Last updated September 7, 2026
Project Tabletop is a session companion for tabletop RPGs. There are no accounts and no login — a campaign is identified by a game code you share with your table. The GM doesn't hold a separate code at all: creating a campaign ties GM control to the browser tab that created it, backed up by a recovery key. This page explains what that means for your data.
When a GM creates a campaign, the app stores whatever is entered into it on our server: the campaign name and description, player names and character stats, inventory and currency, NPCs, the session chat/action log, and any maps, handouts, or portraits uploaded to that campaign. This is the same information the app displays back to your table — it's what makes the tool work, not separately collected data.
Anyone holding the game code can join as a player — treat it like a shared document link, since we have no way to verify identity behind it. GM control isn't a shareable code at all: it's tied to the single browser tab that created the campaign, and it's never displayed as text you could copy or leak. The recovery key (visible to the GM and every player in-session) is the one credential that can leave that tab, and it only ever downloads a backup file — it doesn't grant control of the live session.
A campaign is deleted automatically one hour after everyone (GM and players) has disconnected from it. If a connection briefly drops during a live session — a lost wifi signal, a refreshed page — and reconnects on its own, the deletion is called off and the session continues normally. But once you deliberately leave, there is no way to rejoin that campaign — the session's credentials aren't reusable, and no code or link brings you back in. The one-hour window exists solely to give you time to export the whole campaign as a .vtt file, using your campaign's recovery key (shown in-session to the GM and every player). That export is the durable copy; the server itself is not meant to be one, and after the hour is up, the campaign and its files are gone for good.
Your browser's IP address is held in server memory only, for the duration of your connection, to enforce rate limits that stop a single client from flooding the server. It is never written to disk, logged long-term, or shared with anyone.
The Service is not directed at children under 13, and we do not knowingly collect information from anyone under that age. See the age requirement in our Terms of Service.
Questions about this policy, or requests to delete a campaign's data, can be sent via our contact form.
If what we store or how we handle it changes, this page will be updated with a new date at the top.