▌ LegalLegal

Privacy Policy

▌ Effective July 5, 2026

Titan AI builds autonomous systems that operate in sensitive environments. We treat the data those systems collect — and the data you share with us — with the same standard of care we apply to the autonomy stack itself. This policy explains what we collect, why, who controls it, and the choices you have. It applies to titan.ai, our hosted demo environments (including command.titan.ai), and our sales, support, and recruiting channels. Data collected by deployed customer fleets is governed primarily by the customer's agreement with us, as described below.

§ 01

The two kinds of data we handle

Data about you. Contact details, applications, and website usage. For this data, Titan AI is the controller and this policy is the primary document.

Data collected by customer fleets. Sensor streams, telemetry, mission logs, and audit records produced by machines a customer owns or operates. For this data the customer is the controller and Titan AI acts as a processor under the customer agreement and its data-processing terms. We process fleet data to operate the service, to provide support, and — only where the agreement permits — to improve our models. This policy describes our handling practices; the agreement governs.

§ 02

What we collect from you

Contact and account information. Name, work email, employer, role, and the contents of messages you send when you request a demo, contact sales or support, or apply for a position. Recruiting materials (résumés, portfolios) are used only for hiring.

Website usage. We use Google Analytics to understand which pages are read. The analytics script loads only after the page is interactive, and we do not use analytics identifiers to build advertising profiles. Server logs record IP addresses and requests for security and reliability and are retained for up to 90 days.

Demo environment activity. If you use a hosted demo such as command.titan.ai, we log the operator identifier you connect with and the actions you take in the console — which are also written to the demo's audit chain, because that is the product working as designed. Demo fleets are synthetic; no real-world sensor data is involved.

§ 03

What deployed machines collect

A production Titan machine collects what its mission requires: camera and other sensor streams, position, mission state, model decisions, system health, and a hash-chained audit log of every actuation and command. Two design commitments shape this:

Processing stays local by default. Perception and decision-making run on the machine. Raw sensor streams are not continuously shipped to Titan; telemetry summaries and flagged events are transmitted per the customer's configuration.

PII minimization at the edge. Where deployments operate around people, the stack is designed to detect and redact personal identifiers — such as faces and license plates — on-device before storage or transmission, subject to the customer's configuration and applicable law. Customers are responsible for signage, notice, and lawful basis in the environments where their fleets operate.

§ 04

Data sovereignty

Enterprise and defense customers can elect on-premise or air-gapped deployments where operational data never leaves customer-controlled infrastructure — in that configuration Titan receives no fleet data at all unless the customer exports it to us. Sensor-data retention windows are customer-controlled.

§ 05

How we use data

To provide and secure our services; to respond to your inquiries; to operate demos; to debug and improve the platform; to comply with legal obligations; and — for customer fleet data, only as the agreement permits — to improve models through our simulation and training pipeline. We do not sell personal information, and we do not use it for third-party advertising.

§ 06

When we share data

With service providers who host and support our infrastructure (cloud hosting, analytics, email), bound by contract to process data only on our instructions. With a customer's own organization, for fleet data that customer controls. As part of a merger, acquisition, or asset sale, subject to this policy. And where required by law — in which case we notify the affected customer or individual unless legally prohibited from doing so.

§ 07

Retention

Contact and sales records: while the relationship is active and up to 24 months after last contact. Recruiting materials: up to 12 months unless you ask us to delete them sooner. Website server logs: up to 90 days. Demo audit chains are periodically reset with the demo environment. Customer fleet data is retained per the customer agreement; audit and evidence records may carry longer, contractually defined retention because their integrity is the point.

§ 08

Security

Data in transit is encrypted with TLS; fleet links use mutually authenticated channels. Access to production systems is role-restricted and logged. The platform's own audit mechanisms — hash-chained, tamper-evident logs — apply to our handling of fleet data as well. Our vulnerability disclosure program and security practices are described on the Security page.

§ 09

International transfers

We are headquartered in the United States and may process data there and in other jurisdictions where our service providers operate. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for transfers of personal data from the EEA, the UK, and Switzerland.

§ 10

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export personal data we hold about you, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise any of these, contact [email protected] — we respond within 30 days. If your data was collected by a customer's fleet, we will refer your request to that customer, who controls it, and support them in fulfilling it.

§ 11

Children

Our services are business tools and are not directed to children under 16. We do not knowingly collect personal information from children.

§ 12

Changes and contact

We will post changes to this policy here and update the effective date; material changes affecting customers are notified directly. Questions, requests, and suspected-incident reports: [email protected].