Legal
Privacy Policy
Effective date: September 14, 2026
This Privacy Policy explains what Second Coffee, LLC ("TableThis," "we," "us") collects when you use the hosted TableThis service at app.tablethis.ai, our website at www.tablethis.ai, and related services we operate, and how we use, share, retain, and protect that information.
This Privacy Policy applies only to the hosted Service that we operate. If you or your organization run TableThis software on your own infrastructure, whoever operates that installation is responsible for its data practices and this Privacy Policy does not apply to that installation.
1. Our role
TableThis plays two different roles depending on the information involved.
Account and operational information. For information about your account, your use of the Service, and our security and operations, we decide what we collect and why. We are responsible for that information and this Privacy Policy describes how we handle it.
Workspace content. For the tables, records, and documents placed in a workspace, the person or organization that controls the workspace decides what goes in and what it is used for. We hold and process that content on their behalf and in line with the permissions they set.
This distinction matters in practice. If you are a member of an organization's workspace and you want content about you changed or removed from that workspace, the organization controls that decision, not us. We will generally direct your request to them.
Organization customers who need a data processing agreement can request one at [email protected].
2. Information we collect
Account information
We collect information you provide when creating or using an account, such as:
- your name;
- your email address; and
- information associated with supported authentication methods.
If you sign in using Google, we receive information necessary to authenticate you, such as your email address and basic account information provided by Google.
Workspace content
We store the information you and other authorized users put into TableThis, including:
- tables;
- records;
- Markdown documents;
- document content;
- revisions and change history; and
- other information submitted to a workspace.
Workspace content may contain personal, confidential, financial, health-related, or other information that you or your organization choose to provide.
TableThis is not intended for certain regulated information as described in our Terms of Service, including HIPAA-regulated protected health information unless we have separately agreed to that use in writing.
Workspace membership and permissions
We collect information about:
- which workspaces you belong to;
- workspace ownership;
- your role and permissions; and
- invitations and membership changes.
Audit history
TableThis records information about activity in a workspace, such as who or what changed information and when.
This history may include activity performed by people, applications, APIs, and connected AI clients.
AI-client and application connections
If you connect an AI client or another application to TableThis through MCP, OAuth, an API, or another supported integration, we may store:
- the authorization you grant;
- identifiers associated with the connected client;
- permissions granted to the client;
- connection status; and
- records of actions taken through the connection.
Operational and security information
When you use the Service, our systems may automatically collect technical information necessary to operate, troubleshoot, and secure it, such as:
- server logs;
- IP addresses;
- timestamps;
- request information;
- browser or device information;
- authentication events;
- rate-limiting information; and
- error and diagnostic reports.
We run our own error tracking and product analytics on our own infrastructure. We do not use third-party advertising or behavioral-analytics trackers on the hosted Service.
3. How we use information
We use information we collect to:
Provide the Service
This includes:
- authenticating users;
- creating and managing workspaces;
- saving and synchronizing content;
- maintaining revision and audit history;
- processing authorized application and AI-client requests;
- providing search; and
- operating other TableThis features.
Secure the Service
We use information to:
- prevent unauthorized access;
- enforce workspace permissions;
- rate-limit traffic;
- investigate suspected abuse;
- detect security problems; and
- diagnose and correct errors.
Communicate with you
We may use your contact information for:
- sign-in links;
- account notices;
- security alerts;
- workspace-related messages;
- important Service notices; and
- responses to support or privacy requests.
Operate and improve TableThis
We may use usage, operational, and diagnostic information to understand how the Service operates and to maintain and improve it.
We do not use your workspace content to train AI models.
We do not sell your personal information.
4. Search and AI features
Search. On the hosted Service, TableThis uses vector embeddings to power search across documents and records. To generate those embeddings, document text, record text, and search-query text are sent to an embedding service provider we use for this purpose. That provider processes the text only to generate the embeddings needed to provide TableThis search, and is contractually prohibited from using it to train its models or for its own independent purposes.
AI features. We may use third-party AI model providers to deliver features you request. Where we do, we send only the information needed for that feature, and we use these providers under terms that prohibit them from using your content to train their models or for their own purposes.
We may change or add service providers as the Service develops. A current list of the providers we use is available at [email protected].
Independently operated TableThis installations may handle search and AI features differently and are not covered by this Privacy Policy.
This section describes providers we use to operate the Service. It does not cover AI clients or applications that you choose to connect to your workspace. Those are third-party services governed by their own terms and privacy practices, and what they do with information they access through your workspace is between you and them.
7. How long we keep information
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to the following:
- Account information is generally kept while your account is active.
- The current version of workspace content is generally kept for as long as the workspace exists.
- On the current Free plan, document revision history is retained for 30 days unless otherwise stated in the Service.
- Trashed documents and unresolved edit conflicts are generally permanently removed after 30 days.
- Audit history may be retained for as long as the workspace exists.
- Operational, security, and diagnostic records are kept for as long as reasonably necessary to operate, secure, troubleshoot, and protect the Service.
When an account or workspace is deleted, associated information is generally removed from active systems as part of our normal deletion process.
Copies may remain in routine backup systems for up to 30 days before being overwritten or deleted.
We may retain limited information for longer when reasonably necessary to:
- comply with law;
- resolve disputes;
- enforce agreements;
- detect or prevent fraud or abuse;
- maintain security records; or
- establish, exercise, or defend legal claims.
8. Your choices and controls
You may review or update available account information through your account settings.
You may delete your account at any time. If self-service deletion is not available in your account settings, contact us at [email protected] and we will delete it for you. Deleting your account starts the deletion process described in Section 7.
Deleting your individual account does not necessarily delete content in an organization workspace. That content remains under the control of the organization that owns the workspace.
Workspace owners and administrators can manage workspace membership and may block connected AI clients or applications from their workspace.
You can generally revoke a connection you authorized through the relevant AI client or application. You may also contact us for help revoking a connection.
We do not yet provide every privacy function through a self-service interface. You may contact us at [email protected] to request assistance with:
- accessing account information;
- correcting information;
- deleting information, subject to applicable exceptions;
- exporting information where reasonably available; or
- another privacy-related request.
If the information is controlled by an organization workspace, we may direct your request to the organization that controls that workspace, as described in Section 1.
We may need to verify your identity before fulfilling a request.
9. California and other U.S. privacy rights
Depending on where you live and whether a particular privacy law applies to TableThis, you may have legal rights concerning personal information, including rights to:
- know or access personal information;
- receive a copy of certain information;
- correct inaccurate information;
- request deletion;
- opt out of certain sales, sharing, or targeted advertising;
- limit certain uses of sensitive personal information; or
- exercise other rights provided by applicable law.
The categories of personal information we collect are described in Section 2 and consist of identifiers such as name and email address, internet and network activity information such as logs and IP addresses, and any personal information contained in workspace content that you or your organization choose to provide. We collect this information from you, from your organization, from connected applications and AI clients you authorize, and automatically from your use of the Service. We use and disclose it for the purposes described in Sections 3, 4, and 5, and we retain it as described in Section 7.
TableThis does not:
- sell personal information;
- share personal information for cross-context behavioral advertising; or
- use sensitive personal information to infer characteristics about people for advertising purposes.
Accordingly, there is currently no sale or behavioral-advertising sharing from which you need to opt out.
Even where a particular state privacy law does not technically apply to TableThis, we may choose to honor reasonable access, correction, or deletion requests when we can do so.
To submit a privacy request, contact us at [email protected].
We may verify your identity before completing a request.
Where applicable, an authorized agent may submit a request on your behalf, although we may still need to verify your identity or the agent's authority.
We will not unlawfully discriminate against you for exercising an applicable privacy right.
10. Children's privacy
The Service is intended for users who are at least 16 years old.
We do not knowingly collect personal information from anyone under 16.
If we learn that we have collected personal information from someone under 16 in violation of this policy, we will take reasonable steps to delete it.
If you believe someone under 16 has provided personal information to TableThis, contact us at [email protected].
11. Security
We use reasonable technical and organizational measures designed to protect information against unauthorized access, use, alteration, or disclosure.
These measures may include access controls, authentication, encrypted network connections, monitoring, logging, and other security practices appropriate to the Service.
However, no online service, storage system, or method of transmission can guarantee absolute security.
Security incidents. If a security incident requires notification under applicable law, we will provide the required notifications in accordance with that law, using the contact information associated with your account. For organization workspaces, we may provide notice to the organization that controls the workspace.
You are responsible for protecting access to your account, email account, devices, authentication methods, and integrations.
Please contact us promptly at [email protected] if you believe your TableThis account or workspace has been compromised.
12. Where we operate
TableThis is operated by Second Coffee, LLC in the United States and is intended for users in the United States.
The Service is not directed to individuals in the European Economic Area, the United Kingdom, or Switzerland.
If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and in other countries where our service providers operate. Those countries may have data-protection laws different from the laws where you live.
As TableThis expands, we may provide additional notices, contractual terms, transfer mechanisms, or privacy rights where required by applicable law.
13. Changes to this Privacy Policy
We may update this Privacy Policy as TableThis and our legal obligations change.
If we make a material change, we will update the effective date above and, where appropriate, notify you through the Service or using the contact information associated with your account.
14. Contact us
Questions, privacy requests, or concerns about this Privacy Policy may be sent to:
TableThis, Second Coffee, LLC3559 Mt Diablo Blvd #393
Lafayette, CA 94549
[email protected]
See also our Terms of Service.