Tabletop exercises can involve sensitive facts. Use fictional or minimized data whenever possible. Do not enter real credentials, unnecessary personal information, or restricted legal, security, personnel, health, or customer data.
1. Scope
This Privacy Policy describes how Turnip Games, LLC (“Turnip Games,” “we,” “us,” or “our”) handles information through Crisis Tabletop (the “Service”). It applies to public pages, facilitator workspaces, participant channels, room displays, exercise records, and support communications.
An organization or facilitator controls the substance of an exercise and decides who participates. For Customer Content entered on behalf of an organization, that organization may be the primary decision-maker responsible for notices, permissions, access requests, and retention requirements. Participants should direct exercise-specific questions to their facilitator or organization first.
2. Information we collect
Facilitator account information
When a facilitator signs in through Google or OpenAI, the Service receives the authenticated email address and, when available, the account name. We use the email address to associate sessions with the correct facilitator workspace.
Guest facilitator sessions
Guest-mode session selections and exercise progress are stored in the browser’s local storage rather than in a facilitator account. They are not available to participants or other devices and are removed when that browser’s site data is cleared. Standard web request and security information may still be processed when guest pages are loaded.
Exercise and presentation content
We store information signed-in facilitators create or import, such as session titles, scenarios, injects, roles, decision paths, discussion questions, organization names, uploaded logos, presentation themes, facilitator notes, exercise status, and timestamps.
Participant information and activity
Participants may provide a display name, select a role, join as an observer, submit responses, and receive public or role-specific messages. The Service stores exercise codes, participant access credentials, role assignments, responses, events, and related timestamps so the live session can function and produce an after-action record.
Technical information
Our hosting, authentication, and security providers may process standard request information such as IP address, browser and device characteristics, requested pages, timestamps, diagnostic events, and cookies or similar technologies needed for authentication, security, and service operation. We do not currently use the Service for cross-site behavioral advertising.
Communications
If you contact us, we receive the information in your message and any information reasonably necessary to respond.
3. How we use information
We use information to:
- authenticate facilitators and keep tenant workspaces separated;
- create, run, synchronize, restart, export, and document tabletop exercises;
- route public and private exercise information to the intended screens and roles;
- operate, maintain, troubleshoot, secure, and improve the Service;
- respond to support, legal, safety, and rights requests;
- prevent fraud, abuse, unauthorized access, and violations of our terms; and
- comply with law and protect the rights and safety of users, Turnip Games, and others.
We do not sell personal information. We do not use Customer Content to create advertising profiles.
4. How information is disclosed
Information may be disclosed in these circumstances:
- Within an exercise. Facilitators can view session participants and activity. Public injects appear on participant and room displays. Private injects are routed to designated participants, but facilitators control and can access the exercise record.
- Service providers. Hosting, storage, authentication, security, and technical-support providers process information for us under their applicable terms and safeguards.
- At your direction. We disclose information when a facilitator or authorized user chooses to display, export, or share it.
- Legal and safety reasons. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, enforce terms, investigate abuse, or protect rights, safety, and service integrity.
- Business transactions. Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
External links, including CISA and practitioner resources, are governed by the privacy practices of the destination sites.
5. Facilitator and organizational control
Facilitators choose the scenario facts, participants, role assignments, private messages, notes, uploaded branding, and exercise duration. They may export exercise documents and after-action information. Restarting an exercise clears the prior run’s activity, facilitator notes, and participant responses while retaining the scenario, room code, and role assignments.
Because a facilitator or organization controls Customer Content, participants should contact that facilitator or organization to request access, correction, or deletion of exercise-specific information. We may refer a request to the relevant organization when appropriate.
6. Retention
We retain information for as long as reasonably necessary to provide and secure the Service, maintain requested exercise records, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of information, the facilitator’s actions, the sensitivity of the data, and operational requirements.
Information removed from the active Service may remain temporarily in backups, security records, or legal archives. Facilitators should not rely on the Service as the only repository for records they must preserve, and should avoid retaining sensitive exercise content longer than their organization requires.
7. Security
We use administrative, technical, and organizational measures designed to protect information, including authenticated facilitator workspaces and scoped participant access. No online service can guarantee absolute security. Room codes and participant links can provide access to exercise information and should be shared carefully.
If you believe information or access credentials have been compromised, stop using the affected session, preserve relevant evidence, and contact us. Crisis Tabletop is not an emergency reporting channel.
8. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or information about certain disclosures, and to appeal a decision. These rights may be subject to exceptions, identity verification, and the role of the organization controlling the exercise.
Facilitators can edit many session and scenario fields directly and can export exercise documents. To submit a privacy request, email privacy@tourn.app. Describe the Service account or exercise involved, but do not email sensitive scenario content. We may need to verify your identity and authority before acting.
The Service uses technologies necessary for sign-in, security, and core functionality. Browser controls may allow you to limit cookies, but doing so can prevent authenticated features from working.
9. Children
The Service is intended for professional and organizational use and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information without legally sufficient authorization, contact us so we can review and address the issue.
10. International use
Turnip Games is based in the United States. Information may be processed and stored in the United States and other locations where our service providers operate. Organizations using the Service across borders are responsible for determining whether additional notices, contracts, transfer mechanisms, or data-location controls are required.
11. Changes to this policy
We may update this policy to reflect changes in the Service, law, or our practices. We will post the revised policy and update the effective date. Material changes may also be communicated through the Service when appropriate.
12. Contact
Privacy questions and requests may be sent to privacy@tourn.app.
Turnip Games, LLCOregon, Wisconsin, United States