Privacy
Last updated August 2026
What is collected, and why
An account is an email address and a name — that is the whole sign-up. The address sends your sign-in links, carries invitations when someone shares a database with you, and in your first weeks may carry a few short notes from us if you look stuck — every one of them stoppable in one click, from the email itself or from your profile. Those notes record whether they were opened and whether their link was followed; both are measured on our own servers, by us, and go nowhere else. If you arrived from one of our ads it is also hashed in your own browser and used to match the sign-up to the ad click, which is described under Advertising below. No newsletters, and the address is never sold and never handed to anyone in the clear.
Measurement, self-hosted
Tabla keeps its own record of product activity at the level of actions — signed in, made a database, ran an import — stored in Tabla’s own database and used to operate and improve the service. The public site counts page views and clicks the same way, with a first-party anonymous cookie. No external analytics service is involved in any of it, and nothing is ever sold or shared. Beyond that, the only records of activity are ordinary server logs (which requests arrived, when, and from which network address), kept for operating and securing the service.
Session recording
On the public pages and the sign-in page, Tabla records how the page was used — where the pointer went, what was clicked, what was scrolled past — so we can see where the site is confusing without guessing. It is our own code and it stays on our own server; no recording service is involved. Anything typed into a password, email or phone field is never captured, and the same browser signals as everything else here apply: send Global Privacy Control or Do Not Track and nothing is recorded at all.
Inside Tabla it works the same way, on every account. The contents of your records, including the grid itself, are hidden when a session is watched; showing them is a separate, deliberate step, logged on its own. Only an administrator can open a recording, nothing leaves our server, and recordings are deleted after 30 days. Ask us to switch it off for your account and we will — support@tabladb.com.
Advertising
Tabla buys ads on Google and on Reddit, and carries a measurement tag from each so we can tell which ads actually lead to someone signing up and making something. That is the whole of what they record: an ad click, a page read, a sign-up, a first table. Because signing up here is an email address, that address is what links the click to the account — and neither network is given it. Google’s tag hashes it in your own browser before it goes anywhere; Reddit is handed a hash we compute on our own server, so the address itself never reaches their code at all.
Google’s tag can set one Google cookie — _gcl_aw, and sometimes _gcl_au. Reddit’s sets its own, all first-party: _rdt_uuid for the browser, and beside it the ad click’s reference and the hashed address described above. We keep that click reference in a cookie of ours as well, so a sign-up arriving later from an emailed link can still be matched to the ad it came from. In the European Economic Area and the United Kingdom we ask before any of that is written, on a card that blocks nothing and weighs both answers the same. The answer is a single click, remembered for a year in a cookie that holds one word.
Decline and none of that is written. Reddit’s pixel is not loaded at all, so it learns nothing whatsoever. Google’s tag still learns that a visit happened and, if you arrived from one of our ads, which ad click it was — that reference is part of the address you arrived on. Nothing is stored on your device for it, and nothing carries from one visit to the next.
Separately, and on our own side only, an account created from an ad keeps a note of what brought it: which network the ad ran on, the campaign, which of its ads it was, the search term the ad matched where there was one, and the page it landed on. Where the network gives the click a reference of its own, that reference is kept with the rest. It is kept for as long as the account exists, because the question it answers — which ads bring people who actually stay — is a question about months, not days. It is never sent to Google, to Reddit, or to anyone else, and it is deleted with the account.
Nothing you build in Tabla goes near either of them. Your records, your files, and the names of your databases, tables and fields are never sent to Google, to Reddit, or to anyone else. Both tags honor Global Privacy Control and Do Not Track: if your browser sends either signal, neither is loaded at all. They are the only two pieces of a third party’s code on the site, and if that ever changes this page changes with it.
Where data lives
Records live in a database on the service’s own server, in Germany. Uploaded files live in object storage — a separate file store, either on the same server or with a storage provider. Nightly copies of the database are kept with a separate storage provider, and the built-in export gives you a complete copy of your own at any time, files included. Sign-in links and invitations are sent through a mail provider.
Deletion
Deleted records stay in a trash for 7 days and can be restored during that time; after that they are gone permanently. When a database is deleted, its files in object storage are deleted with it, and its records age out of the nightly backups within the backup retention window (30 days).
Your rights
Tabla honors data-subject rights in the style of the European Union’s data-protection law for everyone, wherever they are: access to a copy of your data (the built-in export does this at any time, no request needed), correction, deletion, and an answer within 30 days for anything the product cannot already do itself.
Contact
Privacy questions and requests go to support@tabladb.com.