What we keep, plainly.
What we store: your account email; the display name and avatar URL you set; the games in your library, and whether you own each one or want it; which tables you're at and your role at each; the nights you propose or host, and your RSVPs; the invitations you send, with the address each went to and what came of it. Each session you open records the IP address and browser it started from. That list mirrors what the app does. Nothing gets collected along the way that it doesn't use.
Signing in: you need an account to use Full Table, so we keep your email and what's needed to sign you in and keep you signed in: a password, stored hashed, if you set one, or the tokens Google hands back if you sign in with Google. Google sign-in is optional. When you use it, Google gives us your name, email and profile picture, and those become your profile. Set a display name if you'd rather your tables see that than your email.
Game data from BoardGameGeek: when you search for a game, what you typed goes to BoardGameGeek from our server, under our API key. When you add one, we fetch its details (title, player counts, thumbnail) from BoardGameGeek and cache them in our shared catalog. Cover art loads from BoardGameGeek's image host in your browser, the way any picture on a page does.
Email: we send email for your account and for invitations: sign-in links, one-time codes, password reset codes, and a confirmation when you create an account. If someone invites you to a table by address, the invitation comes by email too, with their display name and the table's name. All of it goes out through Cloudflare's email service. No marketing email.
Who handles it: Full Table runs on Cloudflare: the app, its database, and its outgoing email. Cloudflare sees the traffic the way any host does. Nobody else receives your data, apart from BoardGameGeek for game searches and Google if you sign in with it.
Who sees what: Full Table is scoped to tables. The other members of a table you're at can see how you show up there (your display name, or your email if you haven't set one), the games you own, the nights you propose, and your RSVPs. Your wishlist stays on your own library page. People who sit at a table with you, or who you've invited, can pick you from a list when they invite others, and that list carries your email address so the invitation can be sent. Anyone holding an invitation link sees the table's name and the display name of whoever sent it. People outside that table can't read any of it. The boundary is enforced where the data lives, not just hidden in the interface.
Cookies: just the one that keeps you signed in. Your light or dark choice lives in your browser's own storage and never leaves it. No tracking, no ads, no third-party analytics. To slow down password guessing we count sign-in attempts per IP address; the count resets after a short window.
Your control: you can edit your profile and leave any table whenever you like. A table's shelf is drawn from its members' libraries, so leaving takes your games off it while your own library stays as it was. Leaving also takes your name off any upcoming nights you were hosting there. You can delete your account at any time from Settings. That removes your profile, your sign-in details, your library, your memberships, your RSVPs, and the invitations you sent, and it permanently deletes any tables you own, for everyone at them (transfer ownership first if you'd rather they stay). Game nights you've hosted elsewhere stay with their tables, minus your name. A catalog entry for a game you were first to add stays, since it's shared, but it no longer points at you.
Changes: if we change what we collect, we'll update this page and say so plainly.