Privacy Policy
Last updated August 10, 2026
This policy explains what Top Table processes when you use its web or desktop tabletop application. Top Table does not sell personal data and does not use it for advertising.
Information Top Table processes
- Account and sign-in data: username, display name, optional email address, account and last-sign-in times, password and recovery-answer hashes, session records, and linked sign-in provider and provider account identifiers. A provider email is stored only when that provider returns it under the permissions you approved.
- Table and play data: invitations, memberships, table ownership, playtime totals, campaign saves and revision metadata, table settings, game content, chat or direct-message state, and image, audio, or PDF files that users choose to add.
- Google Drive connection data: an encrypted refresh credential and Top Table files in Google Drive's private
appDataFolderwhen you explicitly connect Drive. The Drive permission does not allow Top Table to browse your ordinary Drive documents. - Device and service data: browser or desktop storage used for local campaign copies and sign-in return state. Cloudflare and the selected sign-in or storage provider also process ordinary request, security, and diagnostic information under their own policies.
How the information is used
Top Table uses this information to create and secure accounts, complete sign-in and account linking, host multiplayer tables, synchronize permitted table state, save and restore campaigns, provide optional Google Drive storage, recover accounts when configured, and protect the service from unauthorized access.
Providers and sharing
Top Table sends data only as needed to operate the service: Cloudflare hosts the public application and cloud service; Google provides optional sign-in and private Drive app-data storage; and Google, Discord, X, Meta, or Steam receives an authorization request only when you choose that provider. Top Table does not request permission to post to social accounts. Table content is shared with the game master and players according to the table's roles and visibility settings.
Storage and retention
- Top Table account sessions expire after 30 days. OAuth sign-in state and one-use exchanges are short-lived.
- A cloud account becomes eligible for scheduled removal after more than eight calendar months without a sign-in. Account-linked authentication, invitation, membership, playtime, campaign-authority, and Top Table-managed cloud records are removed by that maintenance process where applicable.
- A limited table-ownership marker may remain after account removal so an old invite code cannot be reassigned to a different owner. Multiplayer table state or content already shared to another participant's device may also remain outside the deleted account.
- Scheduled account removal does not delete user-owned Google Drive data. Top Table Drive files remain until you explicitly choose Delete Top Table data from Google Drive while disconnecting Drive, or remove them through Google.
- Local browser and desktop copies stay on the device until you delete them in Top Table or remove the application's local/site data. A cloud deletion request cannot erase a device that Top Table cannot access.
Your choices
You can choose local device storage or explicitly connect Google Drive, disconnect Drive while keeping its private copy, or disconnect and delete Top Table's private Drive files. You can also request access, correction, or deletion of your Top Table cloud account by following the User Data Deletion Instructions.
Security
Passwords and recovery answers are stored as salted hashes, Google Drive refresh credentials are encrypted at rest, and cloud account and table routes require authenticated access. No internet service can guarantee absolute security.
Contact
Privacy and data requests are handled manually at fz.demandred@gmail.com.