Tabletop Index

Privacy Policy

Last updated: May 20, 2026

Overview

Tabletop Index ("we", "us", or "our") is a directory of actual play shows. This policy explains what personal data we collect, how we use it, and your rights regarding that data. We are committed to handling your information responsibly and in compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR).

If you have questions or requests about your data, contact us at tabletopindex@gmail.com.


Data We Collect

We collect the following information when you use Tabletop Index:

  • Email address — collected when you create an account, used for authentication.
  • Username and profile information — the display name, bio, and avatar URL you choose to set on your profile.
  • Show data — titles, descriptions, tags, system info, and other details you submit when listing or editing a show.
  • Ratings and vibes — the vibe ratings you submit for shows.
  • Hearts (favorites) — shows you have saved or hearted.
  • Session data — an authentication session token stored in a browser cookie to keep you logged in.
  • Usage events — anonymous data including AP page views, search queries, and engagement events (hearts, vibe ratings, external link clicks).
  • Session identifiers — a temporary, anonymous identifier stored in your browser to understand how visitors navigate the site. This is not linked to your account unless you are logged in.
  • Referrer information — the URL of the page you came from when you arrive at an AP page.
  • Search queries — the terms you search for and filters you apply, including searches that returned no results.

We do not collect payment information, precise location data, or any sensitive personal data.


Analytics & Usage Data

  • We collect this data to improve the directory and to provide creators with insights about their listings.
  • This data is stored in Supabase, on AWS infrastructure.
  • Page view and session data may be collected from non-logged-in visitors.
  • We do not use third-party analytics services — no Google Analytics, no Mixpanel. All data stays in our own database.
  • Anonymous session data is not linked to your identity unless you are logged in.

How We Use Your Data

We use the data we collect to:

  • Power the show directory and surface relevant content.
  • Authenticate you and maintain your session across visits.
  • Display your public profile and the shows you've created.
  • Personalize your experience (e.g. showing your saved shows and ratings).
  • Attribute show ownership and creator profiles.
  • Generate aggregate analytics for AP creators (a Pro tier feature).
  • Improve search results and directory filters.
  • Understand which content is most valuable to listeners.

We do not use your data for advertising, automated profiling, or any purpose beyond operating Tabletop Index.


Data Storage

All user data is stored with Supabase, a managed database and authentication platform. Supabase stores data on infrastructure hosted by Amazon Web Services (AWS). By using Tabletop Index, your data may be processed and stored on servers located in the United States.

Supabase's privacy practices are described in their Privacy Policy.


Authentication

We currently use email and password authentication. We may add social login options (such as Google) in the future. If we do, this policy will be updated to reflect what additional data those providers share with us.


Cookies and Sessions

We use a single session cookie to keep you authenticated between visits. This cookie is set by Supabase and contains a secure session token — it does not contain personally identifiable information itself.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.


We Do Not Sell Your Data

We do not sell, rent, trade, or otherwise transfer your personal data to third parties for commercial purposes. Your data is used solely to operate Tabletop Index.


Affiliate Links & Partnerships

Tabletop Index may contain affiliate links, including links to DriveThruRPG or Amazon. If you click an affiliate link and make a purchase, we may earn a small commission at no extra cost to you.

We only link to products and services relevant to the tabletop RPG community. Affiliate relationships do not influence which shows appear in the directory or how they are ordered.


Your Rights

Depending on where you live, you may have rights regarding your personal data. Under the GDPR and similar laws, these include:

  • Right of access — you can request a copy of the personal data we hold about you.
  • Right to rectification — you can correct inaccurate or incomplete data via your profile settings.
  • Right to erasure — you can request that we delete your account and associated data.
  • Right to restriction — you can ask us to limit how we process your data in certain circumstances.
  • Right to data portability — you can request your data in a structured, machine-readable format.
  • Right to object — you can object to processing of your data in certain circumstances.

To exercise any of these rights, email us at tabletopindex@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.


Data Retention

We retain your data for as long as your account is active. If you request account deletion, we will remove your personal data from our systems within a reasonable timeframe, except where retention is required by law.


Changes to This Policy

We may update this policy from time to time. When we do, we will revise the "last updated" date at the top of this page. Continued use of Tabletop Index after changes are posted constitutes acceptance of the updated policy.


Contact

For any privacy-related questions or requests, contact us at tabletopindex@gmail.com.