses.

Stripe Payments Europe, Limited (Ireland) and Stripe, Inc. (USA)

Purpose: Payment processing for gem purchases and subscriptions, Stripe Checkout, subscription management in the Stripe customer portal, tax calculation, fraud prevention.

Data: Email address, name, billing address, payment method details, transaction and subscription data, account and product identifiers, purchase consent record.

Legal basis: Art. 6(1)(b) and (c) GDPR.

Role: Stripe processes payment data as an independent controller where it acts for its own purposes (for example payment processing, fraud prevention and its legal obligations); otherwise as a processor.

Location: EU and USA

Transfer safeguard: EU-U.S. Data Privacy Framework (Stripe, Inc. is certified) and Standard Contractual Clauses.

Vercel Inc. (USA), Vercel Blob storage

Purpose: Storing uploaded avatars, alliance and tournament images, and generated base images.

Data: Uploaded image files and their public links; the file name contains an internal identifier.

Legal basis: Art. 6(1)(b) GDPR.

Role: Processor

Location: USA

Transfer safeguard: EU-U.S. Data Privacy Framework (Vercel is certified) and Standard Contractual Clauses.

Discord Inc. (USA)

Purpose: Linking your Discord account, role assignment and alliance channels on our Discord server via our bot, bot commands, and the optional alliance chat bridge.

Data: Discord user ID, Discord username and avatar, role assignments, in-game username and alliance chat messages relayed to the alliance's Discord channel.

Legal basis: Art. 6(1)(b) GDPR (only if you link Discord or use our Discord server).

Role: Independent controller for the Discord platform

Location: USA

Transfer safeguard: EU-U.S. Data Privacy Framework where Discord is certified; otherwise the transfer is necessary for the performance of the service you request (Art. 49(1)(b) GDPR).

Browser push services: Google LLC (Firebase Cloud Messaging), Mozilla Corporation, Apple Inc., Microsoft Corporation (all USA)

Purpose: Delivering push notifications. Which service is used depends on your browser (for example Chrome and most Chromium browsers use Google, Firefox uses Mozilla, Safari uses Apple).

Data: Push endpoint address and the end-to-end encrypted notification; the push service also sees the IP address of our server and your device's connection data.

Legal basis: Art. 6(1)(a) GDPR (only if you enable push notifications).

Role: Provider of the push infrastructure selected by your browser vendor

Location: USA and other countries

Transfer safeguard: EU-U.S. Data Privacy Framework where the provider is certified; otherwise Art. 49(1)(a) GDPR based on your consent after this information.

Reown (WalletConnect network)

Purpose: Connecting your crypto wallet through the wallet connection dialog and relaying signing requests to your wallet app. The Reown usage analytics feature is switched off.

Data: Public wallet address, connection and session data, IP address, signing requests.

Legal basis: Art. 6(1)(b) GDPR (only if you choose to connect a wallet).

Role: Provider of the wallet connection infrastructure

Location: May be outside the EU/EEA, including the USA

Transfer safeguard: Where no adequacy decision applies, the transfer is necessary to provide the wallet connection you request (Art. 49(1)(b) GDPR).

Blockchain node providers: LlamaNodes (llamarpc.com) and Chainstack (chainstack.com)

Purpose: Reading blockchain data and sending transactions for wallet and NFT features.

Data: Wallet addresses, transaction data and hashes; for requests sent from your browser also your IP address.

Legal basis: Art. 6(1)(b) GDPR (only if you use wallet or blockchain features).

Role: Provider of blockchain access

Location: May be outside the EU/EEA

Transfer safeguard: Where no adequacy decision applies, the transfer is necessary to provide the blockchain features you request (Art. 49(1)(b) GDPR).

Public blockchains (Base, Ethereum)

Purpose: Recording on-chain transactions you initiate, such as minting cards as NFTs.

Data: Wallet address, transaction details, token ownership.

Legal basis: Art. 6(1)(b) GDPR (only if you initiate an on-chain transaction).

Role: Public, decentralised networks without a controller we can instruct

Location: Worldwide

Transfer safeguard: Data on a public blockchain is publicly visible worldwide and cannot be changed or deleted.

In addition, other players see the information described in Sections 4.2 and 4.3, and we disclose data to authorities or courts where we are legally required to do so. Our website contains links to external sites such as social networks; no data is sent to them unless you click the link, and their own privacy policies apply from then on.

7. Cookies and Local Storage

Without your consent we only store information on your device that is strictly necessary to provide the Service you request (§165(3) Austrian Telecommunications Act, TKG 2021). The cookie banner lets you allow or refuse the optional categories "Functional" and "Analytics". At present no optional service is loaded in either category; should we introduce one, it will only run if you have allowed that category. We use no marketing or advertising cookies:

ItemPurposeDurationConsent
Session and security cookies (authjs.*)Keeping you logged in, protecting forms against cross-site request forgeryUntil you log out, at the latest 30 daysNot required (strictly necessary)
Cookie settings (local storage)Remembering your cookie choicesUntil you change or clear themNot required (strictly necessary)
Preferences you set (local storage)Sound settings, collapsed sidebar, map position, dismissed hints and reminders, pending transaction displayUntil you change or clear themNot required (requested by you)
Wallet connection state (cookie and local storage)Keeping your wallet connected after you choose to connect itUntil you disconnect or clear themNot required (requested by you)

You can change or withdraw your choice at any time via "Cookie settings" in the footer or, inside the game, in the sidebar. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

8. Transfers Outside the EU/EEA

Our servers are located in the EU. Some of the providers listed in Section 6 are based in the USA or other third countries. For the USA, the European Commission has adopted an adequacy decision for companies certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Where a provider is not certified, we rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR) where we have concluded them, or, for services you actively request such as wallet connections, on the exception in Art. 49(1)(b) GDPR. Please note that in countries without an adequate level of protection, authorities may have access to data and your rights may be harder to enforce. You can request a copy of the safeguards by contacting us.

9. Retention Periods

  • Account and gameplay data: for as long as your account exists. When your account is deleted, your account and the associated game data are deleted, except for the records listed below. Anonymised statistics that no longer relate to you may be kept.
  • Payment and accounting records: 7 years from the end of the calendar year of the transaction (§132 BAO), and longer while a tax or legal procedure concerning them is pending.
  • Moon chat: the newest 200 messages per moon are kept; older messages are deleted automatically once a day.
  • Alliance chat: the newest 200 unpinned messages per alliance are kept; older unpinned messages are deleted automatically. Pinned messages are kept until they are unpinned or the alliance is deleted.
  • Chat messages relayed to Discord: copies posted to a Discord channel by the chat bridge are stored by Discord and are not removed automatically when the in-game message or your account is deleted.
  • Reports and moderation decisions: as long as needed to handle the report and any complaint about the decision, and longer only where needed to defend legal claims.
  • In-game notifications: deleted 7 days after you have read them, and after 30 days at the latest.
  • Push subscriptions: until you turn push notifications off, the push service reports the subscription as expired, or your account is deleted.
  • Last IP address in the simulation game: deleted after 90 days.
  • Server and security logs: only as long as needed to detect and analyse attacks and errors, after which they are deleted or overwritten.
  • Discord link: until you unlink Discord or delete your account.
  • Public blockchain data: cannot be deleted (see Section 4.8).

10. Your Rights

Under the GDPR you have the right to:

  • Access (Art. 15): obtain confirmation and a copy of the personal data we hold about you
  • Rectification (Art. 16): correct inaccurate or incomplete data
  • Erasure (Art. 17): have your data deleted, subject to statutory retention obligations
  • Restriction (Art. 18): restrict processing in certain circumstances
  • Data portability (Art. 20): receive data you provided in a structured, commonly used, machine-readable format
  • Objection (Art. 21): object at any time to processing based on legitimate interests, for reasons arising from your particular situation
  • Withdrawal of consent (Art. 7(3)): withdraw any consent at any time with effect for the future

To delete your account or exercise any other right, write to [email protected]. We may ask for information to confirm your identity. We respond within one month; this period can be extended by two further months for complex requests, in which case we will inform you. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

11. How to Withdraw Consent

  • Cookie categories: open "Cookie settings" in the footer and switch off the categories you no longer allow.
  • Push notifications: turn them off in the game settings or revoke the permission in your browser.

Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal.

12. Right to Lodge a Complaint

If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority responsible for us is:

Österreichische Datenschutzbehörde (Austrian Data Protection Authority)

Barichgasse 40-42, 1030 Wien, Austria

Web: dsb.gv.at

13. Automated Decision-Making

We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). Rankings and game outcomes are calculated automatically according to the game rules. Names you choose for certain in-game objects are checked automatically against a list of prohibited words and rejected if they match. Decisions to restrict or suspend accounts are taken by a person.

14. Children and Young Users

The Service is not directed at children under 13, and the Terms of Service require a minimum age of 13 for an account. If we learn that an account belongs to a child under 13, we will delete it. Processing for the game account is based on the contract (Art. 6(1)(b) GDPR).

Consent-based processing (push notifications) requires the consent of a parent or legal guardian for users below the age of digital consent in their country (for example 14 in Austria and 16 in Germany). Users below that age should not opt in without such consent. Purchases and subscriptions are only permitted from the age of 18 or with the consent of a legal guardian. Parents or guardians can contact us at [email protected].

15. Data Security

We take appropriate technical and organisational measures (Art. 32 GDPR), including:

  • Passwords stored only as hashes, never in plain text
  • Two-factor authentication available for all accounts
  • Encrypted connections (TLS/HTTPS) for all data in transit
  • httpOnly session cookies and protection against cross-site request forgery
  • API keys stored only as hashes; stored Discord bot keys encrypted
  • Access to personal data limited to what is needed

If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the supervisory authority within 72 hours where required (Art. 33 GDPR) and inform you without undue delay where the risk is high (Art. 34 GDPR).

16. Changes to This Policy

We update this Privacy Policy when our processing or the law changes. The current version is always available on this page with its "Last updated" date. We inform you about material changes in the game or by email. Where a change requires your consent, we will ask for it.

17. Contact

Gorden Kirisits, PI IT Solutions (Children of Titan)

Waldesruhgasse 3B, 5111 Bürmoos, Austria

Email: [email protected]