Tabletop Tomes Back

Privacy Policy

Last updated: July 14, 2026

Tabletop Tomes ("we", "the app") is a between-sessions companion for tabletop RPG groups. This policy explains what we collect, why, and the control you have over it. Short version: we collect the minimum needed for the app to work, we don't sell anything to anyone, and you can delete everything whenever you want without asking us.

What we collect

Account information — your name, email address, and (if you choose to upload one) a profile photo.

Content you create — characters, journal entries, Table posts, comments, reactions, custom emoji, trophies, and any images you upload. This content is shown to other members of the campaigns you've joined.

Technical data — the minimum needed to operate the service: session cookies for authentication, browser push-notification subscription data (only if you opt in), and server-side error logs that may temporarily include IP addresses.

We do not use third-party analytics, ad networks, or tracking pixels.

How we use it

  • To display your characters, journal entries, and other content to the other members of the campaigns you've joined.
  • To send you transactional emails (account verification, campaign invitations, reminders you've subscribed to).
  • To send browser push notifications if you've opted in.
  • To investigate abuse or violations of our Terms of Service.
  • To comply with the law — including disclosing information to the appropriate authorities where we are legally required to, or acting on content that sexualises or endangers a minor.

We do not sell your data. We do not share it with advertisers. We do not use it to train machine-learning models.

AI features

Some features send content to an AI provider. This only happens when you use that feature, it only sends the content the feature needs, and it's only used to produce the result you asked for:

  • Character portraits and sheet import (OpenAI). Generating a portrait sends the character details you've written; importing a character sheet sends the sheet image you uploaded. The finished portrait is stored like any other image you'd upload; the sheet image is processed and discarded.
  • The Scriptorium (xAI). A Game-Master-only desk that turns prep notes, photos of notes, voice memos, and full session recordings into drafts the GM reviews — nothing it produces enters the campaign record without the GM's explicit approval. Audio and text are processed by xAI; photos of notes are read and discarded, not stored. Uploading a session recording requires the GM to attest that the whole table agreed to be recorded. Session transcripts are kept only for a retention window the GM controls, then deleted — and curating an entry deletes its transcript early.

We don't use your content to train models, and we use these providers through business API tiers where the provider commits not to train on it either. If you never touch an AI feature, nothing is ever sent.

Where it's stored

  • Account and content data are stored in our database on Amazon Web Services (US region).
  • Uploaded images are stored on Amazon S3 and delivered via Amazon CloudFront.
  • Transactional email is sent via Mailgun.
  • Browser push notifications are delivered via your browser vendor's push service (Google, Apple, Mozilla).
  • GIFs at the Table are searched and served by Klipy, our GIF provider. When you open GIF search or view a post containing a GIF, your browser loads it directly from Klipy's content servers, so Klipy sees your IP address. This is ordinary content delivery — we don't run Klipy's ads, and we don't share your account or any other data with them.
  • AI-feature content goes to OpenAI and xAI as described in "AI features" above — only when you use those features.
  • Errors are reported to Sentry so we can fix bugs, with personal data scrubbed before anything is sent — an error report identifies the bug, not you.

Your rights

You have two self-serve controls on the Profile page:

  • Download my data — exports everything we have on your account (profile, characters, journal entries, comments, reactions) as a JSON file.
  • Delete Account — permanently deletes your account and all of your personal content from our systems. Characters you created are anonymized so that other players' journal entries and posts that reference them continue to read correctly, but all identifying details are removed.

You do not need to email anyone or wait for our approval to do either of these things.

If you are the Game Master of a campaign with other members, you'll be asked to delete the campaign first before deleting your account. This is to protect the work of the other players in your campaign.

Children

Tabletop Tomes is intended for players 13 and older. If you believe a child under 13 has created an account, please contact us and we will delete it.

Contact

Questions about this policy or how your data is handled:

hello@tabletoptomes.com