Privacy Policy
Version 2026-09-03
Who is responsible
The controller of the personal data described here is Titan Software z.s., IČO 29738725, Ametystová 702/46, Praha 16 - Radotín, 153 00, Czech Republic. For anything in this notice, including a request to exercise your rights, write to [email protected].
No data protection officer has been appointed; the criteria in Article 37 GDPR are not met. The supervisory authority for the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7), and you have the right to lodge a complaint with it.
Two different roles
For your account — your e-mail address, your sign-in, your billing — Titan Software decides why and how the data is processed, and is the controller.
For the contents of an archive you upload, Titan Software is a processor acting on your instructions. A FiveM resource can contain personal data belonging to other people — player identifiers, licence identifiers, database credentials — and where it does, you are the controller of that data and we process it only to produce your report. The terms governing that relationship are in the Data Processing Agreement.
What is collected, and why
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| E-mail address, display name, avatar | Running your account; service e-mail | Performance of a contract | Until you delete the account |
| Titan Auth identity and the tokens it issues | Signing you in | Performance of a contract | Until you delete the account |
| Sessions: a hash of the session token, a hash of your IP address, a short browser summary | Keeping you signed in; letting you see and revoke devices | Performance of a contract | 30 days, or until you sign out |
| Sign-in attempts: e-mail address, a hash of the IP address, success or failure | Detecting and slowing brute-force attacks | Legitimate interest in securing accounts | 30 days |
| The archive you upload | Producing the scan you asked for | Performance of a contract | 7 days |
| The report: file metadata, findings, code excerpts, extracted indicators | The result of the scan | Performance of a contract | 90 days |
| Sanitized archive, when you accept patches | Delivering the patched copy | Performance of a contract | 7 days |
| Security audit trail: which account did what, and when | Investigating incidents and abuse; answering “what happened to my account” | Legitimate interest in platform security | 24 months |
| Billing: Stripe customer reference, plan, credit balance and ledger | Taking payment and granting what you paid for | Contract; legal obligation for accounting records | Until deletion; invoices as tax law requires |
| Webhook endpoints you configure | Notifying a system of your choosing when a scan finishes | Performance of a contract | Until you remove them |
| API keys | Machine access to your own scans | Performance of a contract | Until you revoke them |
| Which Titan product referred you, and which cross-product links you followed | Understanding which of our products are useful | Consent — only if you accept the optional cookie | 90 days |
What is deliberately not collected
- No passwords. Sign-in is handled entirely by Titan Auth; FXScan holds no password and no password hash.
- No raw IP addresses. Where an address is needed — rate limiting, the device list — only a keyed hash of it is stored.
- No third-party tracking. No advertising networks, no analytics provider, no tracking pixels, no fingerprinting. The Content-Security-Policy blocks third-party scripts outright and fonts are served from this domain.
- No marketing e-mail. Every message FXScan sends is transactional.
- Nothing is sent to code we analyse. While scanning your archive the application makes no outbound request at all, and never contacts a URL, webhook or endpoint found inside the code.
Analysed code is never executed
Your archive is read, hashed and parsed into a syntax tree. It is not run: there is no eval, no loading of an analysed file as code, no child process and no evaluation of a manifest.
Indicators the scanner extracts — URLs, webhooks, likely secrets, player and licence identifiers — are stored alongside a redacted form. The redacted form is what the application and the API return; the full value is retained for the life of the report so that a finding can be re-examined, and is deleted with it.
Who else sees your data
Only the processors below, each under a contract, and only for what they do for us. Your scan reports are private by default and are never shared, sold or published. A report is visible to somebody else only if you deliberately create a share link, which you can revoke at any time.
| Provider | What it does | What it receives |
|---|---|---|
| Titan Auth (Titan Software z.s.) | Signing you in | Your identity and the sign-in itself |
| Stripe Payments Europe, Ltd. (Ireland) | Taking payment for paid plans and credits | Your e-mail address and payment details. Card numbers are entered on Stripe's own page and never reach FXScan |
| our e-mail delivery provider (see the current subprocessor list) | Delivering service e-mail | Your e-mail address and the message |
| our hosting provider (see the current subprocessor list) | Running the servers and storing the data | Everything described in this notice |
A webhook endpoint you configure yourself is not a processor of ours: when you point one at a system of your choosing, you are directing us to send scan metadata there.
Transfers outside the EEA
FXScan is operated from within the European Economic Area and your data is stored there. Stripe contracts with us through its Irish entity but may transfer data to the United States within its own group; where it does, it relies on the safeguards required by Chapter V GDPR, including the European Commission's standard contractual clauses. Stripe's current documentation of those safeguards is available from Stripe.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to another provider, or object to processing we base on a legitimate interest. Where processing rests on consent you can withdraw it at any time, and doing so does not affect what happened before.
- A copy of everything, immediately: signed in, request
/api/v1/account/export, which returns a JSON file containing every record we hold about your account. - Deletion: Settings → Delete account. What this does and does not reach is described below.
- Withdrawing analytics consent: clear this site's data in your browser and choose Reject when the banner reappears. Refusing also deletes the cookie already stored.
- Anything else: [email protected]. We answer within one month.
What deleting your account actually does
Being precise about this matters more than being reassuring.
- Deleted immediately: your profile, every uploaded archive and sanitized copy, every report, finding and indicator, your sessions, API keys, webhook endpoints, watches, suppressions and credit ledger.
- Detached from you: security audit records are kept for their retention period, but the identifiers linking them to you are removed, and your address is cleared from the sign-in history.
- Not deleted by us: your Titan Software account itself, which is separate and is managed at auth.titansoftware.eu; and invoices held by Stripe, which tax law requires to be retained.
Automated decisions
FXScan scores code, not people. Nothing about you is decided automatically: there is no profiling, and no account is suspended, restricted or refused by an algorithm. Where an account is suspended it is done by a person and recorded in the audit trail.
Cookies
Every cookie and storage key, what it does and which of them need your consent, is listed in the Cookie Policy. One optional cookie exists and it is set only if you accept it.
Children
FXScan is a tool for people who operate game servers and is not directed at children. An account requires a Titan Software account, and you must be at least 15 years old to create one. If you believe a child has given us personal data, write to [email protected] and we will remove it.
Changes
When this notice changes materially you will be asked to read and accept it the next time you sign in, and the version at the top of this page will change. We keep a record of which version each account accepted and when.