Legal
Privacy Policy
Effective date: July 5, 2026
This policy describes what information Clinic Tabletop collects, how we use it, and the choices you have. The short version: we collect what we need to run your exercises and your subscription, we don’t sell it, we don’t run ads, and the Service is built so that real patient information never needs to enter it.
1. What we collect
Account information. Your email address and sign-in method (email magic link or Google).
Clinic profile. What you tell us about your clinic to localize exercises: clinic name, city and state, clinic type, approximate staff size, the name of your EHR, your IT support situation, and your cyber insurance carrier if you choose to provide it.
Exercise data. Participant first names and roles as you enter them, your team’s written answers during exercises, and the resulting after-action reports.
Billing information. Payments are processed by Stripe. We never see or store your card number; we store your subscription status, plan, and Stripe customer reference.
Support messages. What you send through the support page, along with your email and, if you’re signed in, your plan status so we can help faster.
Technical basics. Authentication cookies to keep you signed in, and standard server logs. We do not use advertising trackers or sell data to advertisers.
2. What we deliberately do not collect
The Service is not designed to receive protected health information. Exercises are simulations, and nothing in them requests patient names, records, or identifiers. Please do not enter real patient information in any free-text field. Clinic Tabletop is not a business associate under HIPAA, and use of the Service does not create a business associate relationship.
3. How we use information
We use the information above to run your exercises (including localizing scenarios to your clinic), generate and archive your after-action reports, operate your subscription, respond to support requests, secure the Service, and improve the product. We do not sell personal information, and we do not use your exercise content for advertising.
4. AI processing
Exercise narration and answer evaluation are generated using a third-party AI provider (OpenAI). During an exercise, the relevant scenario text, your clinic profile details, and your team’s written answers are sent to that provider to produce the narration, evaluation, and report content. This is another reason not to enter patient information: text you type during exercises is processed by our AI provider to deliver the Service.
5. Service providers
We use a small set of providers to run the Service, each receiving only what it needs: Supabase (authentication and database hosting, US region), OpenAI (exercise narration and evaluation), Stripe (payments), Netlify (website hosting), Slack (delivery of support messages to our team), and Google (optional sign-in). These providers process data on our behalf under their own security and privacy commitments.
6. Retention and deletion
Exercise records and after-action reports are retained so you can use them as documentation — that’s a core purpose of the product — and remain available if a lapsed subscription is renewed. If you want your account and its data deleted, contact us through the support page and we will delete it, subject to records we must keep (such as billing records).
7. Security
Data is encrypted in transit, stored with a hosted database provider that encrypts data at rest, and separated per account with row-level access controls. Payment credentials are handled entirely by Stripe. No system is perfectly secure, but the Service is built so that the most sensitive category of healthcare data — patient information — is never supposed to be in it at all.
8. Your choices
You can access and update your clinic profile in the Service, manage billing through the billing portal, and request a copy or deletion of your data through the support page. Depending on where you live, you may have additional rights under local law; we honor reasonable requests regardless of jurisdiction.
9. Children
The Service is a business tool for healthcare organizations and is not directed to anyone under 18.
10. Changes to this policy
If we change this policy, we will post the updated version with a new effective date and, for material changes, notify you by email or in the Service.
11. Contact
Questions about privacy? Reach us through the support page.