TableVault
Privacy Notice
Last updated: 31 July 2026
Who is responsible for your data?
TableVault operates tablevault.net and is responsible for the personal data described in this notice. For privacy questions or to exercise your rights, contact us through the contact page.
This notice covers the TableVault website and services. Discord and Steam are independent services with their own privacy notices. Sentry and infrastructure providers process technical data in connection with the services they provide to TableVault.
Data we process
Discord account data
When you sign in with Discord, we receive your Discord user ID, username, display name, avatar and other profile presentation data returned by Discord, such as banner, accent colour, locale and public account flags. We store the Discord OAuth access token and refresh token encrypted, together with their scope and expiry, as part of the authentication record and for Discord API calls that you separately authorise.
Steam data you choose to link
After you explicitly link Steam, we store your SteamID64, public profile information returned by Steam (such as persona name, avatar and profile URL), and the games returned by Steam for your account: app ID, title and total playtime. We do not receive or store your Steam password.
Content and account activity
We process tables and other content you submit, including file content, descriptions, credits, source URLs, public keys, signatures and moderation-related metadata. We also store bookmarks, account roles and sign-in activity needed to operate your account. For authenticated downloads, we retain the table reference, first and most recent download dates, and a download count. For feedback, we retain your vote, selected reason, optional note and submission date. This lets us show your download history and limit feedback to tables you have downloaded.
Technical and diagnostic data
Our servers and security tooling may process request metadata, including IP address, user agent, requested page, referrer, timestamps and error details. TableVault uses a site measurement endpoint to understand traffic and performance, and Sentry may receive error reports and technical context when error monitoring is enabled.
How and why we use data
| Purpose | Legal basis where GDPR applies |
|---|---|
| Create and secure your account, authenticate you and provide account features. | Performance of our agreement with you. |
| Link and display your Steam collection at your request. | Performance of our agreement with you. |
| Publish, protect and moderate community content; prevent abuse and keep the service reliable. | Our legitimate interests in operating a safe, reliable community service. |
| Maintain download history and feedback records, display your history and limit feedback to eligible downloads. | Performance of our agreement with you and our legitimate interests in preventing feedback abuse. |
| Measure performance, diagnose errors and improve the service. | Our legitimate interests in maintaining and improving the service, or consent where required for a tracer. |
| Meet legal obligations and respond to lawful requests. | Legal obligation or our legitimate interests in protecting our rights and users. |
We do not use your data for automated decisions that produce legal or similarly significant effects.
Discord and Steam choices
- Discord sign-in currently requests only the
identifyscope. We do not currently retrieve or store your Discord guild list, connected accounts or email address. - Linking Steam is optional. You can disconnect Steam from My Steam Collection; this deletes the linked Steam account record and its cached collection from TableVault.
- If we later add optional Discord community or connected-account features, we will request the relevant additional permission at that time and update this notice before using that data.
Who receives data?
- Discord provides sign-in and profile data when you choose to use Discord authentication.
- Steam / Valve provides the profile and owned-game information required for a Steam link.
- Infrastructure and security providers may process data to host the service, store the database, deliver the site and monitor errors.
- The public can see content that you submit for publication, together with any credits or other information included in that content.
- Authorities or professional advisers may receive data where required by law or necessary to establish, exercise or defend legal claims.
We do not sell or rent personal data.
International transfers
Discord, Steam, Sentry and infrastructure providers may process data outside the European Economic Area or the United Kingdom. Where a transfer is subject to GDPR or UK GDPR transfer rules, we will rely on an adequacy decision or appropriate safeguards, such as standard contractual clauses, as applicable to the provider and transfer.
Retention and deletion
| Data | Retention approach |
|---|---|
| Account, Discord identity and encrypted tokens | For the lifetime of the account, then deleted when the account is deleted. |
| Linked Steam account and collection | Until you disconnect Steam or delete your account. |
| Submitted public tables | May remain available after account deletion. The account link is removed, but content fields such as credits that you supplied may remain public. |
| Authenticated download history | For the lifetime of your account, then deleted with the account. If a table is removed, its historical entry remains but no longer identifies a published table. |
| Feedback records | Until you remove the feedback, the related table is removed, or your account is deleted. |
| Sessions | For the browser session or until server-side session expiry. |
| Security logs and error reports | Only for as long as needed to secure and operate the service, subject to the retention settings of the relevant provider. |
Cookies and similar technologies
TableVault uses a strictly necessary session cookie to keep a signed-in session secure and to support the Discord sign-in flow. This cookie is not used for advertising. We do not use an application-level advertising cookie in the current service code.
If we introduce a non-essential cookie or similar tracer, we will provide the required notice and obtain consent before activating it where the law requires consent. You can also control or delete cookies through your browser settings; removing necessary cookies may prevent sign-in from working.
Your rights
Depending on the law that applies to you, you may request access to your data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent where processing relies on consent. To make a request, use the contact page. We may ask for information needed to verify that the request comes from the account holder.
If you are in the EEA or UK, you may also complain to your local data protection authority. In France, this is the CNIL.
Changes to this notice
We may update this notice when our service or legal obligations change. The current version will be published here with an updated date. Where a change materially affects your rights or requires new consent, we will provide an additional notice before the change takes effect.