Titanium Home

Privacy Policy

What we collect, why we collect it, who else sees it, and how to get it back or have it deleted. Written to be specific rather than reassuring.

Last updated 25 July 2026 Titanium · titanium.day
01

In short

Titanium is a habit tracker. The record you build is personal, and most of it is nobody else's business — so the defaults are private and the disclosures below are specific rather than generic.

Private by default Your profile is private until you turn it on, and each habit stays private until you publish that habit individually. Both switches start off, so a new account publishes nothing.
Never public Your daily log, to-dos, week planning, infractions, affirmations, calendar events and email address are never shown on your profile — regardless of your settings.
No advertising We do not sell or rent your information, we run no advertising, and we use no ad, attribution or data-broker software. Nothing tracks you across other apps or websites.
AI, narrowly Only one thing is sent to an AI provider: the text of your daily affirmation, so it can be read aloud. Your log, habits, to-dos and infractions are not.
Apple Health Health values are read on your device and never leave it. We receive only "this habit was met today".
Analytics The website has no analytics or third-party scripts at all. The iOS app includes Google Firebase analytics and crash reporting.
02

Who is responsible for your information

Titanium Labs Inc., a corporation incorporated in Canada, is responsible for the personal information described here (the "controller" under European law).

As Canadian law requires, we have designated an individual accountable for our compliance with it. Their title is Privacy Officer, and they are also the person in charge of the protection of personal information for the purposes of Quebec law. To reach them — to ask a question, exercise a right, or complain — write to privacy@titanium.day. That mailbox is monitored and is the fastest route to a human.

03

What we collect, and why

Your account

An email address and a username you choose. If you sign up on the website with a password, we store a hash of it (Argon2) and never the password itself. If you sign in with a one-time code, with Google, or with Apple, no password exists for your account at all.

When you use Sign in with Apple and choose Hide My Email, we receive Apple's private relay address rather than your real one, and that relay address becomes your account email. We treat it as your personal information.

Sign-in with Google returns your Google display name to our server, and Sign in with Apple asks you on Apple's own sheet whether to share your name. We do not store either. There is no name field on your account — the only name we keep is the username you chose. The Google display name passes through a short-lived login handoff and is discarded.

What you record

The substance of the product, all of it entered by you: habit names, emoji, whether each habit is one to keep or to avoid, and any cooldown limits; which habits you completed or failed on which dates, and when a negative habit was triggered; your daily log; your to-dos and week-planning notes; your infractions and their descriptions; your daily affirmation and the voice you picked for it; and target dates. From this we derive your daily completion figures, XP, rank, streaks and perfect-day counts.

Settings and sessions

Your email preferences and your two visibility switches. For sign-in, we store only the SHA-256 hash of your session token — never the token itself — with its expiry, and for one-time email codes only a SHA-256 hash, valid ten minutes.

Google Calendar, only if you connect it

If you connect a calendar, we request read-only access and copy events in a window from about a month back to four months ahead into our database: the event's title and location, its start and end times, whether it is all-day, its Google event identifier and link, plus the name and colour of each calendar and the email address of the Google account you connected. We also hold the access and refresh tokens needed to keep it in sync. We never write to your calendar. Disconnecting deletes all of it, tokens included.

Calendar entries can contain other people's information — who you are meeting, where. Please bear that in mind, and see section 7 for the limits we accept on this data.

Apple Health, only if you use it

You can link a habit to a health metric so it completes itself when you hit your target. We request read-only access to only the metrics you have actually mapped, from this list: step count, exercise minutes, active energy burned, dietary energy consumed, and body mass.

No health value ever leaves your device. Your phone compares the metric to your target locally and sends us only the same thing a tap would have sent: that a habit was completed on a date. We hold no health measurement, and our database has no field that could store one. We never use health data for advertising or marketing, never use it for use-based data mining, and never disclose it to anyone.

The iOS app: analytics and crash reports

The iOS app includes Google Firebase Analytics and Crashlytics. From the moment the app launches these collect: which screens you visit; your device model, operating system version and app version; a Firebase installation identifier; approximate location inferred from your IP address (city-level at best — the app has no location permission and never reads your GPS); crash reports and performance diagnostics. When you are signed in, we also set your account identifier and your username on both services, so this data is linked to you rather than anonymous.

This is currently on for everyone using the iOS app and there is no in-app switch to turn it off. If you want it stopped for your account, write to privacy@titanium.day and we will handle it; we are also working on making it a setting.

The website

The website loads no analytics, no advertising, no third-party fonts and no third-party scripts of any kind. Our servers and our hosting provider produce ordinary operational logs as any web server does, used to keep the service running and secure and kept only briefly; we do not build profiles from them.

04

What we do not collect

Stated plainly, because privacy policies usually leave it ambiguous. Titanium contains no advertising software, no attribution or install-tracking software, and no data-broker integration. Specifically, we do not collect or use:

  • any advertising identifier (there is no IDFA, and the app never asks to track you across apps or websites);
  • your precise or device location, your camera, photos, microphone, contacts or files — the app requests none of these permissions;
  • your real name, date of birth, gender, phone number, or postal address;
  • payment card or bank details — if you subscribe, Apple handles payment and we never see them;
  • push notification tokens; the app sends no push notifications;
  • any health measurement, as described above, and no clinical or medical-record data of any kind;
  • the contents of your Gmail, Drive, or any Google service other than Calendar.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, in the sense those terms carry under US state privacy laws.

05

Why we are allowed to process it

Under Canadian law we rely on your consent, which you give by creating an account and using the features described here, and which you can withdraw. Where the European or UK GDPR applies to you, our legal bases are:

Contract Running your account and the tracking features you came for: storing what you record, computing your scores, keeping you signed in, sending service messages.
Consent Optional things you control: publishing a profile or a habit, connecting Google Calendar, using Apple Health, and the read-aloud affirmation feature — all off until you turn them on. Weekly and monthly summary emails are the exception: they start on, and the daily reminder starts off. You can withdraw any of these at any time, in the same place you set it, without affecting anything else.
Legitimate interests Keeping the service secure and working, preventing abuse, and understanding faults — including crash reporting. We use the minimum needed and you can object.
Legal obligation Responding to lawful requests and keeping records we are required to keep.

Some of what you write in Titanium may reveal sensitive things — your health, your beliefs, your private life. Where that is treated as a special category of data, our basis is your explicit consent, given by choosing to write it down; you can delete any entry, or your whole account, at any time. You do not have to provide an email address to read this page, but you do to have an account, since it is how we identify you.

06

Who else sees it

We use a small number of service providers, who may process your information only on our instructions and only for these purposes. We do not sell your information to anyone.

Fly.io Hosting for the application and its database. Everything described in section 3 is stored here, in the United States. Privacy policy.
Google — Firebase Analytics and crash reporting in the iOS app only. Firebase privacy.
Google — Gemini API Turns your affirmation text into speech. Receives that text and nothing else. API terms.
Google — Sign-in & Calendar Authenticates you if you choose Google, and provides calendar events if you connect them. Privacy policy.
Apple Sign in with Apple, and — if you subscribe — the purchase itself. Apple Canada acts as our agent for App Store sales, takes the payment and decides refunds. Privacy policy.
Resend Sends our email. Receives your address and the message contents, which for summary emails include your username, habit names and completion figures. Privacy policy.

Beyond those, we disclose personal information only: when you have published it yourself (see section 8); when we are legally required to, or to establish or defend legal claims — and we will tell you unless we are prohibited from doing so; to protect someone's safety or the security of the service; or, if Titanium is ever sold or merged, to the acquirer, who would remain bound by this policy or give you notice before changing it.

07

The AI feature, and the calendar, in detail

Read-aloud affirmations

When you play your affirmation, the text of that affirmation — up to 500 characters, whatever you wrote — is sent to Google's Gemini API, which returns audio. That is the only user content Titanium sends to any AI provider. Your daily log, habit names, to-dos, infractions, and calendar events are never sent to it.

We use the paid tier of that API, under which Google acts as our processor and does not use the text to train its models. Google may process it briefly for automated abuse detection. We do not use your content to train any model, and we do not let anyone else do so. We keep the affirmation text on our servers so the app can show it back to you; the generated audio is not stored on our servers at all, though the app caches it on your device so replaying it is instant.

Google Calendar

Our use of information from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Calendar data is used only to show your events alongside your day inside Titanium. It is not used for advertising, is not sold, is not transferred to anyone except as needed to run the feature or where the law requires, and is not read by any human except with your explicit permission or for security or legal reasons. It is never sent to any AI service.

08

What other people can see

Nothing, until you decide otherwise. Two independent switches control it and both start off: one makes your profile viewable, and one per habit decides whether that habit appears on it.

With a public profile, any visitor — signed in or not — can see:

  • your username;
  • the name, emoji and order of only the habits you marked public;
  • whether each of those is complete or failed today; and
  • a per-day grid of how many of those habits you completed on each date.

Not shown, ever: your daily log, to-dos, week planning, infractions, affirmations or their audio, calendar events, email address, XP, rank, streak, or the habits you kept private.

Exceptions worth knowing. The leaderboard publicly shows the usernames, XP and ranks of the top-scoring accounts, and it does that even if your profile is private — write to privacy@titanium.day to be excluded. A public profile page can be indexed by search engines and cached by services we do not control; making a profile private again stops us serving it, but cannot retract copies others already made. And as section 13 explains, older parts of the product predate these visibility controls, so we describe the settings above as how Titanium is designed to behave rather than as a guarantee about every route that has ever existed.

09

Email we send you

Some email is necessary to run your account and is not marketing: your one-time sign-in codes and messages about your account or these policies. You cannot opt out of those while you have an account, though we keep them to a minimum.

Separately, Titanium can send weekly and monthly summaries (on by default) and a daily reminder (off by default). These contain your username, your habit names, your completion figures and streaks, and any reminder message you wrote yourself. Every one of them carries an unsubscribe link and you can change all of it in your email settings. Every one of them carries a link to those settings, where the three switches live — there is no one-click unsubscribe link in the message itself yet, and we would rather say so than imply otherwise. Turning a switch off stops that email immediately, and we act on any request to stop them within ten business days at the outside. Reminder emails are sent at a fixed time in UTC, not in your local timezone, because we do not collect your timezone.

We do not send advertising, and we do not send your address to anyone for marketing.

10

Cookies and storage on your device

We use a small number of strictly necessary first-party cookies to sign you in and to protect the sign-in flow, and the app stores your session token on your device so you stay signed in. We set no analytics, advertising or tracking cookies on the website. The Cookie Policy names every one and says exactly what it does.

11

Where your information goes

We are a Canadian company, but our servers and several of our providers are in the United States, and other providers may process data elsewhere. Your information will therefore be stored and processed outside Canada.

This matters for a specific reason we would rather state than bury: while your information is in another country, it is subject to that country's laws, and may be accessible to its courts, law enforcement and national security authorities under those laws. We remain accountable for it wherever it is, and we require providers by contract to protect it to a comparable standard.

Questions about processing outside Canada — including which countries are involved and what each provider is permitted to do with your information — go to our Privacy Officer, who can answer on our behalf. Written information about these practices is available on request, free of charge.

For people in the European Economic Area and the United Kingdom: the European Commission has decided that Canada provides an adequate level of protection for personal information transferred to organisations subject to our federal privacy law, and the UK maintains an equivalent finding. Where we then send information from Canada onward to providers in the United States, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum for UK data). Some of those providers are additionally certified under the EU–US Data Privacy Framework, but we do not rely on that certification on its own. Ask us and we will tell you which mechanism covers a particular provider.

12

How long we keep it

Account & content For as long as your account exists. This is a history you are deliberately building, so we do not quietly expire it.
After deletion Erased from live systems immediately when you delete your account — not queued for later. Backups roll off on their own cycle within 90 days, after which nothing remains.
Sign-in codes Only ever held as a hash, and unusable after ten minutes. The row itself is deleted when you use the code, when a new one replaces it, or if delivery fails.
Sessions Thirty days, extended while you keep using the app; deleted when you sign out or it expires.
Calendar events Replaced on each sync, and deleted in full — with the access tokens — the moment you disconnect.
Analytics & crashes Held by Google under Firebase's own retention periods. Signing out stops new data being attributed to you but does not erase what was already collected; ask us and we will request its deletion.
Operational logs Days, not months — kept only to run and secure the service.
13

Security, honestly

What we actually do:

  • all traffic to Titanium is encrypted in transit, and HTTPS is enforced;
  • passwords, where one exists, are stored as Argon2 hashes, and sign-in codes and session tokens only as SHA-256 hashes — so none of those can be read back out of our database. The exception, stated plainly: if you connect Google Calendar we must hold a usable Google access token to keep it in sync, and that one is not hashed;
  • sessions expire, and requests for your data are checked against the account that owns it;
  • on your profile page, private data is filtered out on the server before the page is built rather than merely hidden in the browser, so a visitor is not sent it;
  • access to production systems is restricted to the developer.

What we will not pretend. No service is immune. We are a very small team, we hold no security certifications, and we do not run scheduled third-party audits. Titanium has also been built and rebuilt quickly, and not every part of it is equally mature: some older areas predate the profile-visibility controls described above, and we are working through them — so please treat the visibility settings as our intent and our direction of travel, not as a guarantee that no bug has ever left something more visible than you chose.

If you find a vulnerability, tell us at privacy@titanium.day. We will acknowledge it, fix it, and we will not pursue you for reporting it in good faith.

If a breach of your personal information creates a real risk of significant harm to you, we will notify you and the relevant regulators as the law requires, and tell you what happened and what to do about it.

14

Your rights

Wherever you live, you can ask us to do all of the following, and we will not charge you or treat you differently for asking:

  • See it — get a copy of the personal information we hold about you.
  • Get it in a portable form — we do not yet have a self-serve export button, so ask and we will assemble your data in a machine-readable file for you.
  • Correct it — including your username, or your email address if it has changed.
  • Delete it — Settings → Delete account, in the app or on the website, erases your account and all of it at once, immediately. You can also delete individual entries yourself at any time.
  • Withdraw consent — turn off a public profile, disconnect your calendar, revoke Apple Health in iOS Settings, stop the summary emails, or stop using the read-aloud feature. Withdrawing is as easy as enabling it was.
  • Object, or ask us to restrict processing — including our use of analytics and crash reporting.
  • Ask how a decision was made — though we should say that Titanium makes no automated decision with a legal or similarly significant effect on you. XP, rank and streaks are arithmetic applied to what you recorded, and you can see the inputs.

Write to privacy@titanium.day. We will respond within 30 days, and within one month where the GDPR applies. We may need to confirm you control the account before acting.

If we get it wrong, you can complain to a regulator — and we would rather you told us first so we can fix it. In Canada, the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d'accès à l'information; in the UK, the Information Commissioner's Office; in the EEA, your national data protection authority.

15

Children

Titanium is not intended for children under 13, is not directed at them, and we do not knowingly collect their personal information. We do not ask your age, so we rely on this being respected; if you believe a child has given us information, write to privacy@titanium.day and we will delete the account. Where local law sets a higher age for consenting without a parent or guardian — 14 in Quebec, and 13 to 16 across the EEA — that age applies instead.

16

Changes to this policy

If we change this policy we will update the date at the top of the page, and for material changes we will tell you by email or in the app before they take effect. Where a change means using your information for a genuinely new purpose that relies on consent, we will ask you again rather than assume the old consent covers it. Previous versions are available on request.

17

Contact

For anything in this policy, including to exercise a right, reach our privacy contact directly:

Titanium Labs Inc.
Privacy: privacy@titanium.day
Support: support@titanium.day
Legal: legal@titanium.day
Terms Privacy Cookies
© 2026 titanium.day