✺ Legal

Privacy Policy

Effective date: [DATE]Last updated: [DATE]
✺ Draft

This page is not final. The marked passages below are decisions we have not made yet, so read them as gaps rather than as statements of what we do. There are 13 of them.

Galleo turns a brief into a deck, a document or a website. To do that we store what you write and send parts of it to the AI providers that generate and edit it. This page says exactly what we hold, what leaves our systems, who receives it, and how long we keep it.

The short version

We store your account details, the pieces you create, and the files you attach to them. When you generate or edit something, that content goes to a model provider so it can produce the result. We do not sell your content or your personal information, we do not use your content to train models, and our product analytics is built so that no content reaches it: it records that a thing happened and never what the thing said.

Who we are

[LEGAL ENTITY NAME] operates Galleo at galleo.app and is the controller of the personal data described here. You can reach us at [PRIVACY CONTACT ADDRESS].

What we collect

Your account. Your email address, and a display name and avatar if you set one or if they come from Google when you sign in that way. If you set a password we store a scrypt hash of it, never the password. We record when your email was confirmed and when your password last changed.

What you create. The pieces you write and everything in them: text, images, video, uploaded files, comments, speaker notes, and the narration and music beds generated from them. We also store what you attach as context, which includes the text extracted from files you upload and pages you ask us to fetch, and the original file alongside it.

How you use Galleo. Which pieces you open and how often, so the library can order itself sensibly. What each AI action cost, in a credit ledger tied to the person who ran it, so a workspace admin can see where its credits went.

Payments. If you subscribe, Stripe handles the payment and we store only your Stripe customer and subscription identifiers, your plan, and its status. We never see or store your card number.

Published links. When somebody opens a link you published, we record that a view happened, which section they reached, the referring site's hostname, a coarse device type, and a country derived from the request. We do not store the reader's IP address or user agent. To count returning readers without identifying them we store a one-way hash of the day, the address, the user agent and the link, which cannot be reversed into any of those.

What we send to AI providers, and to whom

When you generate or edit a piece, the content of that piece, the instruction you gave, and any context you attached are sent to a model provider so it can produce the result. The default provider for every task is Google, and a workspace on a paid plan can select Anthropic, OpenAI or xAI for a given task instead. Images and video are generated by Google, and narration, voice design and music beds by ElevenLabs. Searching for stock media sends your search terms, or terms derived from the text of your piece, to Unsplash, Pexels, Pixabay and Openverse. Dictation is the one exception to this pattern: your microphone audio goes from your browser straight to ElevenLabs and never passes through our servers.

We send this content only to produce the result you asked for, and we do not train models on it. We have no model of our own to train.

Under the commercial terms these providers publish, Anthropic, OpenAI and Google do not use content sent through their paid interfaces to train their models. Anthropic states this as a contractual prohibition rather than a policy. Each keeps a copy for a limited period so it can detect abuse of its service: up to 30 days at Anthropic and OpenAI, and up to 55 days at Google. Content that a provider's safety systems flag can be kept longer, and Anthropic states that flagged material may be held for up to two years.

[ELEVENLABS: ITS TERMS ALLOW IT TO USE CUSTOMER CONTENT TO IMPROVE ITS SERVICES UNLESS THE ACCOUNT OPTS OUT. STATE OUR POSITION HERE ONCE THE OPT-OUT IS CONFIRMED, OR NAME IT AS AN EXCEPTION.]

These periods are what each provider commits to, not a guarantee we can make on their behalf. A provider may also keep content where the law or a court requires it, which is outside our control and outside theirs.

Everyone who processes data for us

WhoWhat they doWhat they receive
Googlethe default model for every task, image and video generation, embeddings, and Google sign-inyour content, prompts and attached context; your Google profile if you sign in that way
Anthropic, OpenAI, xAImodels a paid workspace can pin a task ontoyour content and prompts, when selected
ElevenLabsnarration, dictation, voice design, music bedsspeaker-note text; microphone audio, browser to provider
Resendtransactional and invitation emailrecipient address, the piece's title, the sender's name, and any note added to an invite
Stripesubscriptions and paymentsyour email, the workspace name, and payment details you give Stripe directly
PostHogproduct analyticsevents about what happened, never content; your IP for the browser's own events
Unsplash, Pexels, Pixabay, Openversestock image and video searchyour search terms
Iconifyicon searchyour search terms
Render, Neon, Cloudflarehosting, the database, and the network in front of iteverything we store, at rest and in transit

Analytics, and what we deliberately do not collect

Our product analytics records ids, counts, durations and fixed categories. It never records content. No prompt text, no section copy, no titles, no file names, no email addresses, no search queries. Where the size of something matters we send a bucket rather than the value, so a search is reported as a result count and a length band and never as the words you typed. You are identified to our analytics by an internal account id rather than by your email.

We record screen sessions on the app and marketing site, with every piece of text and every input masked, so what we can see is layout, scrolling and where a click landed rather than anything you wrote. Recording is switched off entirely inside the editor and on published pages.

Somebody reading a link you published is counted but never recorded, is given no identifier that outlives the page, and has no referrer or campaign information collected. They are your audience rather than ours.

Connected apps

You can connect Galleo to an external AI client such as Claude or ChatGPT. When you do, you choose which of your workspaces that connection can reach and what it is allowed to do, and the connection gets nothing beyond what you granted. We store the tokens as one-way hashes rather than in a form we could read back. You can see every connected app and disconnect it in your account settings, which takes effect immediately.

Tracking across other sites, and Do Not Track

No third party collects information about what you do on other websites through Galleo. We run no advertising pixels, no tag manager and no third-party analytics script: our own analytics is served from our own domain, and the fonts we use are hosted by us rather than fetched from a font service.

Because nothing here follows you across other sites, we do not currently respond to Do Not Track signals or similar browser signals. If that changes we will say so here.

Cookies and local storage

We set a session cookie when you sign in, which lasts 30 days and is signed so it cannot be forged. Three short-lived cookies exist only while you are signing in with Google, and are deleted as soon as that finishes. Our analytics sets its own storage on the app and marketing site, and is prevented from doing so on published pages. Your browser also keeps small preferences locally, such as your theme and library layout.

How long we keep things

Sessions expire after 30 days. Sign-in codes last 15 minutes and password reset links an hour. Access tokens for connected apps last an hour and their refresh tokens 90 days, after which they are cleared.

Your content is kept for as long as your account exists. Moving a piece to Trash does not delete it, and Trash is not emptied automatically, so a piece stays there until you empty it or delete the piece outright. [INTENDED RETENTION FOR CONTENT, MEDIA, NARRATION AUDIO, CHAT HISTORY AND LEDGER ROWS.]

[ACCOUNT DELETION: THERE IS NO SELF-SERVICE DELETION PATH IN THE PRODUCT TODAY. SEE THE NOTE BELOW.]

Your rights

[RIGHTS SECTION, WHICH DEPENDS ON THE DELETION AND EXPORT DECISION.]

Where your data is held

Galleo runs in the United States. Our servers are in Oregon, our database is [NEON REGION], and our analytics is on PostHog's US cloud. Our AI providers process your content in their own regions. [TRANSFER MECHANISM FOR USERS IN THE EU AND UK.]

Security

Passwords are stored as scrypt hashes. Every credential we issue, including invitation tokens, sign-in codes and connected-app tokens, is stored as a one-way hash rather than in a readable form. Traffic is encrypted in transit.

[MEDIA URL DISCLOSURE: IMAGES AND VIDEO IN YOUR PIECES ARE SERVED FROM AN UNGUESSABLE ADDRESS THAT DOES NOT ITSELF CHECK WHO IS ASKING. SEE THE NOTE BELOW.]

Children

Galleo is not intended for children, and we do not knowingly collect personal information from anyone under [AGE].

Requests, and how to reach us

To ask what we hold about you, to correct it, to ask us to delete it, or to opt out of any sale of your personal information, write to [DESIGNATED REQUEST ADDRESS]. We answer a verified request within 60 days, and will tell you if we need up to 30 days more. We do not sell personal information, so there is nothing to opt out of, but the address exists so you can ask.

You can review and change your account details, and the content of anything you have made, in the product at any time.

Changes

We will update this page when what we do changes, and the date at the top will say when. If a change materially affects how we handle your personal data we will tell you rather than relying on you noticing.