ClinicTabletop
DemoHow it worksScenariosPricingSign inRun your first drill

Legal

Privacy Policy

Effective date: July 5, 2026

This policy describes what information Clinic Tabletop collects, how we use it, and the choices you have. The short version: we collect what we need to run your exercises and your subscription, we don’t sell it, we don’t run ads, and the Service is built so that real patient information never needs to enter it.

1. What we collect

Account information. Your email address and sign-in method (email magic link or Google).

Clinic profile. What you tell us about your clinic to localize exercises: clinic name, city and state, clinic type, approximate staff size, the name of your EHR, your IT support situation, and your cyber insurance carrier if you choose to provide it.

Exercise data. Participant first names and roles as you enter them, your team’s written answers during exercises, and the resulting after-action reports.

Billing information. Payments are processed by Stripe. We never see or store your card number; we store your subscription status, plan, and Stripe customer reference.

Support messages. What you send through the support page, along with your email and, if you’re signed in, your plan status so we can help faster.

Technical basics. Authentication cookies to keep you signed in, and standard server logs. We do not use advertising trackers or sell data to advertisers.

2. What we deliberately do not collect

The Service is not designed to receive protected health information. Exercises are simulations, and nothing in them requests patient names, records, or identifiers. Please do not enter real patient information in any free-text field. Clinic Tabletop is not a business associate under HIPAA, and use of the Service does not create a business associate relationship.

3. How we use information

We use the information above to run your exercises (including localizing scenarios to your clinic), generate and archive your after-action reports, operate your subscription, respond to support requests, secure the Service, and improve the product. We do not sell personal information, and we do not use your exercise content for advertising.

4. AI processing

Exercise narration and answer evaluation are generated using a third-party AI provider (OpenAI). During an exercise, the relevant scenario text, your clinic profile details, and your team’s written answers are sent to that provider to produce the narration, evaluation, and report content. This is another reason not to enter patient information: text you type during exercises is processed by our AI provider to deliver the Service.

5. Service providers

We use a small set of providers to run the Service, each receiving only what it needs: Supabase (authentication and database hosting, US region), OpenAI (exercise narration and evaluation), Stripe (payments), Netlify (website hosting), Slack (delivery of support messages to our team), and Google (optional sign-in). These providers process data on our behalf under their own security and privacy commitments.

6. Retention and deletion

Exercise records and after-action reports are retained so you can use them as documentation — that’s a core purpose of the product — and remain available if a lapsed subscription is renewed. If you want your account and its data deleted, contact us through the support page and we will delete it, subject to records we must keep (such as billing records).

7. Security

Data is encrypted in transit, stored with a hosted database provider that encrypts data at rest, and separated per account with row-level access controls. Payment credentials are handled entirely by Stripe. No system is perfectly secure, but the Service is built so that the most sensitive category of healthcare data — patient information — is never supposed to be in it at all.

8. Your choices

You can access and update your clinic profile in the Service, manage billing through the billing portal, and request a copy or deletion of your data through the support page. Depending on where you live, you may have additional rights under local law; we honor reasonable requests regardless of jurisdiction.

9. Children

The Service is a business tool for healthcare organizations and is not directed to anyone under 18.

10. Changes to this policy

If we change this policy, we will post the updated version with a new effective date and, for material changes, notify you by email or in the Service.

11. Contact

Questions about privacy? Reach us through the support page.

ClinicTabletop

Cybersecurity tabletop exercises for small healthcare clinics.

How it worksScenariosPricingFor health centersTalk to usSupportSign in

© 2026 Clinic Tabletop. Exercises are simulations for training and preparedness — no real patient data is used or requested at any point. Terms of Service · Privacy Policy