Privacy Policy
Last updated 5 October 2026
Titan is a spending tracker made by TINYLabs in Singapore (“TINYLabs”, “we”, “us”). This policy explains what personal data Titan collects, why, who receives it, how long it is kept, and the choices you have. It is designed to comply with Singapore’s Personal Data Protection Act 2012 (the “PDPA”).
By using Titan, you consent to the collection, use and disclosure of your personal data as described in this policy. If you do not agree, please do not use Titan.
Your TINYLabs account, which signs you in to every TINYLabs app, is covered by the TINYLabs Privacy Policy. Where the two differ, this policy applies to Titan.
TL;DR
This summary is for convenience only. It is not part of this policy, and the sections below are what apply.
- Titan does not ask for your bank login, and does not hold or move your money.
- Statements are read by Titan’s own software, not by an AI model. The file is not kept; the charges are.
- An AI model reads a chat message or a receipt photo only with your permission.
- Titan does not sell your data or show you advertising.
- You can ask for a copy of your data, or to close your account, by writing to privacy@gotinylabs.com.
1. What Titan collects
| What | Details | Where it comes from |
|---|---|---|
| Account | Email address, name, preferred currency and time zone. | Your TINYLabs account. |
| Charges and subscriptions | Date, amount, currency, merchant, category, your notes, who a charge was for, and which card paid. For a row that collates small charges, or a receipt, the items inside it. | You: typed in, logged in chat, or imported from a statement. |
| Cards | Your label for the card, the issuer and product, the last four or five digits, statement and due days, fees, whether autopay is on, and your notes. Titan does not ask for or store a full card number, expiry date or security code. | You. |
| Statement settings | Which card belongs to which person, your own names for merchants, and the places where you expect charges from abroad. | You. |
| Telegram assistant | Your Telegram user ID, chat ID and display name. The text of each message you log as an entry is kept with that entry. Titan also keeps the words it learned from your corrections and, for 90 days, messages it could not read. | You, through Telegram. |
| Receipt photos | Read once to list the items. Titan does not keep the photo. | You, through Telegram. |
| Invitation request | Your email address and which button you pressed. | You, on the Titan website. |
| On your device | One sign-in cookie, and your display preferences in the browser’s own storage. | Set by Titan when you sign in and change settings. |
| Technical records | IP address, browser type and the page requested, in the hosting provider’s request logs. | Your browser, automatically. |
Titan does not ask for bank or card-issuer logins, full card numbers, expiry dates, security codes, identity card numbers, your location or your contacts, and it does not run advertising or analytics trackers. Please do not put any of these into notes or other free-text fields.
2. Other people’s details
- A statement can carry a supplementary cardholder’s charges, and you can mark who a charge was for. Titan keeps the name or nickname you choose for that person.
- Titan uses those details only to show you your own household’s spending. It does not contact those people or build a profile of them.
- By adding another person’s details, you confirm that you are entitled to share them and that they are for your own personal or household use. You are responsible for what you add about other people.
3. How statements are read
- A PDF you import is sent to Titan’s server over an encrypted connection and parsed in memory by Titan’s own rule-based reader. It is not written to disk or file storage, and it is not sent to an AI model.
- Titan saves the charge lines: date, merchant, the bank’s description of the charge, amount, category, and the last digits of the card.
- Before anything is saved, the reader is designed to cut full card numbers to their last digits and to mask printed names, addresses, email addresses, identity numbers and other long numbers.
- If the reader detects that any of those details remain, or that the charges do not add up to the bank’s printed total, the import stops and nothing is saved.
- No automated process is perfect. Review each import before you confirm it, and delete anything you do not want kept.
- A CSV file is different. A CSV you prepared yourself is saved as you give it, apart from card numbers, which are cut to their last digits. You are responsible for what a CSV contains; remove anything you do not want kept before importing it.
4. When an AI model is used
- The Telegram assistant reads most messages with Titan’s own rules, without AI.
- When the rules cannot read a message, or you send a receipt photo, Titan asks before an AI model sees it. You can answer “Yes, this once”, “Always allow” or “No”, and you can change that setting in the assistant at any time.
- If you agree, Titan sends that single message (with the date and your currency) or that single photo. It does not send your history, your cards, your statements, your name or your email address. Whatever is in the message or the photo itself is sent, so leave out anything you do not want read.
- If you decline, nothing is sent.
- The model is run by a third-party AI provider, which processes the content outside Singapore, including in the United States. Under that provider’s published terms for business customers at the date of this policy, it deletes this content within 30 days and does not use it to train its models, and it may keep content that breaks its usage policy for longer. We do not control the provider’s systems.
- AI output can be wrong. You are responsible for checking, correcting or deleting any entry it produces.
- Titan’s alerts and card suggestions come from fixed rules, not from AI. Titan does not make automated decisions that have a legal effect on you.
- AI reading is offered on some plans only.
5. Why Titan uses your data
| Purpose | What is used |
|---|---|
| Showing your spending, subscriptions, claims and refunds | Charges, subscriptions, cards, statement settings. |
| Flagging charges to check and showing how your cards’ published terms apply | Charges and cards, compared with rules and issuers’ published card terms. |
| Reminders and replies in Telegram | Telegram IDs, due days, charges. |
| Signing you in and keeping accounts separate | Account details and the sign-in cookie. |
| Improving how Titan’s rules read messages | Messages Titan could not read, for 90 days. You can clear them in Titan at any time. |
| Handling your requests and questions | Your email and what you send us. |
| Billing, once paid membership opens | Account details and payment records. Titan does not receive your full payment card number. |
| Security, preventing misuse, enforcing our terms and meeting legal duties | Technical records and account details. |
Titan relies on your consent, and on the cases where the PDPA allows collection, use or disclosure without consent, such as meeting a legal duty. Titan does not use your data for marketing unless you have opted in, and does not use it for advertising, for sale, or to train AI models.
6. Who receives your data
Titan is run with the help of service providers. Each receives only what it needs for its part, and acts on our instructions under its data processing terms. We may change providers from time to time. You can ask us for the current list at privacy@gotinylabs.com.
| Type of provider | What it does | What it receives | Where |
|---|---|---|---|
| Database and sign-in | Stores Titan’s records and signs you in | Everything Titan stores | Singapore |
| Hosting | Runs Titan’s software | Requests as they pass through, including an imported file while it is read; request logs | Singapore, and the provider’s global network |
| Messaging app | Carries the chat assistant, on Telegram | Messages you send the assistant and its replies | Outside Singapore |
| AI model | Reads a message or receipt photo, with your permission | The single message or photo you approved | Outside Singapore, including the United States |
| Sign-in, fonts and logos | Lets you sign in with an outside account if you choose to; supplies fonts and the logos of services you track | Your sign-in with that account; the website address of a service whose logo is shown | Global |
| Payments | Takes payment, once paid membership opens | Your email and payment details | Global |
- The messaging app and any outside account you sign in with also handle your data for their own purposes under their own privacy policies. We are not responsible for how they do so.
- We may disclose data where the law requires or permits it, including to respond to a lawful request, to protect someone’s safety, or to protect Titan’s security and our legal rights.
- If TINYLabs is reorganised or sold, your data may pass to the new owner, who must continue to honour this policy.
- We do not sell personal data, rent it, or share it for anyone else’s marketing.
7. Data that leaves Singapore
- Your Titan records are stored in Singapore. Some providers in section 6 process data elsewhere, mainly in the United States.
- Where data is transferred outside Singapore, we take steps to ensure the recipient is bound by legally enforceable obligations to protect it to a standard comparable to the PDPA.
- By using Titan, you acknowledge that your data may be processed outside Singapore in this way. You can ask us which countries are involved and for a summary of how the data is protected there.
8. How long Titan keeps it
| Data | Kept for |
|---|---|
| Imported statement files (PDF and CSV) | Not kept. Read in memory and discarded when the import finishes. |
| Receipt photos | Not kept by Titan. The photo stays in your own Telegram chat until you delete it there. |
| Charges, subscriptions, cards and settings | While your account is open, or until you delete them. |
| Messages the assistant could not read | 90 days, or until you clear them. |
| Words the assistant learned from your corrections | While your account is open. |
| Telegram link | Until you disconnect Telegram. Entries you already logged stay in your account, because they are your records. |
| Content sent to the AI reader | Held by the AI provider under its own terms, currently up to 30 days. |
| Invitation request | Until you are invited, or you ask us to remove it. |
| Hosting request logs | Held by the hosting provider, currently up to 30 days. |
| Payment records, once billing opens | As long as the law requires, currently five years. |
| Everything in your account, after you ask us to close it | Deleted within 30 business days of your request. |
| Backup copies held by our database provider | Overwritten within 30 days of deletion. |
| Preferences in your browser | Until you sign out or clear your browser. |
- We may keep data for longer where the law requires it, or where it is needed to establish, exercise or defend a legal claim.
- Periods for data held by providers are the ones those providers publish, and may change.
- We keep a record that a request was made and completed, without the data itself.
9. Security
We use reasonable technical and organisational measures to protect your data. At the date of this policy these include:
- In transit: connections use TLS 1.2 or higher, and browsers are instructed to refuse unencrypted connections (HSTS).
- At rest: the database is encrypted with AES-256.
- Location: your records are held in a Singapore data centre.
- Separation: row-level security is enforced on every Titan table, to prevent one account from reading another’s records.
- Sign-in: through your TINYLabs account, with support for passkeys and two-step verification.
- Less to lose: Titan does not ask for bank logins, full card numbers, expiry dates or security codes, and does not keep statement files.
- Fail closed: if the statement reader cannot confirm that personal details were removed, or the charges do not add up to the bank’s total, the import stops.
- Providers: our hosting and database providers publish independent SOC 2 Type 2 and ISO 27001 certifications.
- No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
- You are responsible for keeping your sign-in details, your devices and your Telegram account secure, and for telling us promptly at privacy@gotinylabs.com if you suspect unauthorised access.
- If a data breach occurs that the PDPA requires us to report, we will notify the Personal Data Protection Commission and the people affected as the PDPA requires.
10. Your choices and rights
| You can | How | When |
|---|---|---|
| Correct or delete an entry, card or subscription | In Titan | Immediately |
| Change or withdraw permission for AI reading | In the Telegram assistant | Immediately |
| Disconnect Telegram or switch off reminders | In Titan | Immediately |
| Export your charges and subscriptions | In Titan, as a CSV file | Immediately |
| Get a full copy of everything Titan holds about you | Write to privacy@gotinylabs.com | Within 30 business days |
| Close your account and delete your data | Write to privacy@gotinylabs.com | Within 30 business days |
| Withdraw consent for any other use | Write to privacy@gotinylabs.com | Within 10 business days |
| Ask how your data has been used or disclosed in the past year | Write to privacy@gotinylabs.com | Within 30 business days |
- Write from the email address on your account. We may ask for more information to confirm it is you, and the time for a request runs from when we have it.
- We acknowledge a request within five business days and tell you when it will be completed.
- These rights are subject to the exceptions in the PDPA. If we cannot do what you ask, for example because the law requires us to keep a record, we will tell you why.
- We do not usually charge for a request. Where the PDPA allows a fee for an access request, we will tell you the amount before we proceed.
- If you withdraw consent that Titan needs in order to work, we may not be able to continue providing Titan to you, and may close your account.
- You can also complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg. We ask that you contact us first so that we can try to put things right.
11. Cookies and browser storage
- Titan sets one cookie: the sign-in cookie for your TINYLabs account, shared across TINYLabs apps on gotinylabs.com so that you sign in once. Titan cannot work without it.
- Your display preferences are kept in your browser’s own storage.
- Titan does not set advertising or analytics cookies.
12. Age
Titan is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to privacy@gotinylabs.com and we will delete it.
13. Changes to this policy
- We may update this policy from time to time. The date at the top shows when it last changed.
- If a change materially affects how your data is used, we will tell you by email or in Titan before it takes effect, and ask for your consent again where the law requires it.
- Continuing to use Titan after a change takes effect means you accept the updated policy.
14. Contact
Questions, requests and complaints about personal data go to our Data Protection Officer at privacy@gotinylabs.com. Titan is operated by TINYLabs, Singapore.