Last updated: 2026-07-19
Privacy Policy
Galley ("we", "us") is an AI editorial platform. This policy explains what data we collect, why, and what your rights are. We keep it short and honest.
What we collect
Account data. Your name, email address, and a password stored only as a secure hash by our authentication provider. If a workspace admin creates your account, they provide these details.
Workspace content. Briefs, articles, reference materials, article examples, editorial policies, and settings you or your team create in Galley. This is your content; we store it to provide the service and for no other purpose.
Usage data. Which features you use and how often, including article generations, checks, exports, timestamps, and counters needed to enforce plan limits.
Technical data. IP addresses and browser information in server logs, kept for security and debugging and rotated on a short schedule.
We do not collect payment card data. Paid access is currently arranged directly with us by invoice or agreement.
How we use your data
- To provide the service: generating, checking, storing, and exporting your content.
- To enforce plan limits and prevent abuse of free trials.
- To send transactional email, including account confirmation and password reset messages.
- To improve Galley using aggregated, de-identified usage statistics.
We do not sell your data. We do not use your content for advertising. We do not train our own or anyone else's AI models on your content.
AI processing - read this part
Galley is built on third-party AI models. When you generate or check content:
- Your brief, article text, and relevant settings are sent to AI model providers solely to produce the output you requested. We use API tiers whose published policies state that API content is not used to train their models.
- Fact-checking and uniqueness features send short excerpts of your article as search queries to web search providers, currently Tavily, to find and verify sources. Only the excerpts needed for the check are sent.
- Keyword research features query SEO data providers, currently Ahrefs, with your topic and keywords, not with your article text.
If you are not comfortable with an excerpt of a specific document leaving Galley for these purposes, do not run web-based checks on it.
Article analytics beacon
Galley offers an optional, off-by-default analytics beacon that your team can embed in published articles. When enabled, it reports to us, on your team's behalf: page views, referrer, reading time, scroll depth, and link clicks on the published page. It is cookieless: it sets no cookies and does no cross-site tracking. Approximate unique-visitor counts are derived from a salted, daily-rotating hash; raw IP addresses of readers are not stored. If your team publishes articles with the beacon, your team is responsible for reflecting this in its own site's privacy notice.
Where your data lives
Our subprocessors include Supabase for database, authentication, and file storage; Vercel for web hosting; Railway for API hosting; Resend for transactional email; AI model providers via API gateway; Tavily for web search; and Ahrefs for SEO data. We share with each only what is needed for its function.
Cookies
We use essential cookies only: keeping you signed in and remembering your theme. We do not use advertising or cross-site tracking cookies.
Retention and deletion
Your content stays until you delete it or your account. Deleting an article permanently removes its content. You can request full account and workspace deletion at any time by writing to us; we honor hard deletion. Security logs are kept briefly and rotated.
Your rights
You can access, correct, export, or delete your data. Write to info@galley.media and we will respond within 30 days. If you are in a jurisdiction with statutory data rights, such as the GDPR, those rights apply to you and this is the address to exercise them.
Security
Data is encrypted in transit. Credentials and integration secrets, such as WordPress application passwords, are stored in an encrypted vault. Access inside your workspace is role-based.
Age limit
Galley is a professional tool and is not intended for anyone under 16.
Changes
If we materially change this policy, we will note the new effective date here and, for significant changes, notify account owners by email.
Contact
info@galley.media