1. Data controller
The controller responsible for processing your data is:
Full provider details are being added. Until then, email is the way to reach us: shahbazianzkristian@gmail.com
We have not appointed a data protection officer; we are not required to.
2. What we collect
- Account data: name, email, password (stored only as a salted hash), language, chosen coach, units, country.
- Fitness profile: sex, age, height, weight, activity level, goal, experience, training environment, equipment, and any injuries you type into the free-text field.
- Usage data: workouts, sets, reps, weights, weigh-ins, checked nutrition rules, logged meals, and your messages to the coach.
- Progress photos: full-body photos (front and side) that you choose to upload. They are stored in our database and are served only to your own account.
- Meal photos: photos of your food taken for the calorie estimate. We do not store them — they are processed for the estimate and only the result (dish name, calories, macros) is kept.
- Payment data: handled entirely by Stripe. We never see your card number — only your subscription status and your Stripe customer ID.
- Technical data: your IP address is held briefly in memory for rate limiting and is not stored persistently.
3. Purposes and legal bases
- Account, plan, training, coaching chat: Art. 6(1)(b) GDPR — we need this data to perform our contract with you.
- Payment and billing: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (statutory retention duties).
- Security, rate limits, abuse and cost control: Art. 6(1)(f) GDPR — our legitimate interest in a working, affordable service.
- Squads (leaderboards): Art. 6(1)(f) GDPR. Other members of your squad see your name and your points — not your weight, not your photos, not your chats. Country squads are formed automatically; you can leave at any time and object under Art. 21 GDPR.
4. Health-adjacent data (Art. 9 GDPR)
Your weight, your injury notes and your progress photos can reveal information about your health. We treat them as special categories of personal data under Art. 9 GDPR and process them solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), given when you complete your profile and before you upload a photo.
You can withdraw that consent at any time (Art. 7(3) GDPR) by deleting the entry, deleting the photo, or deleting your account. Withdrawal does not affect the lawfulness of processing before it. Without this data TITAN cannot build a plan — that is what the service is, not a penalty.
5. Recipients and international transfers
We do not sell your data and do not use it for third-party advertising. We use the following processors:
- Anthropic PBC (USA)— generates your plan and your coach's replies and analyses your photos. What we send: your profile, your plan, your recent logs, your messages, your progress photos (for the body read) and your meal photos (for the calorie estimate). Under our API agreement this data is notused to train Anthropic's models. Transfer mechanism: Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Stripe Payments Europe Ltd. (Ireland, EU) — processes payments; Stripe forwards data to Stripe, Inc. (USA). Transfer mechanism: Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- kie.ai (provider outside the EU) — generates the illustrations for dishes and exercises. It receives only the English name of the dish or exercise(twelve words at most, e.g. "grilled salmon with sweet potato") — no photo, no name, no identifier, nothing that leads back to you.
- Hosting: our server and database are located in the EU.
6. Retention
- Account, profile, logs, progress photos: for as long as your account exists. Delete your account and they are deleted immediately and irreversibly.
- Meal photos: not stored at all — processed for the estimate, then discarded.
- Payment records: up to ten years where commercial and tax law require it. These live at Stripe and outlive the deletion of your account.
- Rate-limit data: in memory, gone at the next server restart at the latest.
- Generated dish and exercise images: kept indefinitely in a shared cache. They are not linked to any user and are not personal data.
7. Cookies
We use only strictly necessary cookies — no tracking, no advertising. That is why we do not ask you for cookie consent.
titan_uid — your session. No login without it.titan_lang — your language.titan_tz — your time zone, so that "today" is today where you are.
8. Security
Passwords are hashed with scrypt and never stored in the clear. Transport is encrypted with HTTPS. Progress photos are served only through an endpoint that checks on every request that the photo is yours.
9. Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — what we hold about you;
- Rectification (Art. 16) — you can change your profile and settings yourself at any time;
- Erasure (Art. 17) — in the app under Settings → Delete account. This removes your account, profile, plans, logs, meals, photos and chat context, and cancels your subscription. It is final; there is no backup to restore from;
- Restriction of processing (Art. 18);
- Data portability (Art. 20) — write to us and we will send your data in a common machine-readable format;
- Object (Art. 21) to processing based on Art. 6(1)(f);
- Withdraw consent (Art. 7(3)) at any time, without giving a reason.
Individual progress photos can be deleted one by one without touching your account. For anything else, an email to shahbazianzkristian@gmail.com is enough.
10. Right to lodge a complaint (Art. 77 GDPR)
You may complain to a data protection supervisory authority at any time — in particular the one where you live or work. As we are established in Bulgaria, our authority is:
Commission for Personal Data Protection (Комисия за защита на личните данни)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
www.cpdp.bg
11. Changes
If this policy changes materially we will tell you in the app. The version published here is the one that applies.