Undeployed Adam

TableSync

TableSync — Privacy Policy

Last updated: 11 September 2026

TableSync is a Dungeons & Dragons character sheet and table app published by Adam Mosley. This policy covers the TableSync Player app for Android and iOS, and the TableSync desktop and browser applications.

The short version

TableSync has no servers. There is no TableSync account, no TableSync back end, and nothing you do in this app is sent to the developer. Your characters are stored on your own device. The only time anything leaves your device is when you choose to join a Dungeon Master's table, and then it goes to that DM's computer — run by someone you know, on your own network or, if the DM has chosen to publish their table, reached over the internet — and to nowhere else. Looking up a join code sends the code alone to a small address service the developer runs; it never sees your key or your characters.

What the app stores on your device

a player name if you enter one, and a portrait image if you add one.

rules content.

This is held in the app's own storage on your device. Uninstalling the app removes it. The developer cannot see it, and it is not sent to any service operated by the developer.

Android backup. The Android app allows Android's own backup system to include its data, which is the standard behaviour that lets your characters survive moving to a new phone. Where that is enabled on your device, the backup goes to your Google account, under Google's terms, not to the developer. You can turn it off in Android's system settings under Backup.

What is sent off your device, and when

Nothing is transmitted unless you take one of these actions:

1. Joining a Dungeon Master's table. You enter an address and a key that the DM gives you. Your character sheet is then sent to, and kept on, that DM's computer so the DM can see your character during play. That computer is not operated by the developer. What the DM does with it is between you and your DM. 2. Joining by a join code. A DM can hand you a short code instead of an address. To turn it into the table's address, the app asks a small redirector service run by the developer (undeployedadam.com) where that code points. That request carries the code and nothing else — not your key, not your name, not your characters — and the service keeps no record of who asked. Your key then goes only to the DM's own table, exactly as in step 1. 3. A DM's table reached over the internet. Since September 2026 a DM can publish their table through a tunnel, so the address you join may be a public https://… name rather than a local network one. The connection is encrypted to the tunnel provider and terminated at the DM's machine; the tunnel operator (Cloudflare, for the launcher's built-in option) can see the traffic in transit as any relay can. The developer is not on that path. 4. Exporting a character to a file. The file goes where you put it.

The app makes no other network requests. It contains no advertising, no analytics, no crash reporting, no tracking of any kind, and no third-party SDK that collects data.

The app is able to use plain HTTP connections, because a DM's table on a local network runs on a plain address rather than a public HTTPS site. Those connections go only to the address you type in; a published table's https:// address is used as given and never downgraded.

Children

TableSync is not directed at children under 13, and collects no personal information from anyone, including children.

Permissions

The Android app declares one permission of its own, INTERNET, used solely to reach the DM's table address you enter. The build also carries an internal signature-level permission generated by the Android support libraries (DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION), which grants no access to anything on your device and cannot be used by other apps. The app does not request location, contacts, camera, microphone, or storage permissions. Adding a character portrait uses the system's own picker, which hands the app the single image you chose.

Your data, your control

Because everything is on your device, you are in control of it:

For a sheet you have sent to a DM's table, ask that DM to remove it — the player app deliberately cannot delete from a DM's machine.

Third-party content

The app includes game rules content from the System Reference Document 5.1 and 5.2.1, published by Wizards of the Coast LLC under the Creative Commons Attribution 4.0 International License. That content is bundled in the app and involves no data collection. Full attribution is in the app under About & licences, and in the NOTICE file shipped with it.

TableSync is unofficial Fan Content. It is not approved or endorsed by Wizards of the Coast.

Changes

If this policy changes, the date at the top changes with it, and the updated policy ships with the next release of the app.

Contact

Questions about this policy: adamisdeployed@gmail.com

Back to TableSync